'^.{15,} (.*) sshd\[.* Did not receive (ident|identification) string from (.*)' - - - 0
open "$4" - 5000 1800 90
report "/usr/local/bin/surfmailer -r root -S \"security incident from $4\"" "$4"
'^.{15,} (.*) sshd\[(.*)\]: Failed password for (.*) from (.*) port .*' - - - 0
open "$2 sshd:\\[$3\\]:" - 5000 10800 300
report "/usr/local/bin/surfmailer -r root -S \"SSH LOGIN FAILED for $4@$2 from $5\"" "$2 sshd:\\[$3\\]:"
We use essential cookies to make this site work, and optional cookies to enhance your experience.