Skip to main content
Skip table of contents

Syslog - Generic Linux OS: SSHD Messages

Vendor Documentation

N/A

Classification

Rule Name

Rule Type

Common Event

Classification

SSHD Messages

Base Rule

General Information

Information

SSH Logon Successful

Sub Rule

User Logon

Authentication Success

SSH Logoff

Sub Rule

User Logoff

Authentication Success

SSH Logon Failure

Sub Rule

User Logon Failure : Bad Password

Authentication Failure

SSH Logon Failure

Sub Rule

User Logon Failure

Authentication Failure

SSH Session Closed

Sub Rule

Session Ended

Other Audit Success

SSH Session Opened

Sub Rule

Session Started

Other Audit Success

SSH Session Disconnected

Sub Rule

User Logoff

Authentication Success

SSH Logoff

Sub Rule

User Logoff

Authentication Success

SSH Unauth User

Sub Rule

Unauthorized Host

Error

SSH Invalid User

Sub Rule

Invalid User Context

Warning

SSHD Emergency Message

Sub Rule

General Emergency Log Message

Critical

SSHD Alert Message

Sub Rule

General Alert

Critical

SSHD Critical Message

Sub Rule

General Critical

Critical

SSHD Error Message

Sub Rule

General Error

Error

SSHD Warning Message

Sub Rule

General Warning

Warning

SSHD Notice Message

Sub Rule

General Notice

Information

SSHD Information Message

Sub Rule

General Information

Information

SSHD Debug Message

Sub Rule

General Debug Message

Information

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

Schema Description

N/A

<severity>

Text/String

N/A

N/A

<tag1>

Text/String

N/A

N/A

<dip>

IP Address

N/A

N/A

<dname>

Text/String

N/A

N/A

<process>

Text/String

N/A

N/A

<processid>

Number

N/A

N/A

<subject>

Text/String

N/A

N/A

<tag2>

Text/String

N/A

N/A

<domainorigin><login>

Text/String

N/A

N/A

<sip>

IP Address

N/A

N/A

<sport>

Number

N/A

N/A

<object>

Text/String

N/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.