Hello all, i want to protect the admin panel from ISPConfig. I found the log file is: /var/log/ispconfig/auth.log Here are sample output: Successful login for user 'admin' from 5.62.6.182 at 2013-11-20 21:35:10 Successful login for user 'admin' from 7.7.3.133 at 2013-12-07 19:36:06 Failed login for user 'testuser100' from 9.100.1.22 at 2013-12-08 13:10:24 Can me someone give a regex to match the failed logins for the filter?