sudo journalctl -u sshd
:查看所有SSH服务相关日志。--since "2025-01-01"
或--until "2025-01-31"
。sudo cat /var/log/auth.log | grep sshd
:过滤出SSH相关日志条目。sudo tail -f /var/log/auth.log
:实时查看最新日志。sudo grep 'Failed password' /var/log/auth.log | awk '{print $9}' | sort | uniq -c | sort -nr
。sudo grep '192.168.1.100' /var/log/auth.log
。sudo grep 'Accepted password' /var/log/auth.log
(成功);sudo grep 'Failed password' /var/log/auth.log
(失败)。Failed password
记录,可结合IP统计封禁。Authentication refused: bad ownership
提示密钥文件权限错误。User not allowed
或DenyUsers
配置导致的拒绝登录。注意:日志文件通常需sudo
权限访问,敏感信息需妥善保管。