# Fail2Ban configuration file for guacamole # # Author: Steven Hiscocks # [Definition] logging = catalina failregex = /failregex> maxlines = /maxlines> datepattern = /datepattern> [L_catalina] failregex = ^.*\nWARNING: Authentication attempt from for user "[^"]*" failed\.$ maxlines = 2 datepattern = ^%%b %%d, %%ExY %%I:%%M:%%S %%p ^WARNING:()** {^LN-BEG} [L_webapp] failregex = ^ \[\S+\] WARN \S+ - Authentication attempt from for user "[^"]+" failed. maxlines = 1 datepattern = ^%%H:%%M:%%S.%%f # DEV Notes: # # failregex is based on the default pattern given in Guacamole documentation : # https://guacamole.apache.org/doc/gug/configuring-guacamole.html#webapp-logging # # The following logback.xml Guacamole configuration file can then be used accordingly : # # # /var/log/guacamole.log # # /var/log/guacamole.%d.log.gz # 32 # # # %d{HH:mm:ss.SSS} [%thread] %-5level %logger{36} - %msg%n # # # # # #