Fast extraction of SSH failures with awk
When a server is exposed to the internet, the first line of defense is the log.
In most Linux distributions the file /var/log/auth.log (or /var/log/secure on RHEL‑style systems) contains every authentication event, including failed SSH logins.
If you need a quick snapshot of the last hour’s failures, you can do it in a single awk command that finishes in a fraction of a second, even on a 10‑GB log file.