Any way to stop SSH log spam in System log?
-
I've recently implemented Zabbix monitoring for my infrastructure and have the pfSense Zabbix agent installed and working well. For templates I'm using HTTP, SSH and FreeBSD which may be overkill when used along with the Zabbix agent. The problem is that the System log is logging every SSH check by Zabbix:
Sep 2 14:04:49 sshd 4557 Connection closed by 10.10.0.225 port 35202 [preauth]
Sep 2 14:03:49 sshd 6064 Connection closed by 10.10.0.225 port 33258 [preauth]
Sep 2 14:02:49 sshd 10971 Connection closed by 10.10.0.225 port 59568 [preauth]
Sep 2 14:01:49 sshd 12000 Connection closed by 10.10.0.225 port 57640 [preauth]
Sep 2 14:00:49 sshd 15733 Connection closed by 10.10.0.225 port 55708 [preauth]
Sep 2 13:59:49 sshd 19881 Connection closed by 10.10.0.225 port 53746 [preauth]
Sep 2 13:58:49 sshd 19307 Connection closed by 10.10.0.225 port 51774 [preauth]
Sep 2 13:57:49 sshd 23543 Connection closed by 10.10.0.225 port 49836 [preauth]One for every minute of the day. Is there a way to stop the logging of SSH connections?
-
No, because for security reasons it has to report every attempted connection. The alternative would be someone/something nefarious hitting the port and you'd never know.