Labs · Cyber Security
Lab: Read Your Server's SSH Login Log with journalctl and grep, and Spot Failed Login Attempts
Course: Cyber Security · Chapter 6: Linux Advanced Commands
Chapter 6 teaches grep, pipes and advanced commands; this lab uses them on a real security log.
Chala mitrano! A security analyst's first friend is the log file. Today we open our own server's SSH log and answer three questions: who tried to log in, how many times did they fail, and who actually got in? Only grep and a few pipes. Ekdum mast!
चला मित्रांनो! Security analyst चा पहिला मित्र म्हणजे log file. आज आपण आपल्या server चा SSH log उघडणार आणि तीन प्रश्नांची उत्तरं शोधणार: login करायचा प्रयत्न कोणी केला, कितीदा fail झाले, आणि खरंच आत कोण आलं? फक्त grep आणि काही pipes. एकदम मस्त!
चलो दोस्तों! Security analyst का पहला दोस्त है log file। आज हम अपने server का SSH log खोलेंगे और तीन सवालों के जवाब ढूँढेंगे: login की कोशिश किसने की, कितनी बार fail हुए, और असल में अंदर कौन आया? बस grep और कुछ pipes। बहुत मज़ेदार!
Suppose we are…
Suppose we have joined the HCLTech SOC (Security Operations Centre) as a trainee analyst. The client says: "Our Linux server feels slow; is someone attacking it?" Before any expensive tool, we read the SSH log, the record of every login attempt. On the internet, bots try usernames like admin, test and oracle all day. We learn to see them on our own server.
Goal of this lab
By the end you will have:
- Read SSH log lines and understood Failed password, Invalid user and Accepted publickey.
- A count of failed attempts per IP address, sorted from most to least.
- Confirmed that the only successful login is yours.
What you need (all free)
- Your own Linux server: a free-tier EC2 Amazon Linux 2023 instance (Lab 4) or an Ubuntu VM. For more log lines, a server that has been running for a few hours is best.
- 25–30 minutes.
Safety and ethics
Read logs only on servers you own or have written permission to manage. IP addresses in logs are personal data in many laws; do not post real ones publicly. Do not "attack back" any IP you find; report and block instead.
Steps
-
SSH to your server. On Amazon Linux 2023 the SSH log is in the system journal. Show the last 30 SSH lines:
sudo journalctl -u sshd --no-pager | tail -n 30On Ubuntu use
sudo journalctl -u ssh --no-pager | tail -n 30orsudo tail -n 30 /var/log/auth.log.What you should see: lines with a date, the host name,
sshd[1234]:and a message. -
Find your own successful login:
sudo journalctl -u sshd --no-pager | grep "Accepted"What you should see:
Accepted publickey for ec2-user from 49.36.12.80 port 51544 ssh2with your home IP. -
Find failed attempts. Two kinds matter: wrong password for a real user, and a username that does not exist:
sudo journalctl -u sshd --no-pager | grep -E "Failed password|Invalid user"If your security group allows SSH only from My IP (Lab 4), you may see nothing. That is the point of My IP! To get practice lines, from your own laptop try once with a wrong user:
ssh -i lab-key.pem wronguser@<server-ip>and run step 3 again. -
Count failed attempts per IP.
awkpicks a column,sort | uniq -ccounts,sort -rnsorts by count:sudo journalctl -u sshd --no-pager | grep "Invalid user" | grep -oE "from [0-9.]+" | awk '{print $2}' | sort | uniq -c | sort -rn | headWhat you should see: lines like
3 49.36.12.80: the number of attempts and the IP.grep -oE "from [0-9.]+"cuts out only the words "from 49.36.12.80", andawk '{print $2}'keeps the second word, the IP. -
List which usernames were tried:
sudo journalctl -u sshd --no-pager | grep "Invalid user" | awk '{print $8}' | sort | uniq -c | sort -rn -
Check that password login is switched off (Amazon Linux 2023 default):
sudo sshd -T | grep -E "passwordauthentication|permitrootlogin"What you should see:
passwordauthentication noandpermitrootloginwithnoorprohibit-password. With these, password-guessing bots cannot succeed. -
Look at only today's log, which is faster on a busy server:
sudo journalctl -u sshd --since today --no-pager | grep -c "Invalid user"(-cprints only the count). - Write a 3-line note like a SOC analyst: number of failed attempts, top IP and usernames tried, and "only successful login: ec2-user from my IP".
Ravindra Bagale's Tip
Thousands of "Invalid user" lines look scary, but they only knock on the door. The real question in an investigation is always: is there any Accepted line from an IP you don't know? That one line matters more than ten thousand failures. Lakshat theva!
Ravindra Bagale's Tip – मराठी
हजारो "Invalid user" lines भीतीदायक वाटतात, पण ते फक्त दरवाजा ठोठावतात. Investigation मधला खरा प्रश्न नेहमी हाच: ओळखीचा नसलेल्या IP वरून एखादी Accepted line आहे का? ती एक line दहा हजार failures पेक्षा जास्त महत्त्वाची आहे. लक्षात ठेवा!
Ravindra Bagale's Tip – हिंदी
हज़ारों "Invalid user" lines डरावनी लगती हैं, पर वो सिर्फ दरवाज़ा खटखटाती हैं। Investigation में असली सवाल हमेशा यही है: क्या किसी अनजान IP से कोई Accepted line है? वो एक line दस हज़ार failures से ज़्यादा मायने रखती है। याद रखो!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Looking for /var/log/secure on Amazon Linux 2023 |
"No such file" | AL2023 uses the journal: journalctl -u sshd |
Using the unit name sshd on Ubuntu |
"No entries" | On Ubuntu the unit is ssh |
Forgetting sudo |
Empty output or "not seeing messages from other users" | Logs need sudo |
| Printing the wrong column in awk | You count port numbers instead of IPs | Cut the IP out with grep -oE "from [0-9.]+" first, then print column 2 |
| Panicking at many failures | Time wasted | Check for Accepted lines from unknown IPs first |
Self-check checklist
0 of 5 done
Try-at-home challenge
Make a one-line command that prints only the unique IPs that ever logged in successfully. If any IP is not yours, what are your first three actions?
Check your answer
sudo journalctl -u sshd --no-pager | grep "Accepted" | grep -oE "from [0-9.]+" | awk '{print $2}' | sort -u
sort -u sorts and keeps each IP once. If an unknown IP appears: (1) restrict the security group to My IP, (2) check ~/.ssh/authorized_keys for keys you did not add, (3) tell your lead and follow the incident process before deleting anything, so the evidence stays.
Samjla ka? Failures knock, Accepted enters; grep, awk, sort and uniq tell the story. Aata pudhe jaauya: Chapter 7 installs a web server.