-
-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
error-log or access-log for [apache-noscript]? #12
Comments
Hi @robert1112 yes you should use Check how your paths have been specified in either
|
Hi @mitchellkrogza Thank you so much. I will take a closer look at your suggestion. In addition, should I change all to error-log from access-log? Thank you so much.
|
No don't change them all to error.log .... some jails require reading an error.log file but 99% of jails require reading an access.log file. |
I see. What about the regex? How should I change the code below? I am sorry I am not a programmer so it is a bit difficult for me to tell what is it. Thank you.
|
What filter is that and why are you trying to change it from the defaults? |
Hi It is
|
Try this ... BUT test it thoroughly on a live site.
|
Thank you so much. I will update on this today or tomorrow. Thank you so much. 👍 |
Make sure to reload fail2ban after that change so the new filter change is loaded. |
It is weird. Nothing popped up on my error.log while I run https://myip/test.asp/ from Safari Browser. I also created an attack server and run Did I misunderstand something from your post? This is my 2nd time leaning firewall, so maybe some basic concept is missing here. Please kindly help.😞
|
Post your jail settings for this filter. |
Hi @mitchellkrogza Sorry for my late reply. Here it comes. Thank you so much.
|
Hi @mitchellkrogza Can you kindly suggest? I think I run more than 6 times. If I am correct, each run will generate error log in the error log? Or it will only generate an error log when up to 6 times? Either way, Fail2Ban doesn't take action. Thank you. |
Hi
I am not sure if it is correct place to post but this is the best I can come up with. Sorry if it is inappropriate.
I follow your post here https://ubuntu101.co.za/security/fail2ban/fail2ban-persistent-bans- and left a comment but I think you haven't seen it yet. The main point is I got the recommendation from fail2ban that it is supposed to be
logpath = %(apache_error_log)s
in[apache-noscript]
config file.Here is the link to the issue I posted. fail2ban/fail2ban#2344
Can you kindly help? Thank you so much.
The text was updated successfully, but these errors were encountered: