i finally got this sorted. i thought fail2ban was configured in /etc/fail2ban/fail2ban.conf and i never looked at /etc/fail2ban/jail.conf
i edited /etc/fail2ban/jail.conf and enabled ssh. also updated the ssh log to
it was sshd.log (or something similar)
ssh was my main concern, but i'll try and enable http auth and some others as well.
restarted fail2ban and tested this out. fail2ban works fine now, bans IPs, and ispconfig shows me the log via the control panel.
thanks to everyone for helping me with this!