<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic monitoring incorrect login ssh - sftp in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/monitoring-incorrect-login-ssh-sftp/m-p/3773627#M261787</link>
    <description>Dear expert,&lt;BR /&gt;&lt;BR /&gt;I have read and try script to capture inforect login/ftp and su attempt from therad &lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=962197" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=962197&lt;/A&gt; (Thanks to Mel Burslan for script - however there is error in line 10 and need some modification on line 20).&lt;BR /&gt;&lt;BR /&gt;Now I want to modify it to capture correct/incorrect ssh and sftp login. What should I grep the messages from syslog, for example :&lt;BR /&gt;Apr 19 10:44:30 genrep sshd[16511]: subsystem request for sftp&lt;BR /&gt;Apr 19 10:45:05 genrep sshd[16517]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 10:45:07 genrep sshd[16517]: Failed keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1617 ssh2&lt;BR /&gt;Apr 19 10:45:11 genrep sshd[16517]: Accepted password for sysadm from xxx.xxx.xxx.xxx port 1617 ssh2&lt;BR /&gt;Apr 19 10:45:07 genrep sshd[16517]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 10:45:13 genrep  above message repeats 2 times&lt;BR /&gt;Apr 19 11:04:34 genrep sshd[17740]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 11:04:36 genrep sshd[17740]: Failed keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:04:37 genrep sshd[17740]: Failed password for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:04:36 genrep sshd[17740]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 11:04:49 genrep  above message repeats 2 times&lt;BR /&gt;Apr 19 11:04:49 genrep su: + 0 sysadm-root&lt;BR /&gt;Apr 19 11:04:39 genrep sshd[17740]: Failed password for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:05:01 genrep  above message repeats 2 time.Apr 19 11:08:33 genrep sshd[18621]: Accepted keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1750 ssh2&lt;BR /&gt;Apr 19 11:09:32 genrep sshd[18830]: Accepted keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1797 ssh2&lt;BR /&gt;Apr 19 11:09:32 genrep sshd[18844]: subsystem request for sftp&lt;BR /&gt;&lt;BR /&gt;What is the different for incorrect login for sftp and ssh.&lt;BR /&gt;&lt;BR /&gt;Any idea ?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot before,&lt;BR /&gt;&lt;BR /&gt;EKO</description>
    <pubDate>Tue, 18 Apr 2006 23:12:52 GMT</pubDate>
    <dc:creator>yunardi</dc:creator>
    <dc:date>2006-04-18T23:12:52Z</dc:date>
    <item>
      <title>monitoring incorrect login ssh - sftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/monitoring-incorrect-login-ssh-sftp/m-p/3773627#M261787</link>
      <description>Dear expert,&lt;BR /&gt;&lt;BR /&gt;I have read and try script to capture inforect login/ftp and su attempt from therad &lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=962197" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=962197&lt;/A&gt; (Thanks to Mel Burslan for script - however there is error in line 10 and need some modification on line 20).&lt;BR /&gt;&lt;BR /&gt;Now I want to modify it to capture correct/incorrect ssh and sftp login. What should I grep the messages from syslog, for example :&lt;BR /&gt;Apr 19 10:44:30 genrep sshd[16511]: subsystem request for sftp&lt;BR /&gt;Apr 19 10:45:05 genrep sshd[16517]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 10:45:07 genrep sshd[16517]: Failed keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1617 ssh2&lt;BR /&gt;Apr 19 10:45:11 genrep sshd[16517]: Accepted password for sysadm from xxx.xxx.xxx.xxx port 1617 ssh2&lt;BR /&gt;Apr 19 10:45:07 genrep sshd[16517]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 10:45:13 genrep  above message repeats 2 times&lt;BR /&gt;Apr 19 11:04:34 genrep sshd[17740]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 11:04:36 genrep sshd[17740]: Failed keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:04:37 genrep sshd[17740]: Failed password for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:04:36 genrep sshd[17740]: error: PAM: Authentication failed for sysadm from mypc.com&lt;BR /&gt;Apr 19 11:04:49 genrep  above message repeats 2 times&lt;BR /&gt;Apr 19 11:04:49 genrep su: + 0 sysadm-root&lt;BR /&gt;Apr 19 11:04:39 genrep sshd[17740]: Failed password for sysadm from xxx.xxx.xxx.xxx port 1719 ssh2&lt;BR /&gt;Apr 19 11:05:01 genrep  above message repeats 2 time.Apr 19 11:08:33 genrep sshd[18621]: Accepted keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1750 ssh2&lt;BR /&gt;Apr 19 11:09:32 genrep sshd[18830]: Accepted keyboard-interactive/pam for sysadm from xxx.xxx.xxx.xxx port 1797 ssh2&lt;BR /&gt;Apr 19 11:09:32 genrep sshd[18844]: subsystem request for sftp&lt;BR /&gt;&lt;BR /&gt;What is the different for incorrect login for sftp and ssh.&lt;BR /&gt;&lt;BR /&gt;Any idea ?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot before,&lt;BR /&gt;&lt;BR /&gt;EKO</description>
      <pubDate>Tue, 18 Apr 2006 23:12:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/monitoring-incorrect-login-ssh-sftp/m-p/3773627#M261787</guid>
      <dc:creator>yunardi</dc:creator>
      <dc:date>2006-04-18T23:12:52Z</dc:date>
    </item>
  </channel>
</rss>

