Fail2ban does not provide a built-in Prometheus alerting workflow. To alert on bans and jail status, expose Fail2ban state as metrics with an exporter or a Node Exporter textfile script, scrape those metrics with Prometheus, and define alerting rules. Prometheus evaluates the rules; Alertmanager routes and manages notifications.
Check Fail2ban status before configuring metrics
Use the Fail2ban client to see what state you need to monitor:
fail2ban-client statusshows server status.fail2ban-client status --allshows status for all jails.fail2ban-client status <JAIL>shows status for one jail, such assshd.
These commands are documented in the Fail2ban client manual. Its current page identifies Fail2Ban v1.1.2.dev1; confirm command syntax against the version installed on your host.
Expose jail state as Prometheus metrics
Fail2ban status output is not itself a Prometheus metric endpoint. Choose a bridge, then verify its supported Fail2ban version, permissions, metric names, and maintenance status before deploying it. The projects below are community implementations, not built-in Fail2ban integrations.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- Mega Heat Sink - Black Anodized
| Approach | Collection path | What to check |
|---|---|---|
| hctrdev exporter | Exporter exposes Fail2ban metrics for Prometheus to scrape. | Its documentation describes jail metrics and exporter health/error metrics. Check its current deployment instructions and exact names. |
| jangrewe textfile script | Script invokes Fail2ban and writes metrics for Node Exporter’s textfile collector. | Manage script execution and stale output; confirm the collector directory and required access. |
| mivek exporter | Separate exporter provides an HTTP endpoint. | Its README documents current and total bans and failures by jail, active jail count, a default port of 9921, and an example read-only Fail2ban socket mount. Verify all details against the current project version. |
For general guidance on integrations, see Prometheus’s exporter documentation. Compare the options by how they access Fail2ban (socket, client command, or mounted files), required privileges, process supervision, scrape health, stale-file behavior, and metric semantics.
Understand the metrics before writing rules
The hctrdev project documents metrics with the f2b_ prefix, including f2b_up, exporter errors, jail count, per-jail current and total bans, current and total failures, configuration values, and version information. These names belong to that exporter; they are not Fail2ban built-ins.
Rank #2
- Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
- Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
- CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
- CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
- CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)
In that project, jail_banned_total includes expired bans. Treat it as a cumulative total, not as the number of currently banned addresses. Use the exporter’s current-ban gauge to alert on active bans, and a counter-based query to detect new bans over time. Confirm the selected exporter’s definitions, labels, and reset behavior before adapting these examples.
Configure Prometheus to scrape the exporter
Add the exporter endpoint as a scrape target using the address and port from the chosen project’s current deployment instructions. For example, the mivek README documents port 9921 by default, but that is a project-specific default rather than a Fail2ban or Prometheus standard. After applying your Prometheus configuration, check the target in the Prometheus UI under Status → Targets. It should show as up before you rely on its metrics for alerts.
Rank #3
- Design for Raspberry Pi: Supports installation of 4 Raspberry Pis and 4 ssds, compatible with any 2.5” Solid State Drive (7mm/9mm) and Rpi 4B/3B+, and other B/B+ models.
- The SSD mounting bracket also has two holes reserved for the SD card extension adapter ASIN: B09CKRDFTH, which allows you to access the SD card from the front of the rack.
- Easy to Setup: Just use two included thumbscrews to mount the rackmount, which adopts a screw-in design, which helps you install and replace quickly and easily, no tools needed!
- Applications: This is a hardware solution to get ingenious use of the Raspberry Pi, with this kit and open source software OpenMediaVault, you can use the Pi as a NAS Server, Surveillance station, or even a Web server.
- Optional accessories: Single mounting bracket: B09GFQLPTY; Micro SD card extension adapter ASIN: B09CKRDFTH. I/O Panel: B09FXRQPFM
For a textfile-collector approach, Prometheus scrapes Node Exporter rather than the script directly. Ensure the script writes into the directory configured for Node Exporter’s textfile collector, and consider how you will detect old metric files: an outdated file can continue to look like valid state if the script stops running.
Write alerts for bans, jail coverage, and collection failure
Prometheus alerting rules evaluate PromQL expressions. A matching vector element becomes an alert instance with its labels. A for duration keeps an alert pending until the condition remains true for that long; keep_firing_for can retain a firing alert after the expression stops matching. Choose thresholds and durations for your environment rather than treating any example as universal. See the Prometheus alerting-rules documentation.
Rank #4
- [ULTIMATE RASPBERRY PI 5 CASE & MINI PC] - Unlock the full potential of your Raspberry Pi 5 with the Pironman 5-MAX — the most advanced Raspberry Pi 5 Case for power users. This high-performance Raspberry Pi 5 Cooling Case features dual NVMe M.2 slots with RAID 0/1 support, AI accelerator compatibility ( e.g. Hailo-8l M.2 AI), a PCIe Gen2 switch, a PWM tower cooler + dual RGB fans and a smart OLED display. With its dual transparent panels and optimized cable management (including full-size HDMI), it’s the ideal Raspberry Pi 5 Enclosure for building a high-speed NAS, AI edge computing device, or Home Assistant hub. (Raspberry Pi NOT Included)
- [DUAL NVMe M.2 SLITS & NAS RAID SUPPORT] - Supercharge your storage with the best Raspberry Pi 5 NVMe Case solution. Featuring two expandable NVMe M.2 slots (2230-2280) powered by a built-in PCIe Gen2 switch, this Raspberry Pi 5 NAS Case supports RAID 0/1 for ultra-fast data setups. Whether you're using a high-speed NVMe SSD or a Hailo-8L AI accelerator, Pironman 5-MAX delivers the ultimate performance boost for advanced Raspberry Pi 5 AI applications and edge computing
- [ADVANCED COOLING SYSTEM] - Engineered for high-performance builds, Pironman 5-MAX features a powerful tower cooler, one PWM fan, and dual RGB fans for enhanced airflow. The dual transparent panel design improves ventilation while showcasing vibrant RGB lighting. Ideal for cooling both the Raspberry Pi 5 and dual NVMe SSDs or AI accelerators like Hailo-8L, it ensures stable operation under heavy workloads with low noise and long-term durability
- [SMART OLED DISPLAY WITH VIBRATION WAKE-UP] - Pironman 5-MAX features a 0.96" OLED screen that delivers real-time system insights including CPU usage, memory, temperature, IP address, and disk status. With customizable display options and auto sleep mode, the screen can be instantly reactivated by a light tap thanks to the built-in vibration sensor—offering a smarter and more interactive experience
- [ENHANCED FUNCTIONALITY] - Pironman 5-MAX empowers your Raspberry Pi 5 with advanced features like safe shutdown via a metal power button, customizable RGB lighting, dual full-size HDMI ports, vibration-triggered OLED wake-up, and an external GPIO extender. It also includes RTC battery support for timekeeping and seamless Home Assistant integration. With detailed guides, online tutorials, and full technical support from SunFounder, setup and use are effortless and worry-free
Alert on active bans or new bans
Use the chosen exporter’s current-ban gauge for a jail when active bans themselves need attention. Set a threshold that reflects your operational policy and use for to avoid paging on a brief blip if that is appropriate.
For ban activity over a time window, use a counter increase query rather than the active-ban gauge. The counter answers whether new bans have occurred; it does not answer how many bans are active now. Check the exporter’s counter semantics and how it behaves on process restarts before relying on the result.
Recommended Free Tools
Alert when metrics disappear or fail
Create a separate alert for scrape or exporter failure. Depending on the implementation, this can use Prometheus target health, the exporter’s own up metric (such as f2b_up where documented), or its documented error metric. Verify the actual metric and labels in your Prometheus expression browser. Do not interpret missing metrics as zero bans: missing data can mean that collection has stopped.
Check that expected jails are present
If particular jails must be monitored, check for those jails explicitly using the labels your exporter exposes. A jail count alone does not prove that every expected jail is being reported, unless the chosen exporter defines that count in a way that meets your coverage requirement.
Attach useful context to alerts
Give alerts a severity and annotations that identify the affected instance and jail, explain the condition, and point to a runbook. Keep rules simple and actionable, consistent with Prometheus alerting practices. Those practices also recommend external blackbox monitoring: a separate check of the monitoring or notification path can reveal failures that an alert relying on that same path cannot.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Send notifications through Alertmanager
Prometheus evaluates alert rules and sends resulting alerts to Alertmanager. Alertmanager handles notification concerns such as grouping, routing, silences, inhibition, and rate limiting; configure its routes and receivers for the people or systems that should receive each alert. The Prometheus alerting overview describes this division of responsibility. Prometheus and Alertmanager do not prescribe a universal Fail2ban threshold or notification destination.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

