diff --git a/files/ssh/etc/filter-syslog/ssh b/files/ssh/etc/filter-syslog/ssh
index 8ef72f8590b39acd9f64802acf743ce243694be2..3ffc5ec6f5bac26c4a66f7cf5b116d2c0b37c2a5 100644
--- a/files/ssh/etc/filter-syslog/ssh
+++ b/files/ssh/etc/filter-syslog/ssh
@@ -57,7 +57,6 @@ sshd: /^error: PAM: User not known to the .* from (inspect|scan1)\./
 sshd: /^refused connect from (::ffff:)?171\.67\.22\.12 /
 sshd: / authentication failure; .* rhost=(scan1|inspect(2-scan)?)\.stanford/
 sshd: /^Postponed \S+ for invalid user \S+ from (::ffff:)?171\.67\.22\.12 /
-sshd: /^Postponed \S+ for \S+ from (::ffff:)?171\.67\.22\.12 /
 
 # Ignore the logged disconnect message.  (We'll still get individual
 # authentication failures from compromised systems.)