Simple Log Alerting with Systemd/Journald

This post provides a super simple example script for alerting using Systemd/Journald.

With this script using journalctl’s --since flag for 1 minutes ago, I would recommend setting a cron job for every minute to run the script so as to not miss events:

*/1 * * * * /path/to/sshd-alert.sh

Here’s the script:

With the grep_regex_pattern in the script, there will be an alert generated for every failed login as well as every successful login. Change as needed.

Written on August 9, 2021