<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Airat</title>
    <description>The latest articles on DEV Community by Airat (@airat71).</description>
    <link>https://dev.to/airat71</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4159937%2F1d9b076b-9692-4e30-aef4-29382e3d5d11.png</url>
      <title>DEV Community: Airat</title>
      <link>https://dev.to/airat71</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/airat71"/>
    <language>en</language>
    <item>
      <title>See who's attacking your server in Grafana — fail2ban metrics with Prometheus</title>
      <dc:creator>Airat</dc:creator>
      <pubDate>Sat, 03 Oct 2026 14:45:12 +0000</pubDate>
      <link>https://dev.to/airat71/see-whos-attacking-your-server-in-grafana-fail2ban-metrics-with-prometheus-2d7a</link>
      <guid>https://dev.to/airat71/see-whos-attacking-your-server-in-grafana-fail2ban-metrics-with-prometheus-2d7a</guid>
      <description>&lt;p&gt;Most people set up fail2ban and forget about it. It's running, it's banning IPs, but you have no&lt;br&gt;
  idea what's actually happening unless you SSH in and check the logs manually.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F34r4t6il4w3mw51tipqv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F34r4t6il4w3mw51tipqv.png" alt="fail2ban dashboard in Grafana" width="800" height="441"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This post shows how to add fail2ban metrics to your Prometheus stack and visualize them in Grafana&lt;br&gt;
   — so you see ban activity on the same dashboard as CPU, memory, and disk.&lt;/p&gt;

&lt;p&gt;## What you'll see&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Active bans per jail in real time&lt;/li&gt;
&lt;li&gt;Total banned IPs over time&lt;/li&gt;
&lt;li&gt;Which jails are firing most — SSH? Nginx? Recidive?&lt;/li&gt;
&lt;li&gt;Ban spikes correlated with traffic and load&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;## Step 1 — Add the exporter&lt;/p&gt;

&lt;p&gt;fail2ban doesn't expose Prometheus metrics natively. Add&lt;br&gt;
  &lt;a href="https://github.com/braedon/prometheus-fail2ban-exporter" rel="noopener noreferrer"&gt;fail2ban-exporter&lt;/a&gt; to your&lt;br&gt;
  &lt;code&gt;docker-compose.yml&lt;/code&gt;:&lt;/p&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;
yaml
  fail2ban-exporter:
    image: braedon/prometheus-fail2ban-exporter:latest
    volumes:
      - /var/run/fail2ban/fail2ban.sock:/var/run/fail2ban/fail2ban.sock:ro
    ports:
      - "9191:9191"
    restart: unless-stopped

  The exporter reads fail2ban's Unix socket and exposes /metrics on port 9191.

  Step 2 — Add a scrape job to Prometheus

  In prometheus.yml:

  - job_name: 'fail2ban'
    static_configs:
      - targets: ['fail2ban-exporter:9191']

  Restart Prometheus. You should now see metrics like fail2ban_banned_ips and fail2ban_enabled_jails
   in the Prometheus UI.

  Step 3 — Add an alert rule

  The useful one — fires when more than 10 IPs get banned in 5 minutes on any jail:

  - alert: Fail2BanHighBanRate
    expr: increase(fail2ban_banned_ips_total[5m]) &amp;gt; 10
    for: 0m
    annotations:
      summary: "High ban rate — jail {{ $labels.jail }}"

  This catches coordinated brute-force attempts before they become a problem.

  Step 4 — Import the Grafana dashboard

  Download the fail2ban dashboard JSON from the monitoring-stack repo (grafana-dashboards/json/) and
   import it in Grafana via Dashboards → Import.

  The full repo also includes a one-command Ansible deployment for the entire stack — Prometheus,
  Grafana, Alertmanager, Node Exporter, Blackbox Exporter — if you want to set everything up at once
   rather than piece by piece.

  Why bother?

  The first time I saw a ban spike in Grafana — 40 IPs banned in under 2 minutes at 3am — I realized
   I had zero visibility into this before. It was happening, I just couldn't see it.

  Correlating ban events with CPU and network in one view makes it obvious when something is
  actually an attack versus a misconfigured client.

  ---
  Repo: github.com/Airat71/monitoring-stack
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

</description>
      <category>devops</category>
      <category>prometheus</category>
      <category>grafana</category>
      <category>linux</category>
    </item>
  </channel>
</rss>
