This fail2ban regex generator writes the filter and jail from real log lines. Paste a few lines that show the abuse — failed SSH logins, WordPress login floods, Dovecot authentication failures, 404 scans — and describe the ban policy. You get a filter file with an anchored failregex using the
AI answers can be wrong. Read every command before you run it, and test on a non-production server first. Your input is sent to our AI provider (srvScripts AI) to write the answer. srvScripts does not log your input; the answer, which can quote it, is cached for 24 hours so a repeat question is answered instantly. See the privacy policy.
Table of Contents
Anchored patterns matter: a loose regex can ban your own monitoring or never match at all, and a greedy one can slow fail2ban down on busy logs.
How to use the fail2ban regex generator
- Paste three to ten sample log lines that should trigger a ban.
- Optionally set the ban policy and the log path.
- Press Generate filter, save the two files and run the fail2ban-regex test before reloading.
What you get
- filter.d/NAME.conf with failregex and a datepattern when needed.
- jail.d/NAME.local with maxretry, findtime, bantime and logpath.
- The fail2ban-regex test command and how to reload and check the jail.
- A plain PCRE version of the regex for other tools.
Worked example
Example: you paste Dovecot lines such as “auth failed, 1 attempts … rip=198.51.100.7”. The generator returns a filter anchored on the Dovecot prefix with rip=
Tips for better answers
- Include one line that should not match so the regex can be made precise.
- Pair bans with the AI firewall rule builder for permanent blocks.
Related guide: replace CSF with firewalld and fail2ban.
Privacy and limits
Before anything is sent, srvScripts removes private keys, passwords, tokens and API keys it recognises. With the box ticked it also swaps public IP addresses and e-mail addresses for placeholders, which lowers the risk when you paste real logs. The masking is automatic and best effort: it can miss names, hostnames, keys or other customer details, so remove anything confidential before you paste. Your text goes to our AI provider only to write the answer. srvScripts does not save your input as a record of its own, but the masked input is sent to the AI provider to produce the answer, and the answer, which can quote parts of your input, is cached on our server for 24 hours so a repeat question is answered instantly, and is then deleted. The provider’s own API data terms apply to what it receives. Without an account you get 5 runs a day, a free account gets 15 and srvScripts Pro 200, with larger inputs.
At a glance


Official documentation: fail2ban project, PCRE2 documentation and the journalctl manual.
Frequently asked questions
Does the fail2ban regex generator work with CSF or Imunify360 servers?
CSF and Imunify360 have their own login-failure detection; use fail2ban on servers where they are not installed to avoid double handling.
What is in failregex?
A fail2ban tag that captures the IP or hostname to ban. Every failregex needs it.
How do I test a filter?
Run fail2ban-regex against the real log file with the filter; it reports how many lines matched.