# SSH login attempts dashboard on kibana

**URL:** <https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837>\
**Category:** Kibana\
**Created:** [October 3, 2018, 7:48am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837 "2018-10-03T07:48:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 3, 2018, 7:48am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/1 "2018-10-03T07:48:39Z")

</div>

Hello Team,

I am using ELK 6.4.0 and Beat (Filebeat, Metricbeat). My architecture is Filebeat-\>Logstash-\>Elasticsearch-\>Kibana.

I am sending my auth.log using filebeat but i am not using filebeat system module. Because Filebeat system module can't use directly with logstash. So i am using logstash pipeline. My Grok filter for auth.log is looks like below:

```auto
grok {
match => { "message" => ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped_ip]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:\[%{POSINT:[system][auth][pid]}\])?: \s*%{DATA:[system][auth][user]} :( %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:\[%{POSINT:[system][auth][pid]}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$", "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:\[%{POSINT:[system][auth][pid]}\])?: %{GREEDYMULTILINE:[system][auth][message]}"] }
pattern_definitions => {
        "GREEDYMULTILINE"=> "(.|\n)*"
      }

```

The auth.log are reaching on kibana dashboard. But when i am checking the Filebeat dashbaord for SSH login attempts i am not seeing any value for filed **system.auth.ssh.geoip.country\_iso\_code**. Please refer the below screenshot:

 ![Selection_041](https://us1.discourse-cdn.com/elastic/original/3X/6/6/6602c2d4ec563f5fb57be2fc12a76c362e6ee26c.png)

I have checked on kibana and found that this filed is not created and not available in log. Please refer the below screenshot:

 ![Selection_040](https://us1.discourse-cdn.com/elastic/original/3X/d/e/de8ffc1f01fbd1b817f973a2587e07fbdf7c1cb1.png)

**Can we replace the field system.auth.ssh.geoip.country\_iso\_code with system.auth.ssh.geoip.country\_code2** from visualize in kibana? I have checked but didn't found any such option or can we add any field in grok filter for Auth log?

I want to trace the country name also from where we are tried to SSH our servers.

Please help me to fix the issue. Any assistance will be appreciated.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 3, 2018, 11:33am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/2 "2018-10-03T11:33:23Z")

</div>

Hello Team,

Can you please help me on above issue?

Thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 4, 2018, 11:13am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/3 "2018-10-04T11:13:10Z")

</div>

Hello,

This is a Logstash questions, you should ask in that forum as we can't really help you here.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 5, 2018, 4:35am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/4 "2018-10-05T04:35:19Z")

</div>

@Marius, Thank you for your response.

Sure, i will ask it in logstash forum.

But i have one question for you, **Can we replace the field system.auth.ssh.geoip.country\_iso\_code with system.auth.ssh.geoip.country\_code2** in Visualize of SSH Login attempts?

Thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 5, 2018, 2:37pm UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/5 "2018-10-05T14:37:37Z")

</div>

Yeah, just edit the visualization and change the field. Shouldn't create any problems.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 8, 2018, 8:49am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/6 "2018-10-08T08:49:02Z")

</div>

@marius, Thank you for your response.

I have tried to **replace the field system.auth.ssh.geoip.country\_iso\_code with system.auth.ssh.geoip.country\_code2** in Visualize of SSH Login attempts. But didn't found any such option. Can you please let me know where i can find this filed and replace?

I have tried to add sub-bucket but that also didn't work.

Please refer the below screenshot:

 ![Selection_045](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fe275e75218da5ac56e9fbbe0dcac03344f5da06.png)

Thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 9, 2018, 12:20pm UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/7 "2018-10-09T12:20:30Z")

</div>

You need to look in the saved searches, in the Discover tab, at the `SSH login attempts` saved object. Then you find the field in the left list of fields, remove the system.auth.ssh.geoip.contry\_iso\_code field with system.auth.ssh.geoip.country\_code2.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 6:00am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/8 "2018-10-10T06:00:44Z")

</div>

@Marius, I have made the changes as suggested by you i.e remove that filed and added new fields as per our requirements and saved the search.  
Please refer the below screenshot:

 ![Selection_047](https://us1.discourse-cdn.com/elastic/original/3X/6/6/668029d0118093a7a3a11e2909d3e085e8769c56.png)

But still when i am checking the **Filebeat dashboard for SSH Login Attempts**  **under Dashboard tab** its showing old fields and not updated with the new fields.  
I have restarted the Kibana service as well after making the changes.  
Please refer the below screenshot:

 ![Selection_048](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8d88193e08dbe8d3e7ee6ef02b0db34946cda188.png)

Can you please help me?

Thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 10, 2018, 9:26am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/9 "2018-10-10T09:26:26Z")

</div>

Did you save the search without having checked the `Save as new search` checkbox after you changed the column? There is no need to restart the Kibana service for any changes to the saved objects.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 9:30am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/10 "2018-10-10T09:30:13Z")

</div>

@Marius,

> [@Marius\_Dragomir](#):
>
> Did you save the search without having checked the `Save as new search` checkbox after you changed the column?

Yes, i have saved the serach without checked the `Save as new search`.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 10, 2018, 9:33am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/11 "2018-10-10T09:33:53Z")

</div>

And the dashboard still didn't update with the new value displayed in the column? If this is the case, you can try removing the saved search from the dashboard and adding it again.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 9:48am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/12 "2018-10-10T09:48:15Z")

</div>

> [@Marius\_Dragomir](#):
>
> And the dashboard still didn't update with the new value displayed in the column?

Yes...dashboard is still not updated with new values displayed in the column.

> [@Marius\_Dragomir](#):
>
> If this is the case, you can try removing the saved search from the dashboard and adding it again.

Can you please tell me it step by step. Because i have deleted the `[Filebeat System] SSH login attempts` dashboard in my testing environment and added it again from the saved searches. Now dashboard is created but its not showing under `Filebeat SSH login dashboard`. Its breakdown.

I don't want break anything in my production environment.

So please help me.

Thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 10, 2018, 9:55am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/13 "2018-10-10T09:55:14Z")

</div>

Can you post a screenshot of your Filebeat SSH login dashboard? It would help me to understand what exactly is your status right now.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 10:00am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/14 "2018-10-10T10:00:28Z")

</div>

@Marius, Thank you for your quick response.

Please find the screenshots. I have attached 2 screenshots because its not covered whole data in single screenshot.

 ![Selection_050](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5c2a1bc71c73755bafbc099fc433c28a64533ce6.png)  
 ![Selection_051](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73a3819a02d75f0fef58a84ac974953f64e1821e.png)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [October 10, 2018, 10:17am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/15 "2018-10-10T10:17:46Z")

</div>

Ok, so, going from the start, the steps would be:

1. Change the SSH Login Attempts saved search as you've done it before.
2. Open the dashboard, click on Edit on top right and some borders will be shown for each panel on the dashboard.
3. Remove the SSH Login Attempts panel and then click on Add to add it again with the new fields.

That should be it. Even if something get's messed up, just don't click save so this wouldn't be a destructive action.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 10:32am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/16 "2018-10-10T10:32:01Z")

</div>

@Marius, Thank you for your prompt response.  
Now its working fine and showing all required fields in column.

Really appreciated your efforts. 🙂

Thanks once again.

---

<div class="post-metadata">

**Author:** ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)\
**Post date:** [October 10, 2018, 11:52am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/17 "2018-10-10T11:52:47Z")

</div>

Some please share the exact syntax for the ssh root attempts dashboard on kibana or in the json format. also I need to monitor the queue length of the logs

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 10, 2018, 12:02pm UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/18 "2018-10-10T12:02:13Z")

</div>

@Prasobh,

> [@prasuprasobh](#):
>
> Some please share the exact syntax for the ssh root attempts dashboard on kibana or in the json format.

Sorry didn't get you. Can you please elaborate little bit more?  
If you are using the filebeat then you have default Filebeat dashboard for SSH login attempts. You need to load the filebeat dashboard and its one time setup.

Thanks.

---

<div class="post-metadata">

**Author:** ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)\
**Post date:** [October 11, 2018, 7:13am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/19 "2018-10-11T07:13:26Z")

</div>

Okay. thanks. Currently I am using logstash with kibana.. let me try with filebeat and I will come back to you

---

<div class="post-metadata">

**Author:** ![prasuprasobh](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@prasuprasobh](https://discuss.elastic.co/u/prasuprasobh)\
**Post date:** [October 11, 2018, 11:27am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837/20 "2018-10-11T11:27:02Z")

</div>

[root@k8s-master ~]# more /etc/filebeat/filebeat.yml

filebeat.inputs:

- type: log  
enabled: false  
paths:

[root@k8s-master ~]#

I have configured the filebeat in the client side side , but when I am trying to start the service I am getting below error

Oct 11 16:52:27 k8s-master systemd[1]: Unit filebeat.service entered failed state.  
Oct 11 16:52:27 k8s-master systemd[1]: filebeat.service failed.  
Oct 11 16:52:27 k8s-master systemd[1]: filebeat.service holdoff time over, scheduling restart.  
Oct 11 16:52:27 k8s-master systemd[1]: start request repeated too quickly for filebeat.service  
Oct 11 16:52:27 k8s-master systemd[1]: Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch..  
Oct 11 16:52:27 k8s-master systemd[1]: Unit filebeat.service entered failed state.  
Oct 11 16:52:27 k8s-master systemd[1]: filebeat.service failed.

[Next page](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837.md?page=2)
