capture user, add datepattern (anchored exact main format and fail2ban defaults)

This commit is contained in:
Sergey G. Brester 2022-04-08 09:55:44 +02:00 committed by GitHub
parent 11768a97e9
commit 6a2d2aa97a
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -25,10 +25,11 @@ _daemon = xrdp-sesman
[Definition]
authfail_re = \[INFO \] AUTHFAIL: user=.+ ip=<HOST> time=\d+
authfail_re = \[INFO \] AUTHFAIL: user=<F-USER>.+</F-USER> ip=<ADDR> time=\d+
failregex = ^%(__prefix_line)s%(authfail_re)s$
ignoreregex =
datepattern = ^\[?%%ExY%%Exm%%Exd[-|T]%%ExH:?%%ExM:?%%ExS(?:[.,]%%f)?(?:\s*%%z)?\]?
^{DATE}