Skip to content

Instantly share code, notes, and snippets.

@hilt86
Created December 14, 2018 12:20
Show Gist options
  • Save hilt86/fbdaf0473ccc087cb517089f16660100 to your computer and use it in GitHub Desktop.
Save hilt86/fbdaf0473ccc087cb517089f16660100 to your computer and use it in GitHub Desktop.
JSON for Elasticsearch failed ssh
{
"query": {
"terms":{"system.auth.ssh.event":["Failed","Invalid"],"boost":1}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment