Skip to content

Parse sshd PAM auth failure variants#52

Merged
stacknil merged 1 commit into
mainfrom
stacknil/loglens-sshd-pam-auth-corpus
Jun 7, 2026
Merged

Parse sshd PAM auth failure variants#52
stacknil merged 1 commit into
mainfrom
stacknil/loglens-sshd-pam-auth-corpus

Conversation

@stacknil

@stacknil stacknil commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Summary

  • parse sshd-owned PAM: Authentication failure ... lines into the existing event model
  • normalize sshd PAM invalid/illegal-user variants to ssh_invalid_user events
  • expand auth-family syslog and journalctl fixtures plus parser tests
  • document the supported parser behavior

Validation

  • cmake -S . -B build
  • cmake --build build
  • ctest --test-dir build -C Debug --output-on-failure -R parser
  • ctest --test-dir build -C Debug --output-on-failure
  • git diff --check
  • privacy/sensitive-string scan on touched files

@stacknil stacknil merged commit 3664c56 into main Jun 7, 2026
7 checks passed
@stacknil stacknil deleted the stacknil/loglens-sshd-pam-auth-corpus branch June 7, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant