[DEFAULT] bantime = 30m findtime = 10m maxretry = 5 backend = systemd # --- SSH brute force --- [sshd] enabled = true maxretry = 3 bantime = 1h # --- nginx basic-auth failures (from error.log) --- [nginx-http-auth] enabled = true logpath = /var/log/nginx/error.log maxretry = 5 # --- enable later if bot noise grows (stock filter, matches probe URIs) --- #[nginx-botsearch] #enabled = true #logpath = /var/log/nginx/access.log #port = http,https #maxretry = 20