Bug 2044101

Summary: logwatch sshd report should sort failed logins and illegal users by count, not IP address
Product: Red Hat Enterprise Linux 8 Reporter: Jonathan Kamens <jik>
Component: logwatchAssignee: Pavel Šimovec <psimovec>
Status: ON_QA --- QA Contact: Karel Volný <kvolny>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: CentOS StreamCC: bstinson, jwboyer, psimovec
Target Milestone: rcKeywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: logwatch-7.4.3-20.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
sort failed logins and invalid users by count none

Description Jonathan Kamens 2022-01-23 21:47:08 UTC
Created attachment 1852935 [details]
sort failed logins and invalid users by count

The sections of the sshd report in logwatch that list failed logins by IP and invalid usernames by IP should sort by the count per IP, which is extremely useful, not by the IP address, which is completely useless as a sort metric.

No one wants to see the IP addresses in lexical order. Everyone wants to see the biggest offenders first.

See attached diff.