A Python tool which parses SSH authentication logs, counts the log attempts, correctly formats the results, prints and provides a warning of multiple failed login attempts. It also contains a per-IP tally which has a threshold set at 5 or more failed login attempts. Meant to be used as a simulation for creating a script to notify of brute-force attacks and also parsing through logs.
The primary purpose of this project was two separate goals:
- Create a project which would give me an introduction to critical tools within Python
- Build something which can give me a starting place for any type of log parsing/log analysis.
This was one of the earlier projects within my Python learning journey which took a step above basic/simple functions (calculator, timer, number guesser, etc.). This was an introduction to .split(), indexing and dictionaries all of which are demonstrated within the project as core components.
Requires Python 3.6+ (uses f-strings). No external dependencies. Place the log file to be analyzed in the same directory as logchecker.py, named sample_auth.log, then run:
py logchecker.py
Any source IP with 5 or more failed password attempts prints a [WARNING] line to the terminal.
The results are displayed clearly and directly showing source IP addresses which have 5 failed attempts or more.
Both the attacking IP in addition to the specific number of failed attempts are displayed with a [WARNING] message.
198.51.100.7 appears in the sample log with 3 failed attempts and is correctly excluded, along with successful logins and [preauth] lines.

- Input filename is hardcoded as sample_auth.log; no command-line argument
- No error handling - a missing file raises FileNotFoundError and exits
- Threshold is hardcoded at 5 and not configurable
- Parsing assumes standard OpenSSH syntax. A line containing "Failed password" and "from " but no " port" would produce a malformed key rather than being skipped
- Only detects "Failed password" events. Other authentication failure types (publickey failures, "Invalid user" preauth lines) are not counted
All of the IPs provided in the sample_auth.log come from RFC 5737 documentation ranges. The sample_auth.log included within the project is actually directly generated by a script from the AWS Serverless log parser project which can be found here: Failed-Login_Parser
This project proved to be the catalyst for what eventually became my AWS Serverless log parser. I realized that through the use of AWS services such as S3, DynamoDB and Lambda I could simulate logs being input into an S3 bucket and displayed as attacking IPs, mimicking an environment and situation which I would encounter as a SOC Analyst.