Simple 403 logging (fail2ban)

I’m looking at fail2ban blocking on 403 for incorrect Janus API passwords via websocket (not admin but users).
What’s the easiest way to achieve this without generating crazy log files?

Ignore this, i found this in the old group so will look at events:

Add IP to logs (google.com)