Filters the SSH service's current-boot journal entries for failed password lines, revealing how much password guessing the box is absorbing — the justification for key-only auth and fail2ban. The journal often holds lines that log rotation has already purged from /var/log/auth.log. Pair with wc -l for a count.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.