↑ ↓ select, Enter open, Esc close

IP addresses with the most failed SSH logins

Adjust the values, the command updates live
root@server
journalctl -u ssh --since "24 hours ago" --no-pager | grep -oE 'Failed password for .* from [0-9a-f.:]+' | awk '{print $NF}' | sort | uniq -c | sort -rn | head -20

Searches the SSH service journal for failed password logins, extracts the source IP and counts the attempts per address. The output shows the 20 most active IPs with their count. Useful for judging whether Fail2Ban is working or a ban is needed.

Note: If password authentication is disabled, attempts tend to appear as Invalid user or Connection closed by authenticating user. With rsyslog, the data is also in /var/log/auth.log.

Also searched as

  • count failed ssh login attempts by ip
  • ssh brute force attackers list
  • top ips failed password ssh

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.