|
4 | 4 | "input_mode": "journalctl_short_full", |
5 | 5 | "timezone_present": true, |
6 | 6 | "parser_quality": { |
7 | | - "total_lines": 11, |
8 | | - "parsed_lines": 9, |
9 | | - "unparsed_lines": 2, |
10 | | - "parse_success_rate": 0.8182, |
| 7 | + "total_lines": 15, |
| 8 | + "parsed_lines": 12, |
| 9 | + "unparsed_lines": 3, |
| 10 | + "parse_success_rate": 0.8000, |
11 | 11 | "top_unknown_patterns": [ |
| 12 | + {"pattern": "pam_sss_unknown_user", "count": 1}, |
12 | 13 | {"pattern": "sshd_connection_closed_preauth", "count": 1}, |
13 | 14 | {"pattern": "sshd_timeout_or_disconnection", "count": 1} |
14 | 15 | ] |
15 | 16 | }, |
16 | | - "parsed_event_count": 9, |
17 | | - "warning_count": 2, |
| 17 | + "parsed_event_count": 12, |
| 18 | + "warning_count": 3, |
18 | 19 | "finding_count": 3, |
19 | 20 | "event_counts": [ |
20 | 21 | {"event_type": "ssh_failed_password", "count": 3}, |
| 22 | + {"event_type": "ssh_accepted_password", "count": 1}, |
21 | 23 | {"event_type": "ssh_accepted_publickey", "count": 1}, |
22 | 24 | {"event_type": "ssh_invalid_user", "count": 2}, |
| 25 | + {"event_type": "pam_auth_failure", "count": 2}, |
23 | 26 | {"event_type": "sudo_command", "count": 3} |
24 | 27 | ], |
25 | 28 | "host_summaries": [ |
26 | 29 | { |
27 | 30 | "hostname": "alpha-host", |
28 | | - "parsed_event_count": 5, |
| 31 | + "parsed_event_count": 7, |
29 | 32 | "finding_count": 2, |
30 | 33 | "warning_count": 1, |
31 | 34 | "event_counts": [ |
32 | 35 | {"event_type": "ssh_failed_password", "count": 3}, |
33 | | - {"event_type": "ssh_invalid_user", "count": 2} |
| 36 | + {"event_type": "ssh_accepted_password", "count": 1}, |
| 37 | + {"event_type": "ssh_invalid_user", "count": 2}, |
| 38 | + {"event_type": "pam_auth_failure", "count": 1} |
34 | 39 | ] |
35 | 40 | }, |
36 | 41 | { |
37 | 42 | "hostname": "beta-host", |
38 | | - "parsed_event_count": 4, |
| 43 | + "parsed_event_count": 5, |
39 | 44 | "finding_count": 1, |
40 | | - "warning_count": 1, |
| 45 | + "warning_count": 2, |
41 | 46 | "event_counts": [ |
42 | 47 | {"event_type": "ssh_accepted_publickey", "count": 1}, |
| 48 | + {"event_type": "pam_auth_failure", "count": 1}, |
43 | 49 | {"event_type": "sudo_command", "count": 3} |
44 | 50 | ] |
45 | 51 | } |
|
77 | 83 | } |
78 | 84 | ], |
79 | 85 | "warnings": [ |
80 | | - {"line_number": 10, "reason": "unrecognized auth pattern: sshd_connection_closed_preauth"}, |
81 | | - {"line_number": 11, "reason": "unrecognized auth pattern: sshd_timeout_or_disconnection"} |
| 86 | + {"line_number": 12, "reason": "unrecognized auth pattern: pam_sss_unknown_user"}, |
| 87 | + {"line_number": 14, "reason": "unrecognized auth pattern: sshd_connection_closed_preauth"}, |
| 88 | + {"line_number": 15, "reason": "unrecognized auth pattern: sshd_timeout_or_disconnection"} |
82 | 89 | ] |
83 | 90 | } |
0 commit comments