SSH: filter more
authorRalf Jung <post@ralfj.de>
Mon, 16 Apr 2018 08:52:38 +0000 (10:52 +0200)
committerRalf Jung <post@ralfj.de>
Mon, 16 Apr 2018 08:52:38 +0000 (10:52 +0200)
roles/journalwatch/files/patterns

index ef042a2..8f2b9f7 100644 (file)
@@ -60,7 +60,7 @@ SYSLOG_IDENTIFIER = sshd
 error: Received disconnect from [\da-fA-F.:]+ port \d+:\d+: .*
 error: maximum authentication attempts exceeded for invalid user \w+ from [\da-fA-F.:]+ port \d+ ssh2( \[preauth\])?
 pam_unix\(sshd:auth\): check pass; user unknown
-pam_unix\(sshd:auth\): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=[\da-fA-F.:]+(  user=root)?
+(pam_unix\(sshd:auth\): authentication failure|PAM \d+ more authentication failures); logname= uid=0 euid=0 tty=ssh ruser= rhost=[\da-fA-F.:]+(  user=root)?
 
 _SYSTEMD_UNIT = bind9.service
 client [\da-fA-F.:]+#\d+ \([\w.-]+\): (zone transfer '[\w.-]+/AXFR/IN' denied|message parsing failed: (bad compression pointer|bad label type))