LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 04-30-2005, 02:40 PM   #1
twantrd
Senior Member
 
Registered: Nov 2002
Location: CA
Distribution: redhat 7.3
Posts: 1,440

Rep: Reputation: 52
Logwatch sshd


Has anyone gotten logwatch to monitor failed login attempts on sshd? I have tried:

myhost:/etc/log.d/scripts# ./logwatch.pl --service secure --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam_pwdb --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam_unix --range all --detail high --print

And I'm getting no results. This should be a simple thing to do. Hmm...can anyone shed me some light? Thanks.

-twantrd
 
Old 04-30-2005, 03:03 PM   #2
HappyTux
Senior Member
 
Registered: Mar 2003
Location: Nova Scotia, Canada
Distribution: Debian AMD64
Posts: 4,170

Rep: Reputation: 244Reputation: 244Reputation: 244
Re: Logwatch sshd

Quote:
Originally posted by twantrd
Has anyone gotten logwatch to monitor failed login attempts on sshd? I have tried:

myhost:/etc/log.d/scripts# ./logwatch.pl --service secure --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam_pwdb --range all --detail high --print

myhost:/etc/log.d/scripts# ./logwatch.pl --service pam_unix --range all --detail high --print

And I'm getting no results. This should be a simple thing to do. Hmm...can anyone shed me some light? Thanks.

-twantrd
Never tried logwatch but how about grep -i ssh /var/log/auth.log as root.
 
Old 04-30-2005, 05:19 PM   #3
twantrd
Senior Member
 
Registered: Nov 2002
Location: CA
Distribution: redhat 7.3
Posts: 1,440

Original Poster
Rep: Reputation: 52
Yes, you could just write a script to actually do the grepping itself for failed/illegal login attempts but then that defeats the purpose of logwatch as I want that to parse the logs for me.

I compiled logwatch from source and looks like it's following stupid redhat's directory structure for logs. Grrr..

-twantrd
 
Old 04-30-2005, 05:59 PM   #4
twantrd
Senior Member
 
Registered: Nov 2002
Location: CA
Distribution: redhat 7.3
Posts: 1,440

Original Poster
Rep: Reputation: 52
Ahh, figured out the problem. Thanks anywayz.

-twantrd
 
Old 05-23-2005, 09:52 AM   #5
BrianK
Senior Member
 
Registered: Mar 2002
Location: Los Angeles, CA
Distribution: Debian, Ubuntu
Posts: 1,334

Rep: Reputation: 51
Quote:
Originally posted by twantrd
Ahh, figured out the problem. Thanks anywayz.

-twantrd
care to share? I'm looking to do the same - both successful and failed ssh attempts.
 
Old 05-23-2005, 12:05 PM   #6
twantrd
Senior Member
 
Registered: Nov 2002
Location: CA
Distribution: redhat 7.3
Posts: 1,440

Original Poster
Rep: Reputation: 52
Quote:
care to share? I'm looking to do the same - both successful and failed ssh attempts.
If your distro is redhat, it should work out of the box as the sshd service looks for /var/log/secure for failed ssh attempts. My log file was /var/log/auth.log so I had to change /etc/log.d/conf/logfiles/secure.conf to point to /var/log/auth.log. That's pretty much it and just add the ssh service into logwatch.conf.

Oh yea, /etc/log.d/ was where I placed my logwatch files/scripts. Change that path to whatever yours is.

-twantrd
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Logwatch reports SSHD Killed: / Failed to bind: 0.0.0.0 port 22 rioguia Linux - Security 1 08-13-2005 12:24 PM
timestamped sshd logs with logwatch ddaas Linux - Networking 1 04-30-2005 02:34 PM
Logwatch winchester169 Linux - Security 1 10-21-2004 09:18 AM
LogWatch exyst Linux - Software 0 03-13-2004 06:04 PM
Enabling SSH in mandrake 9.2 - sshd vs. sshd-xinetd DogTags Linux - Newbie 7 11-25-2003 12:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 08:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration