Skip to content

Instantly share code, notes, and snippets.

View hilt86's full-sized avatar

Hilton hilt86

View GitHub Profile
@hilt86
hilt86 / ssh-watcher.json
Created December 14, 2018 13:13
Watcher alert to notify on failed SSH logins
{
"trigger": {
"schedule": {
"interval": "300s"
}
},
"input": {
"search": {
"request": {
"search_type": "query_then_fetch",
@hilt86
hilt86 / elasticsearch_failed_invalid_ssh.json
Created December 14, 2018 12:20
JSON for Elasticsearch failed ssh
{
"query": {
"terms":{"system.auth.ssh.event":["Failed","Invalid"],"boost":1}
}
}

Keybase proof

I hereby claim:

  • I am hilt86 on github.
  • I am hdemeillon (https://keybase.io/hdemeillon) on keybase.
  • I have a public key ASCOOzKiDQT688lmmiH4CzgzwapzAO6b7Iyq1VdlDnzXlwo

To claim this, I am signing this object: