diff --git a/files/ssh/etc/filter-syslog/ssh b/files/ssh/etc/filter-syslog/ssh index 8ef72f8590b39acd9f64802acf743ce243694be2..3ffc5ec6f5bac26c4a66f7cf5b116d2c0b37c2a5 100644 --- a/files/ssh/etc/filter-syslog/ssh +++ b/files/ssh/etc/filter-syslog/ssh @@ -57,7 +57,6 @@ sshd: /^error: PAM: User not known to the .* from (inspect|scan1)\./ sshd: /^refused connect from (::ffff:)?171\.67\.22\.12 / sshd: / authentication failure; .* rhost=(scan1|inspect(2-scan)?)\.stanford/ sshd: /^Postponed \S+ for invalid user \S+ from (::ffff:)?171\.67\.22\.12 / -sshd: /^Postponed \S+ for \S+ from (::ffff:)?171\.67\.22\.12 / # Ignore the logged disconnect message. (We'll still get individual # authentication failures from compromised systems.)