{"repo":"woblerr/authlog_exporter","free":true,"listed":false,"github":"https://github.com/woblerr/authlog_exporter","clone":"git clone https://github.com/woblerr/authlog_exporter.git","description":"Prometheus exporter for collecting events from auth.log file with geoIP support.","language":"Go","stars":11,"topics":["prometheus","metrics","logs","auth","prometheus-exporter","collected-metrics","ip-exporter","whois-client"],"license":"MIT","category":"analytics","readme_excerpt":"authlog exporter Prometheus exporter for collecting metrics from linux auth.log file. Collected metrics The client provides a metric authlog events total which contains the number of auth events group by event type , user and ip address . Client also could analyze the location of IP addresses found in auth.log if geoIP database is specified. Metric description Example metrics: If geoIP database is specified: Prefix regexp: Collecting events: Event type Regexp for search event --- --- authAccepted Accepted (password\\ publickey) for (?P . ) from (?P . ) port authFailed Failed (password\\ publickey) for (invalid user )?(?P . ) from (?P . ) port invalidUser Invalid user (?P . ) from (?P . ) port notAllowedUser User (?P . ) from (?P . ) not allowed because connectionClosed Connection closed by authenticating user (?P . ) (?P . ) port sudoIncorrectPasswordAttempts [ ]+(?P . ) : (?P \\\\d+) incorrect password attempts ; TTY=(?P [^ ]+) ; PWD=(?P .+) ; USER=(?P . ) ; COMMAND=(?P . ) sudoNotInSudoers [ ]+(?P . ) : user NOT in sudoers ; TTY=(?P [^ ]+) ; PWD=(?P .+) ; USER=(?P . ) ; COMMAND=(?P . ) sudoSucceeded [ ]+(?P . ) : TTY=(?P [^ ]+) ; PWD=(?P .+) ; USER=(?P . ) ; COMMAND=(?P . ) suSucceeded \\\\(to (?P . )\\\\) (?P . ) on (?P [^ ]+) suFailed FAILED SU \\\\(to (?P . )\\\\) (?P . ) on (?P [^ ]+) Getting Started Building and running By default, metrics will be collecting from /var/log/auth.log and will be available at http://localhost:9991/metrics. This means that the user who runs authlog exp","default_branch":null,"files":null,"tree":[],"storefront":"/r/woblerr","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/woblerr/authlog_exporter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}