Skip to content

Added Linux tagging rules for the SSH connection end and invalid user events #5339 - #5343

Merged
joachimmetz merged 1 commit into
log2timeline:mainfrom
kev365:feature-tag-linux-ssh-tier3
Oct 11, 2026
Merged

joachimmetz merged 1 commit into
log2timeline:mainfrom
kev365:feature-tag-linux-ssh-tier3

Conversation

@kev365

@kev365 kev365 commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #5340 for #5339: two tag_linux.txt rules for the data types it added.

Change

  • plaso/data/tag_linux.txt:
    • logout also selects data_type is 'syslog:ssh:closed_connection' AND is_authenticated == 1:
      the end of a connection whose user had authenticated (Disconnected from user … and
      Timeout, client not responding from user …). The pam session closed line of the same
      session keeps its rule, so a session end carries the label twice, as a log-in already does
      with syslog:ssh:login and the pam session opened line (Add Linux tagging rules for structured SSH, audit, vsftpd, su, apt and logind events #5217).
    • login_failed also selects data_type is 'syslog:ssh:invalid_user': the Invalid user …
      record sshd writes once per connection for a name that does not resolve, before the
      Failed … for invalid user records that the existing rule already labels per attempt.
  • tests/data/tag_linux.py: one check per rule, in the form of the existing ones.
  • docs/sources/user/Tagging-Rules.md: an entry for each rule with a captured example; the
    logout section, which had no description, now lists its rules.

Verified

  • Re-tagging the two auth.log captures used for Extend syslog SSH record handling to connection end and invalid user messages #5339 (3,467 lines, OpenSSH 10.2p1) with the
    rules of main and with this change: logout 489 → 730, login_failed 24 → 28, every other
    label unchanged (login 495, session_start 259, session_stop 245, application_execution
    421, shutdown 3).
  • tests.data.tag_linux: 22 tests; utils/check_tagging_file.py over the three shipped files:
    no findings.

Backward compatibility

Two rules added; no rule changed or removed.

Checklist:

  • No new new dependencies are required or l2tdevtools has been updated.
  • Test data has a Plaso compatible license. If the test data was not authored by you (the contributor), make sure to mention its original source in ACKNOWLEDGEMENTS.
  • Reviewer assigned.
  • Automated checks (GitHub Actions, AppVeyor) pass.

🤖 Generated with Claude Code

… events log2timeline#5339

logout also selects syslog:ssh:closed_connection events of an authenticated
user and login_failed also selects syslog:ssh:invalid_user events, the data
types added by log2timeline#5340. Tests and the tagging rules documentation follow.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@joachimmetz joachimmetz self-assigned this Oct 11, 2026

@joachimmetz joachimmetz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@joachimmetz
joachimmetz merged commit 40acb5b into log2timeline:main Oct 11, 2026
21 checks passed
@kev365
kev365 deleted the feature-tag-linux-ssh-tier3 branch October 11, 2026 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants