Fwd: exclusion of ssh failures
"Kirk Bauer" <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
---------- Forwarded message ---------- From: Nathaniel Taylor <[email protected]> Date: Sat, May 24, 2008 at 11:39 AM Subject: exclusion of ssh failures To: [email protected] Every computer on every network that I work on gets a load of (automatic) attempted ssh logins every day. The weekly logwatch email is typically approaching 1MB in size, almost entirely from ssh and pam login failures all being listed. This huge amount of data is not at all important compared to knowing what logins did actually succeed, and other information such as kernel messages. In my installation (logwatch-7.3.2 according to gentoo) there seems no way to avoid this, other than the crude changes I've made to the ssh2 and pam_unix scripts. Even setting the Detail to 1 doesn't remove this. It strikes me that such a lot of failure details ought only to be seen at a much higher level, e.g. 8, since they could be summarised as 'N failed login attempts'. Perhaps I've missed some other config setting? Suggestions: extra setting in a config file for pam_unix and ssh[2] to exclude or summarise failures; or, just put them to a higher detail level. If such scanning were uncommon (as it used to be when I started using logwatch) I'd agree with the current behaviour, but nowadays such detailed logging just obscures the more important data. Best regards (and thanks for this useful program), Nathaniel -- Kirk Bauer <[email protected]> http://linux.kaybee.org | www.logwatch.org Author, Automating UNIX & Linux Administration