Use this command to upload the SSH log file to the SCP Server.
Ensure the following before using this command:
- The SCP server IP address must be set using the command set scpserver ip <server_ip>.
The file uploaded on the SCP server is the TAR file containing one or more zipped files:
- Untar the file using the command tar –xvf <filename> to get the individual zipped files.
- Each file must be unzipped using the command gunzip <zipped_file> to view the file.
- For NS-series Sensors, when loading the SSH log file to the SCP server, the first attempt will be based on SSH public key authentication. If that fails, the Sensor will fall back to the password authentication. If SSH public key authentication is successful, you will not be prompted for the SCP server credentials.
Syntax
sshlogupload scp word
A sample SSH log message is displayed below:
Sep 16 09:09:52 localhost kernel: SSHD_DROP:IN=eth0 OUT=
MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 SRC=172.16.232.47
DST=172.16.199.89 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=4286 DF
PROTO=TCP SPT=2821 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
Note
SSH log only contains entries for SSH accept or SSH drop from a particular client IP address as defined in the ACL.
| Log Message Fields | Description |
|---|---|
| SSHD_DROP | The Log prefix. It can be SSHD_DROP or SSHD_ACCEPT. |
| IN=etho | Interface the packet was received from; empty value for locally generated packets |
| OUT= | Interface the packet was sent to; empty value for locally received packets |
| MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 |
The MAC field consisting of 14 entities, separated by colons, and this can read as:
|
| SRC=172.16.232.47
DST=172.16.199.89 |
Source IP address
Destination IP address |
| LEN=48 | The total length of IP packet in bytes |
| TOS=0x00
PREC=0x00 |
The Type Of Service, “Type” field
The Type Of Service, “Precedence” field |
| TTL=127 | The remaining Time To Live is 127 hops. |
| ID=4286
DF |
The unique ID for this IP datagram, shared by all fragments if fragmented
Do not Fragment flag |
| PROTO=TCP | The protocol name |
| SPT=2821
DPT=22 WINDOW=65535 |
The source port
The destination port The number of bits specified on the “Window Scale” TCP option |
| RES=0x00 | The reserved bits |
| SYN
URGP=0 |
The synchronize flag which is only exchanged at TCP connection establishment
The urgent flag |
Applicable to:
NS-series Sensors