Hi guys!!! First of all english is no my language so... sorry if I have errors in my text. I have a standalone server that until yesterday was runing debian 8 and ISPConfig 3.1.12 (Too old... I know) Yesterday I've updated it to Debian 9 and ISPconfig 3.1.15p3. With the debian update I had to remove and install again fail2fan to make things works again. Before the update my fail2ban logs looked like: And I understood the data on it but now they looks like this: And I'm not sure how to read this information. I've went to to the fail2fan page but I can't find this kind of data on it.
Those info lines tell you that the jail (either 'sasl' or 'dovecot' in your examples) matched and shows you the ip address it found. When the same ip has been found enough times to trigger a ban, you will also see a Ban line like the example from your old log shows.