---
title: 'lfd:loginfailurecustomtriggers'
url: 'https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-loginfailurecustomtriggers'
markdown: 'https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-loginfailurecustomtriggers.md'
date: '2026-09-24'
description: 'Configure custom regex matching patterns for use by the login failure daemon. juggernaut --task=lfd:loginfailurecustomtriggers --oper=<trigger_add|trigger_edit|trigger_del> --name=<string> Option Value Description --oper <string> The operation you want to perform. Operations: …'
taxonomy:
  category:
    - docs
  tag:
    - login_failure_blocking
---

[](#)  [ Basics ](https://docs.danami.com/juggernaut/)     [ Command Line Interface ](https://docs.danami.com/juggernaut/command-line-interface)      Lfd       lfd:loginfailurecustomtriggers    

# lfd:loginfailurecustomtriggers

Configure custom regex matching patterns for use by the login failure daemon.

```
juggernaut --task=lfd:loginfailurecustomtriggers --oper=<trigger_add|trigger_edit|trigger_del> --name=<string>
```

| Option | Value | Description |
|---|---|---|
| `--oper` | <string> | The operation you want to perform. Operations: trigger\_add, trigger\_edit, trigger\_del |
| `--name` | <string> | A unique identifier for this custom rule. It must be alphanumeric and have no spaces. |
| `--log_file` | <string> | The log file that needs to be scanned for log line matches. Log files: HTACCESS\_LOG, MODSEC\_LOG, SSHD\_LOG, SU\_LOG, FTPD\_LOG, SMTPAUTH\_LOG, POP3D\_LOG, IMAPD\_LOG, IPTABLES\_LOG, SUHOSIN\_LOG, BIND\_LOG, SYSLOG\_LOG, CUSTOM1\_LOG-CUSTOM9\_LOG |
| `--message` | <yes> | Text for custom failure message. |
| `--patterns` | <yes> | The regex pattern to match. Single quotes must be properly escaped replacing a single quote with '\\'' |
| `--ip_address` | <digit> | The capture group position of the IP address. |
| `--trigger` | <digit> | The trigger level for blocking. |
| `--ports` | <digit1,digit2> | The ports to block the IP from in a comma separated list, only used if LF\_SELECT is enabled. |
| `--block_time` |  | The block time in seconds. n/temporary (n = number of seconds to temporarily block) or 1/permanant IP block, only used if LF\_TRIGGER is disabled. |
| `--cloudflare` | <1\|0> | Whether to trigger Cloudflare block if CF\_ENABLE is set. |
| `--enabled` | <1\|0> | Enable or disable the trigger. |
| `--restart` | <yes> | Restart the service after saving settings. |

## Examples

```
// add a custom trigger for mysql
juggernaut --oper=trigger_add --name='mysqld' --log_file='CUSTOM_LOG' --message='Failed mysqld login with username [$1] from' --ip_address=2 --trigger=5 --ports=3306 --block_time=86400 --cloudflare=1 --enabled=1 --patterns='^(?:\d+ |\d{6} \s?\d{1,2}:\d{2}:\d{2} )?\[Warning\] Access denied for user \'\''(\w+)\'\''\@\'\''(\S+)\'\'' (?:to database \'\''[^\'\'']*\'\''|\(using password: (?:YES|NO)\))*\s*$'

// remove the custom mysql trigger
juggernaut -oper=trigger_del --value='mysqld' 
```

## Related Pages

- [Login Failure Custom Triggers](https://docs.danami.com/juggernaut/user-guide/login-failure-custom-triggers "Login Failure Custom Triggers")
- [Netblock Settings](https://docs.danami.com/juggernaut/settings/login-failure-daemon/netblock-settings "Netblock Settings")
- [Login Failure Blocking](https://docs.danami.com/juggernaut/settings/login-failure-daemon/login-failure-blocking "Login Failure Blocking")

 [ ](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-loginfailureblocking) [](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-netblock)

---

## Navigation

- Previous: [lfd:loginfailureblocking](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-loginfailureblocking.md)
- Next: [lfd:logscanner](https://docs.danami.com/juggernaut/command-line-interface/lfd/lfd-logscanner.md)
