icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Fail2ban
SHA256 checksum (fail2ban_30.tgz) 3e4a84e8673d339a97125342b9eb5ad4c3ed2686f909068262bf8cd1067b10a6 SHA256 checksum (fail2ban_204.tgz) fb5e9b1eed41496fbd4bf9432f64be4bc83aec72cc7c9b68792fa3dc2468e6c8 SHA256 checksum (fail2ban_203.tgz) 1f6333ccdca31c6e3a0480720ecf729a2b7d161fc4b12db42c17ef1d2abc6088 SHA256 checksum (fail2ban_202.tgz) 4f5043162a9c01c95752b450cbed38032aacf41ce08e0b13933cad9fd677a96b SHA256 checksum (fail2ban_201.tgz) 9493f967fae6c2084b34b54bf521d148e95b1bb406bdb565bc94d6942c826dba SHA256 checksum (fail2ban_20.tgz) ce43128997d64c3bbe36dbce2e9d44220b15c74eb7e29b3bba90aec5b9a6b1c1 SHA256 checksum (fail2ban_13.tgz) d7cb166d1dc3cf498e20951d85c23e835572aac6a956f7f2eb902cbab2d474ca
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Fail2ban

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Fail2ban provides field extractions for Fail2ban events (Multi-Host supported) with overview Dashboards, Google Maps views, saved searches and dedicated event search interface

Full installation and use guides are available in:

  • My blog dedicated post, includes details steps and screenshots: 1
  • README.txt file under the application root directory
  • Main menu under the application "About Splunk For Fail2ban" / "Installation / Use guide - Splunk for Fail2ban"

This app is maintained by Guilhem Marchand (see author). Suggestions and bug reports are appreciated.


Please note you need some Splunk addons:
- Sideview utils addon - V2
- Google Maps addon
- Maxmind geo location addon


Functional Overview

You will need to create appropriate dedicated index and apply required input to begin analyzing Fail2ban events reporting.
Also, some configurations steps are required to be able to use this application, please installation guides above

Functionalities

Main functionalities:

  • Multi-Host supported: This application can manage as many Fail2ban host as required
  • Fail2ban can be installed locally on same server, or any remote server
  • Using centralized Syslog or Splunk forwarders is required in a Multi-Host environnement
  • Main overview Dashboards with Time Range selection, dashboards with pre-set time ranges are provided for more convenience
  • Google Maps view of country origin IP
  • Dedicated search interface
  • Saved searches

Fail2ban events fiels extractions

Following field are being extracted from Fail2ban events:

  • id = Unique ID applied to every Fail2ban event
  • srcip = Denied host IP
  • fail2ban_host = Reporting Fail2ban host
  • jailname = Jail name reported for every denied event
  • number_of_failures = Number of failures for every denied event
  • message = content of event message (not yet exploited)

Full installation and use Guides

Full installation and use guides are available in:

Splunk application Installation Overview

To install, extract the .spl file in $SPLUNK_HOME/etc/apps

Configuration

To get all this working, you have several steps to proceed:

Fail2ban / Syslog Configurations steps:

  1. Set each fail2ban host to log events using SYSLOG
  2. Modify each faiL2ban host default action (eg. ban host action) to send log messages with required fields to SYSLOG
  3. Configure SYSLOG to trap these events and put them in a dedicated log file of your choice
  4. Test your fail2ban / Syslog configuration to ensure events are being sucessfully trapped by your centralized Syslog
  5. Create a new dedicated index for Fail2ban called "index_fail2ban"
  6. Add the Input source log file in Splunk corresponding to the log file where your Syslog is trapping events
  7. Open Splunk for Failban and observe the magical power of Splunk ^^

Release Notes

Version 3.0
Oct. 12, 2013
  • Splunk 6.x compatibility
  • css update
Version 2.04
June 14, 2013

V2.04:
- Corrected Event Search Interface

V2.03:
- Home page Realtime window change
- Minor corrections

V2.02:
- Code cleaning
- Views improvement
- Hide info message when subsearches running in realtime

V2.01:
- Added System Dashboard
- Correction in event search interface
- Other smalls corrections and screenshot place change in views

V2.0:

Version 2.0, interfaces have been fully rewrited:
- Home page with Realtime Overview summary and centralized links to other interfaces
- Rewritten Activity Overview interface
- Added support to stats and chart attempted connect username (SSH wrong user and invalid user)

Version 2.03
June 13, 2013

V2.03:
- Home page Realtime window change
- Minor corrections

V2.02:
- Code cleaning
- Views improvement
- Hide info message when subsearches running in realtime

V2.01:
- Added System Dashboard
- Correction in event search interface
- Other smalls corrections and screenshot place change in views

V2.0:

Version 2.0, interfaces have been fully rewrited:
- Home page with Realtime Overview summary and centralized links to other interfaces
- Rewritten Activity Overview interface
- Added support to stats and chart attempted connect username (SSH wrong user and invalid user)

Version 2.02
June 9, 2013

release notes:

V2.02:
- Code cleaning
- Views improvement
- Hide info message when subsearches running in realtime

V2.01:
- Added System Dashboard
- Correction in event search interface
- Other smalls corrections and screenshot place change in views

V2.0:

Version 2.0, interfaces have been fully rewrited:
- Home page with Realtime Overview summary and centralized links to other interfaces
- Rewritten Activity Overview interface
- Added support to stats and chart attempted connect username (SSH wrong user and invalid user)

Version 2.01
June 4, 2013

V2.01:
- Added System Dashboard
- Correction in event search interface
- Other smalls corrections and screenshot place change in views

V2.0:

Version 2.0, interfaces have been fully rewrited:
- Home page with Realtime Overview summary and centralized links to other interfaces
- Rewritten Activity Overview interface
- Added support to stats and chart attempted connect username (SSH wrong user and invalid user)

Version 2.0
May 11, 2013

Version 2.0, interfaces have been fully rewrited:
- Home page with Realtime Overview summary and centralized links to other interfaces
- Rewritten Activity Overview interface
- Added support to stats and chart attempted connect username (SSH wrong user and invalid user)

Version 1.3
Jan. 31, 2013
  • Added config samples for Fail2ban

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.