Skip to main content
Skip table of contents

SSHD Messages

Classification

Rule Name

Rule Type

Common Event

Classification

SSHD MessagesBase RuleSSHD NoticeInformation
Accepted Keyboard-interactive/pamSub RuleGeneral SSHD Audit MessageOther Audit
Authentication FailureSub RuleAuthentication Failure ActivityAuthentication Failure
Check PassSub RuleGeneral Authentication InformationInformation
Connection ClosedSub RuleSession ClosedInformation
Identification String Not ReceivedSub RuleConnection InformationInformation
Failed With Invalid ArgumentSub RuleAuthentication Failure ActivityAuthentication Failure
User Does Not ExistSub RuleUser Identity MissingWarning
Postponed Keyboard-interactiveSub RuleSSHD Information MessageInformation
Received DisconnectSub RuleSession DisconnectedOther Audit Success
Session Closed For UserSub RuleSession Closed For UserOther Audit Success
Session OpenedSub RuleSession StartedOther Audit Success
User Not KnownSub RuleAmbiguous UserWarning
Sshtest User Not KnownSub RuleAmbiguous UserWarning

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

SAU1<severity>Text/String
N/A<process>Text/String
N/A<processid>Number
PAM<subject>Text/String
PAM<tag1>Text/String
for<object>Text/String
from<sip>Ipaddress/Number
N/A<sport>Numeric
N/A<protname>Text/String
N/A<login>Text/String
N/A<session>Number
N/A<status>Text/String
N/A<amount>Number
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.