segt wrote:
First of all, I think its crazy that after just a short amount of time my IP was discovered and set as a target for a dictionary attack.
The Internet is a crazy place — that’s perfectly normal.
segt wrote:
Usually each of these 3 types of messages appear by themselves, but sometimes a single IP will generate all of them. Is there anything here to be worried about? Is there a better way to parse the log file to only look for true threats?
If you truly disabled root and password auth, there isn’t much of anything to worry about (unless something like the Debian OpenSSL screwup happens again).
You can do things to reduce the amount of stuff that gets logged — such as move SSH to a different port, or install fail2ban or DenyHosts — but you don’t really need to.