Simple Log Alerting with Systemd/Journald
This post provides a super simple example script for alerting using Systemd/Journald.
With this script using
--since flag for
1 minutes ago, I would recommend setting a cron job for every minute to run the script so as to not miss events:
*/1 * * * * /path/to/sshd-alert.sh
Here’s the script:
grep_regex_pattern in the script, there will be an alert generated for every failed login as well as every successful login. Change as needed.