【问题标题】:fail2ban datepattern regexfail2ban 日期模式正则表达式
【发布时间】:2019-06-14 14:34:37
【问题描述】:

我正在尝试在 fail2ban 中匹配此日期模式:

test.example.org 12.100.3.45 - - [14/Jun/2019:13:54:50 +0000] "GET

可以使用正则表达式测试器:

fail2ban-regex -d ^%%d/%%M/%%Y:%%H:%%M:%%S "test.example.org [14/Jun/2019:13:22:57 +0000] 1.2.3.4" "<HOST>"

我希望找到 ip 地址,但找不到日期模式。

Running tests
=============

Use      datepattern : {^%d/%M/%Y:%H:%M:%S}
Use   failregex line : <HOST>
Use      single line : test.example.org [14/Jun/2019:13:22:57 +0000] 1.2.3.4


Results
=======

Failregex: 0 total

Ignoreregex: 0 total

Date template hits:

Lines: 1 lines, 0 ignored, 0 matched, 1 missed
[processed in 0.00 sec]

|- Missed line(s):
|  test.example.org [14/Jun/2019:13:22:57 +0000] 1.2.3.4

更新:

我使用 my.conf 文件:

# fail2ban filter configuration for nginx proxy
# hk

[Definition]


failregex = ^<HOST> - [^-[ ]+.+HTTP/1.[0-9]" 401

ignoreregex =

datepattern = ^%%d/%%M/%%Y:%%H:%%M:%%S

当使用这样的日期模式时,我在正则表达式解析器中遇到错误。

我理解 fail2ban 的工作方式是采用 datepattern 并将其转换为查找日期的正则表达式。那么日期模式不是有效的吗?我相信正则表达式(正如肖恩在 cmets 中指出的那样)。

Running tests
=============

Use   failregex filter file : nginx-proxy-auth, basedir: /etc/fail2ban
Use      datepattern : ^Day/Minute/Year:24hour:Minute:Second
Use         log file : /data/docker/nginx-proxy/logs/access.log
Use         encoding : UTF-8

Traceback (most recent call last):
  File "/usr/bin/fail2ban-regex", line 34, in <module>
    exec_command_line()
  File "/usr/lib/python3/dist-packages/fail2ban/client/fail2banregex.py", line 685, in exec_command_line
    if not fail2banRegex.start(args):
  File "/usr/lib/python3/dist-packages/fail2ban/client/fail2banregex.py", line 635, in start
    self.process(test_lines)
  File "/usr/lib/python3/dist-packages/fail2ban/client/fail2banregex.py", line 458, in process
    line_datetimestripped, ret = self.testRegex(line)
  File "/usr/lib/python3/dist-packages/fail2ban/client/fail2banregex.py", line 409, in testRegex
    ret = self._filter.processLine(line, date)
  File "/usr/lib/python3/dist-packages/fail2ban/server/filter.py", line 526, in processLine
    (timeMatch, template) = self.dateDetector.matchTime(l)
  File "/usr/lib/python3/dist-packages/fail2ban/server/datedetector.py", line 373, in matchTime
    match = template.matchDate(line)
  File "/usr/lib/python3/dist-packages/fail2ban/server/datetemplate.py", line 153, in matchDate
    self._compileRegex()
  File "/usr/lib/python3/dist-packages/fail2ban/server/datetemplate.py", line 147, in _compileRegex
    raise e
  File "/usr/lib/python3/dist-packages/fail2ban/server/datetemplate.py", line 144, in _compileRegex
    self._cRegex = re.compile(self.regex)
  File "/usr/lib/python3.6/re.py", line 233, in compile
    return _compile(pattern, flags)
  File "/usr/lib/python3.6/re.py", line 301, in _compile
    p = sre_compile.compile(pattern, flags)
  File "/usr/lib/python3.6/sre_compile.py", line 562, in compile
    p = sre_parse.parse(p, flags)
  File "/usr/lib/python3.6/sre_parse.py", line 855, in parse
    p = _parse_sub(source, pattern, flags & SRE_FLAG_VERBOSE, 0)
  File "/usr/lib/python3.6/sre_parse.py", line 416, in _parse_sub
    not nested and not items))
  File "/usr/lib/python3.6/sre_parse.py", line 765, in _parse
    p = _parse_sub(source, state, sub_verbose, nested + 1)
  File "/usr/lib/python3.6/sre_parse.py", line 416, in _parse_sub
    not nested and not items))
  File "/usr/lib/python3.6/sre_parse.py", line 759, in _parse
    raise source.error(err.msg, len(name) + 1) from None
sre_constants.error: redefinition of group name 'M' as group 6; was group 3 at position 107

所以这个模式试图找到minutes而不是Months

【问题讨论】:

  • 这不是正则表达式
  • 我遇到了同样的问题,首先要注意的是 ^ 符号将日期时间锚定到字符串的开头,这在您的情况下无效,因此您应该删除^.

标签: regex fail2ban


【解决方案1】:

在fail2ban 日期模式中,M 匹配分钟,如所示。如果要匹配数字月份,请使用m;如果要匹配三字母缩写,请使用b。

您也可以将 nanos 与 %f 匹配,但 + 需要转义。

所以日期模式无效?正则表达式

datepattern 是一个有效的正则表达式,它只是匹配了错误的东西。但是我认为你的失败正则表达式也太模糊了("&lt;HOST&gt;" 只会匹配文字"1.2.3.4")。它需要类似于 ".*&lt;HOST&gt;" 或 "&lt;HOST&gt;$" 才能知道在哪里寻找 IP。

因此,将所有这些放在一起以匹配您的预期模式,您可以使用:

fail2ban-regex -d "%d/%b/%Y:%H:%M:%S \+%f" "test.example.org [14/Jun/2019:13:22:57 +0000] 1.2.3.4" "^.*<HOST>"

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2017-05-13
    相关资源
    最近更新 更多