Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prometheus does not read Fail2ban’s Unix socket directly. A Fail2ban exporter reads that socket and serves metrics over HTTP; Prometheus then scrapes the exporter. To find the break, check whether Prometheus has a target, whether it can reach the exporter’s /metrics endpoint, and whether the exporter can access the correct Fail2ban socket.

How Fail2ban metrics reach Prometheus

The data path has two separate connections:

  1. The exporter connects to Fail2ban through its Unix socket and collects information.
  2. Prometheus makes an HTTP request to the exporter, usually at /metrics.

A healthy Prometheus scrape only confirms that Prometheus received an HTTP response. The exporter may still be unable to read Fail2ban, so check both the scrape status and the exporter’s own output or logs. Exporter implementations differ in their collection method and metric names; use the documentation for the specific exporter and inspect its endpoint before building queries or alerts. The hctrdev exporter README documents metrics such as f2b_up, f2b_errors, f2b_jail_count, and per-jail ban and failure counts. The cfuk exporter README also documents a textfile mode.

Find where the scrape is failing

Start with Prometheus’s Targets status page. It distinguishes a target that was never loaded or discovered from one that exists but cannot be scraped. You can also inspect the targets API at /api/v1/targets; it reports active and dropped targets and labels after relabeling, as described in the Prometheus HTTP API documentation.

  • No target listed: Check that the scrape job is in the configuration Prometheus actually loaded, that its static target or service discovery is correct, and that relabeling has not dropped it.
  • Target is down: Read the target’s exact scrape error, then verify the address, scheme, port, path, listener, and network route.
  • Target is up, but Fail2ban metrics are missing: Fetch the endpoint’s response and examine exporter metrics and logs. The exporter may be serving HTTP successfully while failing to reach Fail2ban.

Test the exporter endpoint from Prometheus’s network

Request the exporter’s metrics endpoint from the Prometheus host or container, not only from your workstation or Docker host. For example, from an environment with access to the target, request http://fail2ban-exporter:9191/metrics if that is the address and port you configured. The hctrdev README’s example exporter listens on port 9191; your installed exporter may use a different port.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the request works on the host but fails from Prometheus, the issue is likely the address or network path. In a shared Docker network, the exporter service name may be reachable; from a host-installed exporter, Prometheus needs a host address it can route to. Choose an address that resolves and is reachable from Prometheus’s own deployment context.

Prometheus uses /metrics as the default metrics path. A 404 or an unexpected response can mean the path is wrong or the target points to another service rather than the exporter. A connection refusal or timeout instead points first to the listener, port, or route. Check the error shown for the target rather than treating all failures as the same problem.

Check the scrape job and apply changes

A basic static scrape job for an exporter reachable at fail2ban-exporter:9191 looks like this:

scrape_configs:
  - job_name: fail2ban
    static_configs:
      - targets: ['fail2ban-exporter:9191']

This uses Prometheus’s default /metrics path. Replace the example target with the host and port reachable from your Prometheus process. For configuration syntax and scrape options, see the Prometheus scrape configuration documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After editing the configuration, reload it using SIGHUP or the /-/reload endpoint if Prometheus was started with the lifecycle flag enabled. If the configuration is malformed, Prometheus does not apply it. The Prometheus management API documentation describes reload behavior. Revisit Targets to confirm the job and target are present and healthy, then query a metric that the selected exporter actually exposes.

Fix exporter-to-Fail2ban socket errors

If the exporter reports socket errors, verify the socket path it is configured to use and whether the exporter process can access it. A “no such file or directory” error can result from a wrong path or, in Docker, a host-directory mount that does not put the socket where the exporter expects it. If the socket exists at the expected path, check the process’s permissions.

The hctrdev README recommends mounting the socket’s parent directory rather than mounting only fail2ban.sock: Fail2ban can delete and recreate the socket during shutdown and startup, leaving a direct file mount stale. Ensure the exporter’s configured socket path matches the path visible inside its container. The README discusses giving the exporter appropriate access, changing the Fail2ban service user, or relaxing socket permissions; choose an approach that fits your security requirements. It also notes that permissions can revert when Fail2ban recreates the socket after restart.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose an exporter that fits your setup

Exporter choice affects how data is collected and what you need to troubleshoot. A standalone HTTP exporter reads the Fail2ban socket and exposes metrics for Prometheus to scrape. A textfile-capable approach writes metrics for collection through a textfile workflow instead. Compare the project’s documented collection mode, deployment and mount requirements, access controls, metric names, and compatibility with the release you intend to run. The available project documentation does not establish one implementation as the best choice for every environment.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.