Auth.log


Debug logs are located in different files depending on distro:

SSH log overview


For real-time debug logs:

tail -f /var/log/secure    

For last 50 logs:

tail -n 50 /var/log/secure    

For systemd-based distros (Ubuntu, CentOS, etc.):

journalctl -u sshd -n 50   

Find unauthorized sudo attempts:

grep "sudo:" /var/log/auth.log | grep "authentication failure"