Re: [PATCH] sshd: fix unmatched entries because of the output change in openssh-7.2p2

Niels Baggesen <[email protected]> Tue, 15 Mar 2016 20:37:18 +0100
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
Den 15-03-2016 kl. 10:37 skrev Jan Synacek:
> ---
>  scripts/services/sshd | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/scripts/services/sshd b/scripts/services/sshd
> index e238863..b94ea5a 100755
> --- a/scripts/services/sshd
> +++ b/scripts/services/sshd
> @@ -387,7 +387,7 @@ while (defined(my $ThisLine = <STDIN>)) {
>        $RefusedConnections{$1}++;
>     } elsif ( my ($Reason) = ($ThisLine =~ /^Authentication refused: (.*)$/ ) ) {
>        $RefusedAuthentication{$Reason}++;
> -   } elsif ( my ($Host,$Reason) = ($ThisLine =~ /^Received disconnect from ([^ ]*): (.*)$/)) {
> +   } elsif ( my ($Host,$Reason) = ($ThisLine =~ /^Received disconnect from ([^ ]*) port [^ ]*: (.*)$/)) {
>        # Reason 11 (SSH_DISCONNECT_BY_APPLICATION) is expected, and logged at severity level INFO
>        if ($Reason != 11) {$DisconnectReceived{$Reason}{$Host}++;}
>     } elsif ( my ($Host) = ($ThisLine =~ /^ROOT LOGIN REFUSED FROM ([^ ]*)$/)) {
> 

This might be a good fix for those on 7.2.p2 of OpenSSH, but it breaks
compatibility for those of us still on an earlier version.

Please consider backwards compatibility.

/Niels

-- 
Niels Baggesen -- @home -- Ã…rhus -- Denmark -- [email protected]
The purpose of computing is insight, not numbers  --  R W Hamming

------------------------------------------------------------------------------
Transform Data into Opportunity.
Accelerate data analysis in your applications with
Intel Data Analytics Acceleration Library.
Click to learn more.
http://pubads.g.doubleclick.net/gampad/clk?id=278785231&iu=/4140