Pylogsparser : a use case, analysing ssh attacks. In this article we will see how easy it is to use the pylogsparser library through a simple use case.

Pylogsparser : a use case, analysing ssh attacks

It should help you start working on your own project involving log analysis. The problem Here at Wallix we mostly switched to using VPN links when we need to access local resources from the outside world, and all inbound SSH traffic is redirected to a small unused server, completely isolated in our firewall’s DMZ. We could have simply shut down the service, but it is more interesting to keep it up as a kind of “honeypot”, giving us insight on what happens to any machine exposed to the Internet. The solution We will use a few python libraries to tackle our problem : the pylogsparser library, obviously, will be used to parse the SSH logs;the matplotlib library will be used to plot pie charts related to our findings;the GeoIP library will be used to translate incoming IPs into countries of origin;the numpy library will be used once to define a pretty color map for our pie charts.

