lnav/example-scripts/tag-ssh-msgs.lnav
2021-02-25 15:47:36 -08:00

11 lines
255 B
Plaintext

#
# @synopsis: tag-ssh-msgs
# @description: Tag interesting SSH log messages
#
;UPDATE all_logs
SET log_tags = json_concat(log_tags, '#ssh.invalid-user')
WHERE log_text LIKE '%Invalid user from%'
;SELECT 'Tagged ' || changes() || ' messages';