Skip to main content
Skip table of contents

SSHD Messages 1

Classification

Rule Name

Rule Type

Common Event

Classification

SSHD MessagesBase RuleSSHD Information MessageInformation
SSHD : Unknown HostSub RuleUnknown HostInformation
SSHD : Terminating SessionSub RuleSSH Session ClosedOther Operations
SSHD : Authentication FailureSub RuleUser Logon FailureAuthentication Failure
SSHD : Session OpenedSub RuleSSH Session OpenedNetwork Traffic
SSHD : Session ClosedSub RuleSSH Session ClosedOther Operations
SSHD : Server ListeningSub RuleServer Listening On IP And PortInformation
SSHD : Received DisconnectSub RuleSession DisconnectedOther Audit Success
SSHD : Failed PasswordSub RuleUser Logon Failure : Bad PasswordAuthentication Failure
SSHD : Connection ClosedSub RuleSSH Session ClosedOther Operations
SSHD : Cannot Bind Any AddressSub RuleCannot Bind ConnectionError
SSHD : Bind To Port FailedSub RuleFailed To Bind PortWarning
SSHD : Authentication FailuresSub RuleUser Logon FailureAuthentication Failure
SSHD : Accepted PasswordSub RuleUser LogonAuthentication Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<severity>Text\String
N/A<dname>Text\String
N/A<sname>Text\String
N/A<sip>IP Address
N/A<dip>IP Address
N/A<sport>Number
N/A<dport>Number
N/A<protname>Text\String
N/A<login>Text\String
N/A<session>Text\String
N/A<process>Text\String
N/A<processid>Number
N/A<object>Number
N/A<subject>Text\String
N/A<command>Text\String
N/A<tag1>Text\String
N/A<tag2>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.