efk/prospectors.d/secure.yml
2021-08-29 00:02:22 +08:00

10 lines
293 B
YAML

#------------------------------ Secure Log -------------------------------
- type: log
enabled: true
paths:
- /var/log/secure
include_lines: [": Invalid user ", ": Accepted password ", ": Accepted publickey ", ": authentication failure;"]
tail_files: false
pipeline: secure-login