# Add the reporter as a SECOND action. Keep your existing %(action_)s or custom banaction. [sshd] enabled = true action = %(action_)s blocklist-report[category=ssh_bruteforce,services="tcp:22"] # Example for a typical Apache authentication jail. Reuse the filter/logpath # already provided by your distribution rather than copying brittle regexes. [apache-auth] enabled = true action = %(action_)s blocklist-report[category=credential_stuffing,services="tcp:80,tcp:443"] # Asterisk SIP example; actual jail/filter/log path vary by deployment. [asterisk] enabled = true action = %(action_)s blocklist-report[category=credential_stuffing,services="udp:5060,tcp:5060,tcp:5061"] [postfix-sasl] enabled = true action = %(action_)s blocklist-report[category=credential_stuffing,services="tcp:25,tcp:465,tcp:587"] [dovecot] enabled = true action = %(action_)s blocklist-report[category=credential_stuffing,services="tcp:110,tcp:143,tcp:993,tcp:995"]