BACKEND="/usr/lib/x86_64-linux-gnu/sshg-fw-nft-sets" # mail auth authpriv (https://en.wikipedia.org/wiki/Syslog#Facility) #LOGREADER="LANG=C /bin/journalctl -afb -p info -n1 -o cat SYSLOG_FACILITY=2 SYSLOG_FACILITY=4 SYSLOG_FACILITY=10" THRESHOLD=30 BLOCK_TIME=120 DETECTION_TIME=1800 WHITELIST_FILE=/etc/sshguard/whitelist {% if docker is defined %} # docker is there - we also need to check container logs # e.g. gitea runs openssh within FILES="/var/log/mail.log /var/log/auth.log /var/lib/docker/containers/*/*.log" {% else %} FILES="/var/log/mail.log /var/log/auth.log" {% endif %}