journalwatch: ignore failed SSH attempts... there are just too many...
[ansible.git] / roles / journalwatch / files / patterns
similarity index 93%
rename from roles/journalwatch/templates/patterns
rename to roles/journalwatch/files/patterns
index 8b5d7d2384eb1f0b8e3465f4dcc82806f92ee155..ef042a2d07faf3d16cc0a4b0ef737b739759a488 100644 (file)
@@ -59,6 +59,8 @@ warning: non-SMTP command from \w+\[[\da-fA-F.:]+\]: .*
 SYSLOG_IDENTIFIER = sshd
 error: Received disconnect from [\da-fA-F.:]+ port \d+:\d+: .*
 error: maximum authentication attempts exceeded for invalid user \w+ from [\da-fA-F.:]+ port \d+ ssh2( \[preauth\])?
+pam_unix\(sshd:auth\): check pass; user unknown
+pam_unix\(sshd:auth\): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=[\da-fA-F.:]+(  user=root)?
 
 _SYSTEMD_UNIT = bind9.service
 client [\da-fA-F.:]+#\d+ \([\w.-]+\): (zone transfer '[\w.-]+/AXFR/IN' denied|message parsing failed: (bad compression pointer|bad label type))