cscli parsers install crowdsecurity/dropbear-logs
Parser for dropbear SSH server.
1onsuccess: next_stage2filter: "evt.Parsed.program == 'dropbear'"3name: crowdsecurity/dropbear-logs4description: "Parse dropbear logs"5nodes:6 - grok:7 pattern: "Bad PAM password attempt for '%{DATA:user}' from %{IP:source_ip}:%{INT:port}"8 apply_on: message9 - grok:10 pattern: "Login attempt for nonexistent user from %{IP:source_ip}:%{INT:port}"11 apply_on: message12 - grok:13 pattern: "Exit before auth from <%{IP:source_ip}:%{INT:port}>:"14 apply_on: message15statics:16 - meta: service17 value: dropbear18 - meta: target_user19 expression: evt.Parsed.user20 - meta: source_ip21 expression: evt.Parsed.source_ip22 - meta: log_type23 value: ssh_failed-auth24