How to exclude SELINUX protection for NC log

I’m not an SELINUX expert either, but maybe this is of any help: Fail2ban does not access the nextcloud log - #6 by bb77

Or maybe it would be even better to place the log file outside of the nextcloud data directory, e.g. in /var/log/