Pretty print journalctl messages with extra fields inline
-
Updated
Oct 2, 2018 - Go
Pretty print journalctl messages with extra fields inline
Shipping systemd logs to Elasticsearch in Kibana-friendly format
Practical SOC project demonstrating SSH brute-force detection using Linux logs (journalctl), including attack simulation, log analysis, attacker attribution, and incident investigation aligned with MITRE ATT&CK.
A 100% locally-run Host SOC and Intrusion Detection System (IDS) for Ubuntu Linux featuring real-time journalctl streaming, online anomaly detection with River ML, local SQLite persistence, and an interactive Rich CLI dashboard.
Live heatmap of failed SSH login attempts based on GeoIP. Works on any system that uses journalctl to log sshd. Uses http://geoip.nekudo.com and https://freegeoip.net for GeoIP data.
Some scripts made in Python
Hands on Ubuntu Server administration lab covering installation, networking, OpenSSH, SSH hardening, user and group management, systemd, log management, UFW firewall configuration and Linux server hardening in a virtual environment.
a simple log reader for linux
SOC lab demonstrating SSH brute-force attack using Hydra across two virtual machines and detection using Linux logs (journalctl), including attacker attribution and MITRE ATT&CK mapping.
This guide walks through setting up SSH between two machines on the same network, logging into another system, and managing logs.
journalctl scripts to monitor logs
OPS (Oh Please, Save-me) — A secure C utility to quickly fetch, filter, and save systemd service logs. Because when things break, you need your logs fast
Mobile-first admin panel for Ubuntu servers — systemd, PTY terminal, file editor, journalctl
Bash script to parse Linux system logs (dmesg, journalctl, syslog) — detects kernel panics, OOM kills, disk errors, and service failures with a colour-coded severity summary report.
Turn journalctl and syslog into a ready-to-edit incident postmortem in seconds — timeline, failure patterns, cascading failures and action items.
Simple Flask WebSocket application which sends journalctl data to browser in realtime
Local registry-based CLI for safely tracking, inspecting, and operating selected systemd and launchd services.
To associate your repository with the journalctl topic, visit your repo's landing page and select "manage topics."