Usermin is webmail (plus some extras). It has nothing to do with Let’s Encrypt certificates, it is merely a user of those certificates, like Apache or Postfix. Webmin is what performs administrative tasks, like LE renewals and publishing those certs to all the right places.
Like I said. I’m on the OLD log system prior to the journal thing so it carried over so I couldn’t give you an exact method to try.
As a guess, I’d say simply try fail2ban, not fail2ban.service in the filter. An hour a day of fail2ban cpu usage in your last post may not be all that high but in the post I referenced it seemed to run continuously. If it was an hour between restarts it used an hour of cpu time.
There was an issue that if fail2ban starts before the firewall it wouldn’t work. The restarts should take care of that though. Are the jails being filled with ‘criminal ip’s’?
You could just turn it off at the firewall so no external connections hit it. Probably the safest thing to do and easiest to restore if needed if you are worried about the external ‘load’ it adds.