diff --git a/files/ssh/etc/filter-syslog/ssh b/files/ssh/etc/filter-syslog/ssh
index 3ffc5ec6f5bac26c4a66f7cf5b116d2c0b37c2a5..cfb42f7d0f2b0c55dd99b2af3dac07e34b03e62f 100644
--- a/files/ssh/etc/filter-syslog/ssh
+++ b/files/ssh/etc/filter-syslog/ssh
@@ -64,11 +64,11 @@ sshd: /^Disconnecting: Too many authentication failures for \S+$/
 
 # Ignore failed logins by IDG, Systems, and other ITS staff.  We all mistype
 # passwords occasionally.
-sshd: /^sshd\(pam_unix\): authentication failure; .* user=(adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jmcdermo|jcowart|jonrober|ktai|laltman|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|tzakrajs|whm|vdc|xinlei|yuelu)$/
-sshd: /^pam_(unix|krb5)\(sshd:auth\): authentication failure;.* (logname|user)=(adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|tzakrajs|whm|vdc|xinlei|yuelu)( |\Z)/
-sshd: /^PAM \d+ more authentication failures?; .* user=(adamhl|atayts|bxk|chehk|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|tzakrajs|whm|vdc|xinlei|yuelu)$/
-sshd: /^Failed (password|gssapi-with-mic|keyboard-interactive/pam) for (adamhl|atayts|bxk|chehk|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|tzakrajs|whm|vdc|xinlei|yuelu) from [a-f:\d.]+ port \d+ ssh2$/
-sshd: /^error: PAM: Authentication failure for (adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jcowart|jonrober|jmcdermo|ktai|laltman|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|tzakrajs|whm|vdc|xinlei|yuelu) from [a-z:\d.-]+$/
+sshd: /^sshd\(pam_unix\): authentication failure; .* user=(adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jmcdermo|jcowart|jonrober|ktai|laltman|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|swl|tzakrajs|whm|vdc|xinlei|yuelu)$/
+sshd: /^pam_(unix|krb5)\(sshd:auth\): authentication failure;.* (logname|user)=(adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|swl|tzakrajs|whm|vdc|xinlei|yuelu)( |\Z)/
+sshd: /^PAM \d+ more authentication failures?; .* user=(adamhl|atayts|bxk|chehk|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|swl|tzakrajs|whm|vdc|xinlei|yuelu)$/
+sshd: /^Failed (password|gssapi-with-mic|keyboard-interactive/pam) for (adamhl|atayts|bxk|chehk|darrenp1|digant|frobozz|hallk|jcowart|jmcdermo|jonrober|ktai|laltman|martinp|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|swl|tzakrajs|whm|vdc|xinlei|yuelu) from [a-f:\d.]+ port \d+ ssh2$/
+sshd: /^error: PAM: Authentication failure for (adamhl|atayts|bxk|chekh|darrenp1|digant|frobozz|hallk|jcowart|jonrober|jmcdermo|ktai|laltman|meeilee|mgoll|nbfa|pradtke|rra|saracook|sfeng|swl|tzakrajs|whm|vdc|xinlei|yuelu) from [a-z:\d.-]+$/
 
 # Ignore GSS-API failures as root.  This is normally because people try to
 # use their normal credentials for root access.