Commit 13055c95 authored by Karl Kornel's avatar Karl Kornel
Browse files

Removed some no-longer-here people from ssh filter-syslog

parent 9c4e16f0
UNRELEASED
[pam] Stop overriding common PAM files with Debian jessie. (akkornel)
[ssh] Misc. filter-syslog cleanups. (akkornel)
release/004.056 (2015-11-05)
......
......@@ -64,12 +64,12 @@ sshd: /^Disconnecting: Too many authentication failures for \S+$/
# Ignore failed logins by ACS and other AS and ITS staff. We all mistype
# passwords occasionally.
sshd: /^sshd\(pam_unix\): authentication failure; .* user=(adamhl|atayts|bxk|chekh|chom|frobozz|hallk|jmcdermo|jcowart|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl|tzakrajs|whm)$/
sshd: /^pam_(unix|krb5)\(sshd:auth\): authentication failure;.* (logname|user)=(adamhl|atayts|bxk|chekh|chom|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl|tzakrajs|whm)( |\Z)/
sshd: /^Disconnecting: Too many authentication failures for (adamhl|atayts|bxk|chehk|chom|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl|tzakrajs|whm) \[preauth\]$/
sshd: /^Failed (password|gssapi-with-mic|keyboard-interactive/pam) for (adamhl|atayts|bxk|chehk|chom|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl|tzakrajs|whm) from [a-f:\d.]+ port \d+ ssh2$/
sshd: /^PAM \d+ more authentication failures?; .* user=(adamhl|atayts|bxk|chehk|chom|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl|tzakrajs|whm)$/
sshd: /^error: PAM: Authentication failure for (adamhl|atayts|bxk|chekh|chom|frobozz|hallk|jcowart|jonrober|jmcdermo|ktai|laltman|nbfa|saracook|sfeng|swl|tzakrajs|whm) from [a-z:\d.-]+$/
sshd: /^sshd\(pam_unix\): authentication failure; .* user=(adamhl|atayts|bxk|chekh|chom|jmcdermo|jcowart|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl)$/
sshd: /^pam_(unix|krb5)\(sshd:auth\): authentication failure;.* (logname|user)=(adamhl|atayts|bxk|chekh|chom|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl)( |\Z)/
sshd: /^Disconnecting: Too many authentication failures for (adamhl|atayts|bxk|chehk|chom|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl) \[preauth\]$/
sshd: /^Failed (password|gssapi-with-mic|keyboard-interactive/pam) for (adamhl|atayts|bxk|chehk|chom|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl) from [a-f:\d.]+ port \d+ ssh2$/
sshd: /^PAM \d+ more authentication failures?; .* user=(adamhl|atayts|bxk|chehk|chom|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|nbfa|saracook|sfeng|swl)$/
sshd: /^error: PAM: Authentication failure for (adamhl|atayts|bxk|chekh|chom||jcowart|jonrober|jmcdermo|ktai|laltman|nbfa|saracook|sfeng|swl) from [a-z:\d.-]+$/
# Ignore GSS-API failures as root. This is normally because people try to
# use their normal credentials for root access.
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment