I'm having trouble capturing failed login attempts to my blueiris VM with haproxy. I'm using the pfSense version of haproxy and it is working perfectly for a jellyfin container and the blueiris VM. Unfortunately, the only thing that is being captured in the haproxy logs for failed connections to BI (bad passwords) is a code 200 which is considered "successful".
Example line from haproxy log for BI:
2025-11-30T22:43:10-05:00 haproxy haproxy[2131]: 999.999.999.999:4956 [30/Nov/2025:22:43:07.379] port-443~ blueiris_ipv4/blueiris 0/0/1/2651/2652 200 461 - - ---- 1/1/1/1/0 0/0 "POST HTTP/2.0"
Haproxy does show a 401 for failed logins to jellyfin:
2025-11-30T22:58:33-05:00 haproxy haproxy[2131]: 999.999.999.999:4957 [30/Nov/2025:22:58:33.596] port-443~ jellyfin_ipv4/jellyfin 0/0/1/2/3 401 213 - - ---- 1/1/0/0/0 0/0 "POST HTTP/2.0"
Is there a setting in BI to return a 401 or something other than 200 when an invalid login/password is detected? I know BI offers IP blocking but I would prefer to do all my IP blocking using fail2ban and pfsense/pfblockerng as as I have a centralized syslog server that gets all my logs and it makes sense to do everything there, if possible.
I am a unix guy and not too familiar with windows logging but if I could install a log server app on the BI server to send Windows syslogs to my syslog server, is there anything available in Windows syslogs that show a 401 for BI's webserver app? Thanks for your time!
Example line from haproxy log for BI:
2025-11-30T22:43:10-05:00 haproxy haproxy[2131]: 999.999.999.999:4956 [30/Nov/2025:22:43:07.379] port-443~ blueiris_ipv4/blueiris 0/0/1/2651/2652 200 461 - - ---- 1/1/1/1/0 0/0 "POST HTTP/2.0"
Haproxy does show a 401 for failed logins to jellyfin:
2025-11-30T22:58:33-05:00 haproxy haproxy[2131]: 999.999.999.999:4957 [30/Nov/2025:22:58:33.596] port-443~ jellyfin_ipv4/jellyfin 0/0/1/2/3 401 213 - - ---- 1/1/0/0/0 0/0 "POST HTTP/2.0"
Is there a setting in BI to return a 401 or something other than 200 when an invalid login/password is detected? I know BI offers IP blocking but I would prefer to do all my IP blocking using fail2ban and pfsense/pfblockerng as as I have a centralized syslog server that gets all my logs and it makes sense to do everything there, if possible.
I am a unix guy and not too familiar with windows logging but if I could install a log server app on the BI server to send Windows syslogs to my syslog server, is there anything available in Windows syslogs that show a 401 for BI's webserver app? Thanks for your time!
