Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To monitor Fail2ban in Grafana, expose its jail metrics to Prometheus, then use Grafana’s Prometheus data source to query and chart the series. The most direct option is a dedicated exporter that reads Fail2ban’s server socket; if Node Exporter’s textfile collector is already part of your setup, a script that writes a .prom file may fit better.

Choose how to expose Fail2ban metrics

Prometheus scrapes metrics from an endpoint, while Grafana queries Prometheus. Fail2ban does not need to be instrumented directly: an exporter can translate data from the Fail2ban server socket into Prometheus metrics. The Prometheus documentation describes exporters as a common way to expose metrics from third-party systems that do not instrument Prometheus directly. It also cautions: “We encourage the creation of more exporters but cannot vet all of them for best practices.” See Prometheus exporters and integrations before choosing a community project for production.

Consideration Dedicated socket exporter Node Exporter textfile script
How it collects Reads the Fail2ban server socket and serves an HTTP metrics endpoint. Runs fail2ban-client and writes metrics to a .prom file for Node Exporter.
Best fit A standalone exporter deployment; the hctrdev project also documents a sample Grafana dashboard. An existing Node Exporter textfile-collector workflow and a suitable periodic script schedule.
Operational dependency Exporter process or container, socket path, and socket permissions. Script schedule, command permissions, output path, and valid Prometheus text format.
Example metric names f2b_-prefixed metrics, such as f2b_jail_banned_current. fail2ban_-prefixed metrics, such as fail2ban_banned_current.

The hctrdev project documents both a standalone binary and a container deployment. Its quick start uses /var/run/fail2ban/fail2ban.sock and port 9191; treat these as project defaults, not guaranteed paths or ports on every host. The project documents its metrics and sample dashboard at hctrdev/fail2ban-prometheus-exporter.

The jangrewe textfile script collects current and total failures and bans. By default, it writes to /var/lib/prometheus/node-exporter/fail2ban.prom; it can collect all enabled jails or a specified jail and accepts a custom output file. This avoids a separate exporter HTTP service, but the scheduled script must run successfully and write valid metrics where Node Exporter can read them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Deploy the dedicated exporter

Check the socket path and permissions

Confirm where Fail2ban creates its server socket and configure the exporter to use that path. A missing-socket error can mean the path is wrong or the socket is not mounted into the exporter. A permission error can occur because Fail2ban commonly runs as root and restricts socket access to that user. Prefer a deliberate service-user arrangement with only the access the exporter needs; do not casually make the socket broadly readable or writable.

For Docker, mount the socket’s parent directory

The hctrdev project recommends mounting /var/run/fail2ban, rather than binding only the socket file. Fail2ban deletes and recreates its socket when it stops and starts, so a file-only bind can become stale. Its sample uses a read-only directory mount and maps exporter port 9191. Review the image source and select a pinned release tag when you need reproducible deployments instead of assuming a moving latest tag is stable.

Keep the endpoint private

Allow access to the exporter endpoint only from Prometheus or a trusted monitoring network unless you have configured appropriate authentication and access controls. The hctrdev exporter documents optional basic authentication. Review the exporter’s maintenance, source, release process, permissions, and container image provenance before relying on it.

Configure Prometheus to scrape the exporter

Add the exporter’s reachable host and port as a scrape target in your Prometheus configuration. The following is an example target; use the actual address and port for your deployment:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
scrape_configs:
  - job_name: "fail2ban"
    static_configs:
      - targets: ["fail2ban-exporter-host:9191"]

Apply the configuration using the reload or restart procedure supported by your installed Prometheus version and service manager; the right procedure depends on how Prometheus is deployed. Then check the exporter’s /metrics endpoint and verify in Prometheus that the target is healthy before building dashboard panels.

Verify the metrics before writing queries

The hctrdev exporter documents series for exporter health and errors, jail count, current and total banned IPs, current and total failures, jail configuration, and version. Inspect the actual /metrics output for your installed exporter and use those exact names and labels. Do not copy queries intended for the textfile script: the projects use different prefixes and may define similar-looking values differently.

In particular, check each metric’s type and reset behavior before choosing PromQL functions. The hctrdev documentation distinguishes current values from totals since Fail2ban startup. The jangrewe example labels its totals as gauges, so a metric name containing total is not, by itself, proof that Prometheus should treat it as a counter.

Connect Grafana to Prometheus

  1. In Grafana, add a Prometheus data source and enter the URL that Grafana can use to reach your Prometheus server.
  2. Test the connection using Grafana’s data-source controls.
  3. Use Grafana’s query editor to select series discovered from the exporter’s /metrics output. Start with a single series and confirm the query returns data before adding filters or transformations.

Grafana documents Prometheus as a preinstalled data source that supports PromQL, visualization, and alerting. Consult its Prometheus data source documentation for the current interface and configuration details.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build a useful Fail2ban dashboard

Choose panels based on the exact series your exporter emits and the operational questions you need to answer:

  • Current banned IPs by jail: a snapshot of active bans.
  • Total bans and failures by jail: activity context over time, interpreted according to the metric type and reset behavior.
  • Current failures by jail: a view of recent or ongoing activity as represented by the exporter.
  • Exporter and scrape health: exporter health/error series alongside Prometheus target health, so collection failures are visible too.
  • Jail configuration: values such as ban time, find time, and maximum retries when that context helps explain activity.

The hctrdev project includes a sample Grafana dashboard, supports multiple exporters through an instance variable, and states compatibility with Grafana 9.1.8 and above. Check its imported queries against your installed Grafana version and the metric names emitted by your chosen exporter. A dashboard cannot compensate for a different metric schema.

Troubleshoot missing or empty data

  • Exporter reports a missing socket: check the socket’s actual host path and, for Docker, whether the correct parent directory is mounted.
  • Exporter cannot access the socket: review the socket owner and permissions, then arrange access for the exporter’s service user. The project describes running the exporter as the same user as Fail2ban as a simple option; manual permission changes may be temporary because restarts recreate the socket.
  • Prometheus target is unhealthy: confirm the exporter process is running, the configured target address and port are reachable from Prometheus, and the endpoint responds at /metrics.
  • Target is healthy but a panel is empty: inspect the endpoint’s current metric names and labels, then adjust the query. Dedicated-exporter f2b_ names and textfile fail2ban_ names are not interchangeable.
  • Textfile metrics are absent: check that the script runs, writes to the textfile collector’s configured directory, and produces a valid Prometheus text-format file. The hctrdev exporter documentation says its textfile collector reads files ending in .prom; do not assume another collector has the same behavior without checking its configuration.

Keep Grafana protection separate from metrics export

Fail2ban upstream configuration includes a [grafana] jail example that watches Grafana’s log file. That is an optional way to protect a Grafana service; it is separate from exposing Fail2ban metrics to Prometheus and is not required for monitoring. See the Fail2ban jail configuration for the example and adapt it to the logs and setup you actually use.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.