نقل قول نوشته اصلی توسط 1eng.ir نمایش پست ها
journalctl -xe

ببین ارور چی میگیری
کد:
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit session-c44.scope has finished starting up.
--
-- The start-up result is done.
Mar 07 04:01:49 ip208.ip-79-137-121.eu sshd[9816]: pam_unix(sshd:session): session opened for user root by (uid=0)
Mar 07 04:01:50 ip208.ip-79-137-121.eu sshd[9813]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhos
Mar 07 04:01:50 ip208.ip-79-137-121.eu sshd[9813]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Mar 07 04:01:50 ip208.ip-79-137-121.eu sshd[9820]: Accepted password for root from 83.121.118.243 port 28573 ssh2
Mar 07 04:01:50 ip208.ip-79-137-121.eu systemd[1]: Started Session c45 of user root.
-- Subject: Unit session-c45.scope has finished start-up
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit session-c45.scope has finished starting up.
--
-- The start-up result is done.
Mar 07 04:01:50 ip208.ip-79-137-121.eu systemd-logind[752]: New session c45 of user root.
-- Subject: A new session c45 has been created for user root
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- Documentation: http://www.freedesktop.org/wiki/Software/systemd/multiseat
--
-- A new session with the ID c45 has been created for the user root.
--
-- The leading process of the session is 9820.
Mar 07 04:01:50 ip208.ip-79-137-121.eu sshd[9820]: pam_unix(sshd:session): session opened for user root by (uid=0)
Mar 07 04:01:50 ip208.ip-79-137-121.eu dbus[723]: [system] Activating service name='org.freedesktop.problems' (using servicehelper)
Mar 07 04:01:50 ip208.ip-79-137-121.eu dbus[723]: [system] Activated service 'org.freedesktop.problems' failed: The permission of the set
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Failed password for root from 198.199.124.109 port 60351 ssh2
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Received disconnect from 198.199.124.109 port 60351:11: Bye Bye [preauth]
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Disconnected from 198.199.124.109 port 60351 [preauth]
Mar 07 04:01:53 ip208.ip-79-137-121.eu PAM-hulk[9894]: Brute force detection active: 550 LOGIN DENIED -- TOO MANY FAILURES
Mar 07 04:01:53 ip208.ip-79-137-121.eu sshd[9894]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhos
Mar 07 04:01:53 ip208.ip-79-137-121.eu sshd[9894]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

[root@ip208 ~]# clear
[root@ip208 ~]#  journalctl -xe
-- Documentation: http://www.freedesktop.org/wiki/Software/systemd/multiseat
--
-- A new session with the ID c45 has been created for the user root.
--
-- The leading process of the session is 9820.
Mar 07 04:01:50 ip208.ip-79-137-121.eu sshd[9820]: pam_unix(sshd:session): session opened for user root by (uid=0)
Mar 07 04:01:50 ip208.ip-79-137-121.eu dbus[723]: [system] Activating service name='org.freedesktop.problems' (using servicehelper)
Mar 07 04:01:50 ip208.ip-79-137-121.eu dbus[723]: [system] Activated service 'org.freedesktop.problems' failed: The permission of the set
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Failed password for root from 198.199.124.109 port 60351 ssh2
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Received disconnect from 198.199.124.109 port 60351:11: Bye Bye [preauth]
Mar 07 04:01:52 ip208.ip-79-137-121.eu sshd[9813]: Disconnected from 198.199.124.109 port 60351 [preauth]
Mar 07 04:01:53 ip208.ip-79-137-121.eu PAM-hulk[9894]: Brute force detection active: 550 LOGIN DENIED -- TOO MANY FAILURES
Mar 07 04:01:53 ip208.ip-79-137-121.eu sshd[9894]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhos
Mar 07 04:01:53 ip208.ip-79-137-121.eu sshd[9894]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Mar 07 04:01:55 ip208.ip-79-137-121.eu sshd[9894]: Failed password for root from 206.189.148.203 port 54204 ssh2
Mar 07 04:01:55 ip208.ip-79-137-121.eu sshd[9894]: Received disconnect from 206.189.148.203 port 54204:11: Bye Bye [preauth]
Mar 07 04:01:55 ip208.ip-79-137-121.eu sshd[9894]: Disconnected from 206.189.148.203 port 54204 [preauth]
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9928]: Invalid user shangzengqiang from 202.175.46.170 port 53676
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9928]: input_userauth_request: invalid user shangzengqiang [preauth]
Mar 07 04:01:57 ip208.ip-79-137-121.eu PAM-hulk[9928]: Brute force detection active: 580 LOGIN DENIED -- EXCESSIVE FAILURES -- IP TEMP BA
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9928]: pam_unix(sshd:auth): check pass; user unknown
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9928]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhos
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9915]: Invalid user anil from 37.71.147.146 port 52119
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9915]: input_userauth_request: invalid user anil [preauth]
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9915]: pam_unix(sshd:auth): check pass; user unknown
Mar 07 04:01:57 ip208.ip-79-137-121.eu sshd[9915]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhos
Mar 07 04:01:59 ip208.ip-79-137-121.eu sshd[9928]: Failed password for invalid user shangzengqiang from 202.175.46.170 port 53676 ssh2
Mar 07 04:01:59 ip208.ip-79-137-121.eu sshd[9915]: Failed password for invalid user anil from 37.71.147.146 port 52119 ssh2
Mar 07 04:01:59 ip208.ip-79-137-121.eu sshd[9915]: Received disconnect from 37.71.147.146 port 52119:11: Bye Bye [preauth]
Mar 07 04:01:59 ip208.ip-79-137-121.eu sshd[9915]: Disconnected from 37.71.147.146 port 52119 [preauth]
Mar 07 04:02:00 ip208.ip-79-137-121.eu sshd[9928]: Received disconnect from 202.175.46.170 port 53676:11: Bye Bye [preauth]
Mar 07 04:02:00 ip208.ip-79-137-121.eu sshd[9928]: Disconnected from 202.175.46.170 port 53676 [preauth]
Mar 07 04:02:05 ip208.ip-79-137-121.eu sshd[9927]: Connection closed by 140.143.226.19 port 60918 [preauth]
Mar 07 04:02:17 ip208.ip-79-137-121.eu sshd[9736]: Connection closed by 14.29.184.152 port 52002 [preauth]
Mar 07 04:02:24 ip208.ip-79-137-121.eu PAM-hulk[10097]: Brute force detection active: 580 LOGIN DENIED -- EXCESSIVE FAILURES -- IP TEMP B
Mar 07 04:02:24 ip208.ip-79-137-121.eu sshd[10097]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rho
Mar 07 04:02:24 ip208.ip-79-137-121.eu sshd[10097]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "daemon"
lines 1360-1396/1396 (END)