Where Are Linux Login Attempts Logged?
Failed and successful logins land in /var/log/auth.log on Debian systems, /var/log/secure on Red Hat ones.
Last updated
Every SSH login, sudo use and password prompt writes to the auth log. It is the first file to open when something accessed your machine or something legitimate got locked out.
The filename splits by distro family. Debian and Ubuntu use auth.log, Red Hat and Fedora use secure, and both rotate through the same logrotate machinery. Journal based systems mirror the same events under the sshd unit.
Where Linux stores this, by platform
/var/log/auth.log
Debian and Ubuntu location for login, sudo and SSH events. Red Hat family uses /var/log/secure instead. Grep for Failed or Accepted to triage, and check rotated auth.log.1 files for older entries.
Frequently asked questions
how do i see failed ssh login attempts
Grep the auth log for Failed: grep 'Failed' /var/log/auth.log. Bursts from one IP mean a bot is knocking. Fail2ban automates blocking if the noise bothers you.
why is there no auth.log on my fedora machine
Red Hat systems log the same events to /var/log/secure instead. The content and rotation work identically; only the filename differs.
is auth.log replaced by the systemd journal
Both exist on most systems. The journal holds the same sshd entries queryable with journalctl _SYSTEMD_UNIT=sshd.service, while the text log suits grep and long term archiving.
Notice an outdated path? Let us know.