SSH Failure Alert Rule

Microsoft.HPUX.11iv2.LogFile.Syslog.SSHAuth.PAM.Root.Failure.Alert (Rule)

Alert rule for failed SSH as root messages.

Knowledge Base article:


An SSH authentication failure for the root account has been detected in the system log files.


A failure may be caused by a mistyped password or an attempt to use an invalid username. However, a persistent failure could be an indication that someone is attempting to gain unauthorized access.


The description of the alert and/or the output data item contains information on the problem encountered. If a failure occurs, check the associated event details and any other events that happened around the time of this failure to diagnose the problem.

Element properties:

Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Message
Failed SSH as Root detected

Member Modules:

ID Module Type TypeId RunAs 
EventDS DataSource Microsoft.Unix.SCXLog.Datasource Default
GenerateAlert WriteAction System.Health.GenerateAlert Default

Source Code:

<Rule ID="Microsoft.HPUX.11iv2.LogFile.Syslog.SSHAuth.PAM.Root.Failure.Alert" Target="Microsoft.HPUX.11iv2.Computer" Enabled="true" Remotable="true">
<!-- [TYPE] HP SSH False -->
<!-- [INPUT] Dec 17 16:40:39 scxhpi10 sshd[29681]: error: PAM: Authentication failed for root from -->
<!-- [INPUT-MISS] Dec 17 16:40:45 scxhpi10 sshd[29681]: Failed keyboard-interactive/pam for root from port 36815 ssh2 -->
<!-- [INPUT-MISS] Dec 17 16:40:53 scxhpi10 sshd[29681]: Failed password for root from port 36815 ssh2 -->
<DataSource ID="EventDS" TypeID="Unix!Microsoft.Unix.SCXLog.Datasource">
<RegExpFilter>[[:space:]]sshd\[[[:digit:]]+\]: error: PAM: Authentication failed for root from [^[:space:]]+</RegExpFilter>
<WriteAction ID="GenerateAlert" TypeID="SystemHealth!System.Health.GenerateAlert">