> is that correct, that attacker logins (GUI) are logged in the > /var/log/daemon.log? > This is defined in your wiki for the fail2ban - filter - I mean this > cant been correct! What do you think is wrong?