分xi日志能力,查出来看看日志
invalid : 无效的
invalid user maint 无效的删了
第三部分存疑
grep -v " invalid " /tmp/secure-202303* /tmp/secure | grep "Failed password " | awk '/from/ {for (i=1; i<=NF; i++) if ($i == "from") print $(i-1)}' | sort -t. -k1,1nr -k2,2nr -k3,3nr -k4,4nr | uniq -c | sort -nr | head -10
第二部分存疑
grep -v " invalid " /tmp/secure-202303* /tmp/secure | grep "Failed password" | awk '{print $11}' | sort -t. -k1,1nr -k2,2nr -k3,3nr -k4,4nr | uniq -c | sort -nr | head -10
grep -v " invalid " /tmp/secure-202303* /tmp/secure | grep "Failed password" | awk '{print $11}' | sort -t. -k1,1nr -k2,2nr -k3,3nr -k4,4nr | uniq -c | sort -nr | head -10