grep "Failed password for root" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -nr | more
2、centos查看嘗試登錄服務(wù)器的ip,一般用來(lái)查看攻擊ip來(lái)源:
cat /var/log/secure | awk '/Failed/{print $(NF-3)}'| sort| uniq -c| awk '{print $2"="$1;}'
然后將以上ip加入/etc/hosts.deny 文件,格式:all:114.115.116.117