Unsuccessful login attempts events in audit log from unknown host
Applies to
- ONTAP 9
- SSH
- Event Management System (EMS)
Issue
- Security audit logs shows unknown host and internal as source IP address for a SSH authentication log.
- Logs shows failure events , exactly the same time there is a successful event.
- Successful login attempt has the source IP, however the failed attempt has the "internal:audit" event.
Audit log
00000003.0023595c 00abe53e Mon Jun 19 2023 14:39:57 +01:00 [kern_audit:info:4159] 0000000000000000 :: unknown:ssh :: internal:audit :: cluster001:admin :: Login Attempt :: Error: Unsuccessful attempts since last login :1.
00000003.0023595d 00abe53e Mon Jun 19 2023 14:39:57 +01:00 [kern_audit:info:4159] 8003e80000024be3:8003e80000024be4 :: lonprntcvop001:ssh :: 10.18.xx.xxx:xxxx :: cluster001:admin :: Logging in :: Success