See what data patterns fail2ban is using. Run fail2ban-regex
(change for your log file and filter) with the -v switch:
fail2ban-regex -v /var/log/httpd/access_log
/etc/fail2ban/filter.d/my_apache_access.conf
I have a server using version0.9.3 which gives:
Date template hits:
|- [# of hits] date
- Fail2Ban version (including any possible distribution suffixes): Fail2ban
v0.9.3
- OS, including release name/version: Ubuntu 16.04.3 LTS
- [X] Fail2Ban installed via OS/distribution mechanisms
- [X] You have not applied any additional foreign patches to the codebase
- [ ] Some customizations we