Skip to content
Discussion options

You must be logged in to vote

2025-06-16 8:38:22 5 [Warning] Access denied for user 'db'@'ip' (using password: YES)

If the ip is really IP (just "blackened"), then it shall work (at least works with current filter).

PoC (test with fail2ban-regex)...
$ fail2ban-regex "2025-06-16  8:38:22 5 [Warning] Access denied for user 'db'@'192.0.2.100' (using password: YES)" mysqld-auth

Running tests
=============

Use             jail : mysqld-auth
Use      datepattern : {^LN-BEG} : Default Detectors
Use      single line : 2025-06-16  8:38:22 5 [Warning] Access denied for ...

...

Lines: 1 lines, 0 ignored, 1 matched, 0 missed

Journal matches:

This means your jail monitoring systemd journal and not the log-file (probably …

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@robotrono
Comment options

@sebres
Comment options

Answer selected by sebres
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants