import re
from systemd import journal
-from logparse.formatting import *
-from logparse.util import resolve
from logparse import config
+from logparse.formatting import *
from logparse.load_parsers import Parser
+from logparse.util import resole
class SshdJournald(Parser):
section = Section("ssh")
j = journal.Reader()
- j.this_boot()
- j.log_level(journal.LOG_DEBUG)
+ j.this_machine()
+ j.log_level(journal.LOG_INFO)
j.add_match(_COMM="sshd")
+ j.seek_realtime(section.period.startdate)
messages = [entry["MESSAGE"] for entry in j if "MESSAGE" in entry]