Changeset 888


Ignore:
Timestamp:
Nov 20, 2008, 12:38:26 AM (14 years ago)
Author:
geofft
Message:
Display failed root logins from off campus only at 10+10k attempts.
File:
1 edited

Legend:

Unmodified
Added
Removed
  • server/fedora/config/etc/syslog-ng/d_zroot.pl

    r887 r888  
    6767    map { s/^(.*?): // } @message;
    6868    %toclass = ();
     69    my %ips = ();
    6970    foreach my $message (@message) {
    7071        sub sendmsg ($;$) {
     
    8687            } else {
    8788                sendmsg($message." (UNKNOWN KEY)");
     89            }
     90        } elsif ($message =~ m|^Failed keyboard-interactive/pam for root from ([^ ]*)| {
     91            my $count = ++$ips{$1};
     92            if ($count % 10 == 0 or $1 =~ /^18\./) {
     93                sendmsg($message." (repeated $count times)", "scripts-spew");
    8894            }
    8995        } elsif ($message =~ m|^Out of memory:|) {
Note: See TracChangeset for help on using the changeset viewer.