Spickblatt

Das Nutzen, Vervielfältigen, Ändern, und Verbreiten dieser Kommandos ist gestattet.

# cat /var/log/secure | grep <Internetprotokolladresse>

# truncate --size=0 /var/log/secure

# cat /var/log/auth.log | grep <Internetprotokolladresse>

# truncate --size=0 /var/log/auth.log

Slackware 15.0, Fedora Server 43

# cat /var/log/secure | grep "Failed password for invalid user" | cut --delimiter=" " --fields=13 > tmp

# cat /var/log/secure | grep "Failed password for root from" | cut --delimiter=" " --fields=11 >> tmp

# cat /var/log/secure | grep "]: Connection reset by" | cut --delimiter=" " --fields=9 >> tmp

# cat /var/log/secure | grep "Unable to negotiate with" | cut --delimiter=" " --fields=10 >> tmp

# cat /var/log/secure | grep "Invalid user from" | cut --delimiter=" " --fields=10 >> tmp

# cat tmp | sort | uniq

# rm --force tmp

Alternative: Slackware 15.0, Fedora Server 43

# cat /var/log/secure | grep "Failed password for invalid user" | cut --delimiter=" " --fields=14 > tmp

# cat /var/log/secure | grep "Failed password for root from" | cut --delimiter=" " --fields=12 >> tmp

# cat /var/log/secure | grep "Invalid user from" | cut --delimiter=" " --fields=11 >> tmp

# cat tmp | sort | uniq

# rm --force tmp

Debian 12

# cat /var/log/auth.log | grep "Failed password for invalid user" | cut --delimiter=" " --fields=11 > tmp

# cat /var/log/auth.log | grep "Failed password for root from" | cut --delimiter=" " --fields=9 >> tmp

# cat tmp | sort | uniq

# rm --force tmp

Debian 13

# journalctl -u ssh -o cat --since yesterday | grep "Failed password for invalid user" | cut --delimiter=" " --fields=8 > tmp

# journalctl -u ssh -o cat --since yesterday | grep "Failed password for root from" | cut --delimiter=" " --fields=6 >> tmp

# cat tmp | sort | uniq

# rm --force tmp