[Definition]
failregex = ^(?:error: PAM: )?[A|a]uthentication failure for .* from <HOST>\s*$
ignoreregex =
[sshd]
enabled = true
port = 22
filter = sshd
logpath = /var/log/auth.log
maxretry = 8
findtime = 1d
bantime = 30d
# Will lock for 30 days after 8 attemps in 24h