【ELK --- Grok正则过滤Linux系统登录日志】教程文章相关的互联网学习教程文章

ELK --- Grok正则过滤Linux系统登录日志【代码】

过滤Linux系统登录日志/var/log/secure 登陆成功 Jan 6 17:11:47 localhost sshd[3324]: Received disconnect from 172.16.0.13: 11: disconnected by user Jan 6 17:11:47 localhost sshd[3324]: pam_unix(sshd:session): session closed for user root Jan 6 17:11:48 localhost sshd[3358]: Address 172.16.0.13 maps to localhost, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! Jan 6 17:11:5...