File: //lib/systemd/system/fail2ban.service.d/50-ensure-log.conf
[Service]
# Ensure existence of the log file used for the recidive jail.
# Otherwise fail2ban service is unable to start for the first time.
# If you have a STRONG reason to disable this step then use
#
# install --directory /etc/systemd/system/fail2ban.service.d
# ln --symbolic /dev/null /etc/systemd/system/fail2ban.service.d/50-ensure-log.conf
# systemctl daemon-reload
ExecStartPre=-/bin/sh -c 'umask 077; touch /var/log/fail2ban.log; restorecon /var/log/fail2ban.log >/dev/null 2>&1'