Monitors for logins, addition or removal of users, and other security events.
The Linux/SSH Login Event Monitor runs 'lastlog' on systems that support it and alerts based on user security events.
This event monitor provides the following options:
Enable this option to receive alerts if the SSH server can't be reached.
Use this option to receive an alert if a user logs in.
This option will let you know if a new user is detected.
This option will alert you if a user has been removed since the last time the event monitor ran.
Check this box to add a list of all users and their last logins to the event text generated each time the event monitor runs.
Enter a comma-separated list of users you want to receive alerts on in the provided text box.
Specify a comma-separated list of users to ignore in the text box provided.
The default port for SSH connections is 22 but if your servers are using a non-standard port you can specify it here.
Specify the time you want to wait for a connection before timing out.
The account used for authentication must have interactive login rights via SSH. It also must have permission to run the following command:
This event monitor doesn't generate any data points.
To view the tutorial for this event monitor, click here.
Add a comment