This site is for tech Q&A. Please keep your posts focused on the subject at hand.

Ask one question at a time. Don't conflate multiple problems into a single question.

Make sure to include all relevant information in your posts. Try to avoid linking to external sites.

Links to documentation are fine, but in addition you should also quote the relevant parts in your posts.

0 votes

I'm creating a custom filter for fail2ban, so I can lock out bots attacking my webserver. How do I test the filter rules to make sure they match what they're supposed to match and nothing more?

in General by (335) 2 9
edited by

Your answer


Privacy: Your email address will only be used for sending these notifications.
Anti-spam verification:
By submitting this post you agree to our Terms & Conditions.
To avoid this verification in future, please log in or register.

1 Answer

0 votes

Fail2ban comes with a tool fail2ban-regex for this exact purpose. You run it like this:


where LOG, REGEX and IGNOREREGEX (optional) can be either strings or files. Note that if you have a filter file that defines both a fail expression and an ignore expression, you need to specify the file twice, once as the parameter REGEX and once as the parameter IGNOREREGEX.


To test both expressions in a filter like this:

# /etc/fail2ban/filter.d/fltr.local


failregex = ^\[\] foo

ignoreregex = ^\[\] bar

you'd run the command like this:

fail2ban-regex /var/log/your.log /etc/fail2ban/filter.d/fltr.local /etc/fail2ban/filter.d/fltr.local

The "Results" section of the output shows how many lines of the log file were matched or ignored (if you specified an ignore expression), and also which lines were missed (not matched by any expression).


Failregex: 5 total
|-  #) [# of hits] regular expression
|   1) [5] ^\[\] foo

Ignoreregex: 2 total
|-  #) [# of hits] regular expression
|   1) [2] \[\] bar


|- Ignored line(s):
|  [2020-06-29T08:04:58+02:00] bar some
|  [2020-06-29T08:10:01+02:00] bar or other
|- Missed line(s):
|  [2020-06-29T07:28:03+02:00] baz xyz
|  [2020-06-29T13:34:55+02:00] - foobar

Add the option --print-no-ignored and/or --print-no-missed to omit the lists of ignored/missed lines at the end. Add the option --print-all-matched, --print-all-ignored and/or --print-all-missed to expand collapsed lists of matched, ignored, or missing lines.

For more information on developing and testing fail2ban filters see here.

by (335) 2 9