# Shh login attempt

**URL:** https://discuss.elastic.co/t/shh-login-attempt/152479
**Category:** Elasticsearch
**Created:** [October 15, 2018, 11:07am UTC](https://discuss.elastic.co/t/shh-login-attempt/152479 "2018-10-15T11:07:23Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)
#### Post date: [October 15, 2018, 11:07am UTC](https://discuss.elastic.co/t/shh-login-attempt/152479/1 "2018-10-15T11:07:23Z")

</div>

Hii...

I have configured the elatsicsearch and logs are shipping from the client using filebeat with logstash. Need help to configure ssh login attempts failed in the dashboard

---

<div class="post-metadata">

### Author: ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)
#### Post date: [October 15, 2018, 1:53pm UTC](https://discuss.elastic.co/t/shh-login-attempt/152479/2 "2018-10-15T13:53:50Z")

</div>

Hi @prasuprasobh,

Follow this thread it might be helpful to you because i think same question is their.

> [@SSH login attempts dashboard on kibana](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837):
>
> Hello Team, I am using ELK 6.4.0 and Beat (Filebeat, Metricbeat). My architecture is Filebeat-\>Logstash-\>Elasticsearch-\>Kibana. I am sending my auth.log using filebeat but i am not using filebeat system module. Because Filebeat system module can't use directly with logstash. So i am using logstash pipeline. My Grok filter for auth.log is looks like below: grok { match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[sys…

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

### Author: ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)
#### Post date: [October 17, 2018, 8:29am UTC](https://discuss.elastic.co/t/shh-login-attempt/152479/3 "2018-10-17T08:29:30Z")

</div>

Thanks Krunal....still I have some issue with the dash board

---

<div class="post-metadata">

### Author: ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)
#### Post date: [October 29, 2018, 12:36pm UTC](https://discuss.elastic.co/t/shh-login-attempt/152479/4 "2018-10-29T12:36:51Z")

</div>

can some one please share the working configuration with filebeat + logstash for ssh login attempts and other

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 26, 2018, 12:41pm UTC](https://discuss.elastic.co/t/shh-login-attempt/152479/5 "2018-11-26T12:41:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
