| User | TTY | From IP | Login time |
|---|---|---|---|
| admin | pts/0 | 203.0.113.20 | Oct 11 18:20 |
| admin | pts/1 | 203.0.113.20 | Oct 11 17:34 |
| User | TTY | From IP | Login time |
|---|---|---|---|
| admin | pts/0 | 203.0.113.20 | 11.10.2026 19:22 |
| admin | pts/1 | 203.0.113.20 | 11.10.2026 12:09 |
| admin | pts/2 | 203.0.113.20 | 11.10.2026 12:10 |
SSH is the way in, so it is the first thing worth watching. This page shows who is connected now, who connected recently and from where, and the failed attempts grouped by source address.
The failure list looks alarming on any server with a public address, and mostly is not. Automated scanning against port 22 is constant and undirected — thousands of attempts against root, admin, test and a dictionary of common names, from addresses that will never return. What deserves attention is different in shape: attempts against a username that actually exists on this machine, repeated attempts from a single address that persists across days, or a successful login from somewhere none of your people are.
The way to make this page quiet is to remove what the noise is aiming at. Disable password authentication entirely and require keys; the automated traffic keeps arriving but can no longer succeed at anything. Fail2ban then reduces the volume, and the successful logins list becomes short enough to read at a glance — which is the point.