• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Persistent SSHGuard Log Messages

Scheduled Pinned Locked Moved General pfSense Questions
6 Posts 4 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kristiyan.kolev
    last edited by Apr 14, 2024, 7:55 AM

    Hello, Netgate Community,

    I'm having an issue with pfSense 2.7.2 in which SSHGuard repeatedly exits and restarts monitoring. My system logs are filling up with these entries, which show a continuous cycle of "Exiting on signal" and "Now monitoring attacks," as follows:

    Apr 14 01:19:00 sshguard 62312 Exiting on signal.
    Apr 14 01:19:00 sshguard 72750 Now monitoring attacks.
    ... [similar entries repeated with different process IDs]
    

    I found discussions from two years ago that described similar issues, but I would have expected a solution or patch by now. Is anyone else experiencing this issue, or has it been addressed in a more recent update that I may have overlooked? Any insights or solutions would be greatly appreciated, as this issue is causing concern for both log management and system stability.

    Thank you for any assistance you can offer!

    P 1 Reply Last reply Apr 14, 2024, 8:18 AM Reply Quote 0
    • P
      pst @kristiyan.kolev
      last edited by Apr 14, 2024, 8:18 AM

      @kristiyan-kolev I can confirm I saw the same in pfSense+ 23.09.1, and it's still in 24.03-RC (24.03.r.20240410.1729). There's a new log entry roughly every 11-12 minutes.

      B 1 Reply Last reply Apr 14, 2024, 8:47 AM Reply Quote 0
      • B
        Bob.Dig LAYER 8 @pst
        last edited by Apr 14, 2024, 8:47 AM

        @pst I don't see it.

        P 1 Reply Last reply Apr 14, 2024, 9:24 AM Reply Quote 0
        • P
          pst @Bob.Dig
          last edited by pst Apr 14, 2024, 9:26 AM Apr 14, 2024, 9:24 AM

          @Bob-Dig according to this thread: https://forum.netgate.com/topic/169923/tons-sshguard-log-entries-and-its-not-enabled it is related to the amount of logging going on and the log limits set, as it is log rotations that trigger the sshguard restarts. Which explains my case at least.

          1 Reply Last reply Reply Quote 0
          • K
            kristiyan.kolev
            last edited by Apr 14, 2024, 11:53 AM

            I see, so if I understand correctly, the messages are logged each time SSHGuard resets in conjunction with a log rotation. This rotation happens whenever the log reaches its size limit, at which point the current log is compressed, and a new one is started. Is that accurate?

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Apr 14, 2024, 2:15 PM

              Yup you will see it everytime any log rotates. So you can mitigate it by increasing the log file sizes or reducing what is logged in whichever log is rotating.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received