{"id":14331,"date":"2025-12-30T10:57:55","date_gmt":"2025-12-30T05:27:55","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=14331"},"modified":"2026-09-07T11:13:20","modified_gmt":"2026-09-07T05:43:20","slug":"how-to-monitor-secure-ssh-on-linux-server","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/how-to-monitor-secure-ssh-on-linux-server\/","title":{"rendered":"How to Monitor &amp; Secure SSH on Linux Server &#8211; Easy Guide"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Monitoring and securing SSH on a Linux server<\/strong> means continuously watching SSH logs for suspicious activity, enforcing key-based authentication, restricting access with a firewall, and hardening sshd_config with best practices. Combine real-time protections (Fail2ban\/CrowdSec), two-factor authentication, and regular patching to reduce brute-force attacks, account compromise, and misconfiguration risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you manage Linux servers, learning how to monitor and secure SSH on a Linux server is non-negotiable. SSH is the default remote access method and a top target for automated bots. In this guide, I\u2019ll show you how to harden sshd_config, set up real-time monitoring and alerts, and implement layered defenses\u2014without locking yourself out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-threats-target-ssh-and-what-to-watch\">What Threats Target SSH and What to Watch<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.youstable.com\/blog\/what-is-fail2ban-on-linux-server\/\">SSH faces constant brute-force<\/a> attempts, credential stuffing, and privilege escalation attempts. Your defense starts with visibility. Know where to look and what \u201cbad\u201d looks like in your logs and metrics.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"key-log-signals\"><strong>Key log signals<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repeated \u201cFailed password\u201d or \u201cInvalid user\u201d entries from the same IP<\/li>\n\n\n\n<li>Logins at odd hours, from unfamiliar countries or networks<\/li>\n\n\n\n<li>Frequent disconnects at authentication (bot scans)<\/li>\n\n\n\n<li>Root login attempts and sudo authentication failures<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"core-metrics-to-track\"><strong>Core metrics to track<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Authentication success\/failure rates and spikes per IP<\/li>\n\n\n\n<li>Number of banned IPs (Fail2ban\/CrowdSec)<\/li>\n\n\n\n<li>New public keys added, user changes, and sudoers edits<\/li>\n\n\n\n<li>SSH daemon restarts, configuration changes, and kernel updates<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"quick-ssh-security-checklist\"><strong>Quick SSH Security Checklist<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use key-based authentication; disable passwords<\/li>\n\n\n\n<li>Disable direct root login<\/li>\n\n\n\n<li>Restrict users\/groups allowed to SSH<\/li>\n\n\n\n<li>Enable Fail2ban or CrowdSec to block brute-force IPs<\/li>\n\n\n\n<li><strong>Firewall:<\/strong> allow SSH only from trusted IPs where possible<\/li>\n\n\n\n<li>Set idle timeouts and lockout policies<\/li>\n\n\n\n<li>Enable 2FA (TOTP) for privileged accounts<\/li>\n\n\n\n<li>Monitor logs, enable alerts, and patch OpenSSH regularly<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-to-monitor-ssh-access-in-real-time\"><strong>How to Monitor SSH Access in Real Time<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"inspect-ssh-logs-quickly\"><strong>Inspect SSH logs quickly<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Most Debian\/Ubuntu systems log to \/var\/log\/auth.log, while RHEL\/CentOS\/AlmaLinux use \/var\/log\/secure. With systemd, journalctl is often the fastest lens.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># See SSH activity today\nsudo journalctl -u ssh -S today\n\n# Tail SSH logs live (Debian\/Ubuntu)\nsudo tail -f \/var\/log\/auth.log\n\n# Tail SSH logs live (RHEL\/CentOS\/AlmaLinux)\nsudo tail -f \/var\/log\/secure\n\n# Top failing IPs (Debian\/Ubuntu)\nsudo grep \"Failed password\" \/var\/log\/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr | head\n\n# List recent successful and failed logins\nlast\nlastb  # failed logins (requires btmp)<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"block-brute-force-attacks-with-fail2ban\"><strong>Block brute-force attacks with Fail2ban<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fail2ban reads your logs and bans offending IPs at the firewall automatically, a core component of SSH hardening.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Install\n# Debian\/Ubuntu\nsudo apt update &amp;&amp; sudo apt <a href=\"https:\/\/www.youstable.com\/blog\/install-fail2ban-on-linux\/\">install -y fail2ban<\/a>\n# RHEL\/CentOS\/AlmaLinux\nsudo dnf install -y fail2ban\n\n# Enable and start\nsudo systemctl enable --now fail2ban\n\n# Create jail override\nsudo tee \/etc\/fail2ban\/jail.d\/sshd.local &gt;\/dev\/null &lt;&lt;'EOF'\n&#91;sshd]\nenabled = true\nport    = ssh\nfilter  = sshd\nlogpath = %(sshd_log)s\nmaxretry = 4\nfindtime = 10m\nbantime  = 24h\nignoreip = 127.0.0.1\/8 ::1\nEOF\n\n# Reload and check status\nsudo systemctl restart fail2ban\nsudo fail2ban-client status sshd<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Tip:<\/strong> Use ignoreip to whitelist your office\/VPN. For cloud servers, combine with provider-level firewalls for defense-in-depth.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"audit-ssh-changes-and-logins-with-auditd\"><strong>Audit SSH changes and logins with auditd<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use Linux Audit to track critical SSH events (config edits, daemon execs, auth changes).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Install\nsudo apt install -y auditd || sudo dnf install -y audit\n\n# Watch sshd_config changes\nsudo auditctl -w \/etc\/ssh\/sshd_config -p wa -k ssh_config\n\n# Track sshd execution (may vary by distro path)\nsudo auditctl -a always,exit -F arch=b64 -S execve -F exe=\/usr\/sbin\/sshd -k sshd_exec\n\n# Query recent related events\nsudo ausearch -k ssh_config\nsudo ausearch -k sshd_exec | aureport -x --summary<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For larger fleets, forward logs to a SIEM or a centralized stack (Elastic, Graylog, Wazuh) and set threshold alerts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"harden-sshd_config-step-by-step\"><strong>Harden sshd_config (Step-by-Step)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"back-up-and-test-safely\"><strong>Back up and test safely<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo cp \/etc\/ssh\/sshd_config \/etc\/ssh\/sshd_config.bak.$(date +%F)\n# Keep an existing SSH session open while reloading to avoid lockout\nsudo sshd -t    # syntax check\nsudo systemctl reload sshd<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"recommended-baseline-options\"><strong>Recommended baseline options<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">These settings implement key-based auth, restrict accounts, reduce attack surface, and improve safety. Adjust for your distro and compliance policy.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/ssh\/sshd_config (excerpt)\nProtocol 2\n# Optional: changing port reduces noise but is not a security control\n# Port 22\n\nPermitRootLogin no\nPasswordAuthentication no\nKbdInteractiveAuthentication no\nPubkeyAuthentication yes\n\n# Restrict to known users or groups\nAllowUsers deploy adminuser\n# or\n# AllowGroups sshusers\n\n# Limit auth attempts and connection bursts\nMaxAuthTries 3\nMaxStartups 10:30:60\nLoginGraceTime 20\n\n# Disconnect idle sessions\nClientAliveInterval 300\nClientAliveCountMax 2\n\n# Modern defaults in OpenSSH are secure; only pin ciphers if required\n# Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes256-ctr\n# MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com\n\n# Log more detail\nLogLevel VERBOSE\n\n# Banner to warn unauthorized users\nBanner \/etc\/issue.net<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">After editing, validate with sshd -t and reload. Always test from a second terminal before closing your admin session.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"firewall-and-rate-limiting\"><strong>Firewall and Rate Limiting<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ufw-simple-or-nftables-iptables-advanced\"><strong>UFW (simple) or nftables\/iptables (advanced)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># UFW example (Debian\/Ubuntu)\nsudo ufw allow 22\/tcp\n# or restrict to office\/VPN\nsudo ufw allow from 203.0.113.10 to any port 22 proto tcp\nsudo ufw enable\nsudo ufw status\n\n# nftables example (policy-based)\nsudo nft add table inet filter\nsudo nft add chain inet filter input { type filter hook input priority 0 ; }\nsudo nft add rule inet filter input ct state established,related accept\nsudo nft add rule inet filter input iif lo accept\nsudo nft add rule inet filter input tcp dport 22 ip saddr 203.0.113.0\/24 accept\nsudo nft add rule inet filter input tcp dport 22 drop<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Pair your <a href=\"https:\/\/www.youstable.com\/blog\/benefits-of-using-tally-on-cloud-hosting\/\">host firewall with cloud<\/a> security groups. If you change the SSH port, remember to update rules accordingly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"crowdsec-vs-fail2ban-quick-comparison\"><strong>CrowdSec vs. Fail2ban (quick comparison)<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fail2ban:<\/strong> Lightweight, local bans, simple config, great for single servers.<\/li>\n\n\n\n<li><strong>CrowdSec:<\/strong> Community-driven reputation feeds, distributed signals, rich scenarios; ideal for fleets.<\/li>\n\n\n\n<li><strong>Both: <\/strong>Can integrate with iptables\/nftables and export alerts.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"add-2fa-totp-to-ssh\"><strong>Add 2FA (TOTP) to SSH<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two-factor authentication adds a one-time code (Time-based OTP) on top of your <a href=\"https:\/\/www.youstable.com\/blog\/how-to-add-ssh-keys-to-github-account\/\">SSH key<\/a>. This mitigates risks if a key or password is exposed. Apply to privileged users and break-glass accounts.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Install Google Authenticator PAM module\n# Debian\/Ubuntu\nsudo apt install -y libpam-google-authenticator\n# RHEL\/CentOS\/AlmaLinux\nsudo dnf install -y google-authenticator\n\n# Per-user setup (run as each user)\ngoogle-authenticator -t -d -f -r 3 -R 30 -W\n\n# Update PAM (common path; verify on your distro)\n# Add this line near the top of \/etc\/pam.d\/sshd:\n# auth required pam_google_authenticator.so nullok\n\n# Update sshd_config to allow keyboard-interactive for 2FA\nKbdInteractiveAuthentication yes\n# Keep PasswordAuthentication no for key+TOTP flow\nAuthenticationMethods publickey,keyboard-interactive\n\nsudo sshd -t &amp;&amp; sudo systemctl reload sshd<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Test with a secondary session before enforcing across all users. Store emergency scratch codes securely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"set-up-alerts-and-reports\"><strong>Set Up Alerts and Reports<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"email-summaries-with-logwatch\"><strong>Email summaries with Logwatch<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Install and configure\nsudo apt install -y logwatch || sudo dnf install -y logwatch\n# On systemd servers, create a daily timer or use cron\nsudo logwatch --service sshd --range today --detail Med --mailto you@example.com<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For real-time alerting, integrate Fail2ban with an action script to send notifications on bans\/unbans, or forward logs to a SIEM with rules for spikes and anomalies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ongoing-maintenance-and-compliance\"><strong>Ongoing Maintenance and Compliance<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Patch OpenSSH and OS packages regularly; remove deprecated crypto configs as defaults evolve.<\/li>\n\n\n\n<li>Rotate and protect private keys; prefer hardware tokens for high-value access.<\/li>\n\n\n\n<li>Review users, groups, and authorized_keys monthly; remove stale access.<\/li>\n\n\n\n<li>Back up sshd_config and authorized_keys; document change history.<\/li>\n\n\n\n<li>Centralize logs; retain for at least 90 days to support forensics.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"common-mistakes-and-safe-recovery\"><strong>Common Mistakes and Safe Recovery<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Locking yourself out: <\/strong>Always keep one SSH session open while reloading; test from a second terminal.<\/li>\n\n\n\n<li><strong>Over-tuning ciphers: <\/strong>Modern OpenSSH defaults are secure; pin algorithms only if your compliance policy demands it.<\/li>\n\n\n\n<li><strong>Relying on port changes:<\/strong> Non-standard ports reduce noise but don\u2019t replace authentication and monitoring.<\/li>\n\n\n\n<li><strong>Ignoring egress: <\/strong>Attackers often exfiltrate data; monitor unusual outbound connections (use ss, nft, or a NIDS).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"why-this-works-layered-practical-security\"><strong>Why This Works: Layered, Practical Security<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Across 12+ years hardening Linux servers, the most resilient SSH posture combines strong auth (keys + 2FA), minimal access (firewall + AllowUsers), active defense (Fail2ban\/CrowdSec), and continuous visibility (logs + alerts). Each layer compensates for the others, cutting risk without harming uptime.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"need-a-hand-managed-hardening-by-youstable\"><strong>Need a Hand? Managed Hardening by YouStable<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you prefer expert setup, YouStable\u2019s managed servers include SSH hardening, firewall tuning, proactive monitoring, and 24\/7 support. We apply these best practices from day one and keep them aligned with evolving OpenSSH and <a href=\"https:\/\/www.youstable.com\/blog\/optimize-lets-encrypt-on-linux\/\">Linux security<\/a> standards.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs\"><strong>FAQ&#8217;s<\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765953721158\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"1-u003cstrongu003ehow-do-i-check-ssh-logs-in-linuxu003c-strongu003e\">1. u003cstrongu003eHow do I check SSH logs in Linux?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Use journalctl -u ssh -S today on systemd hosts, or tail -f \/var\/log\/auth.log (Debian\/Ubuntu) and tail -f \/var\/log\/secure (RHEL family). For summaries, run last and lastb to view recent successful and failed login attempts.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765953733105\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"2-u003cstrongu003eis-changing-the-default-ssh-port-necessaryu003c-strongu003e\">2. u003cstrongu003eIs changing the default SSH port necessary?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. It reduces bot noise but isn\u2019t a security control. Focus on key-based authentication, disable passwords and root login, enforce firewall rules, and deploy Fail2ban or CrowdSec. If you do change the port, update firewall rules and monitoring.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765953741370\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"3-u003cstrongu003ewhats-the-best-way-to-block-ssh-brute-force-attacksu003c-strongu003e\">3. u003cstrongu003eWhat\u2019s the best way to block SSH brute-force attacks?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Combine Fail2ban or CrowdSec with SSH key-only authentication and a firewall that limits source IPs. Set MaxAuthTries low, enable LoginGraceTime, and monitor for spikes in failed logins with alerting.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765953750471\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"4-u003cstrongu003ehow-do-i-disable-ssh-password-login-safelyu003c-strongu003e\">4. u003cstrongu003eHow do I disable SSH password login safely?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Add your public key to ~\/.ssh\/authorized_keys, verify key login works, then set PasswordAuthentication no in \/etc\/ssh\/sshd_config and reload sshd. Keep an existing session open while testing another to avoid lockout.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765953759345\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"5-u003cstrongu003eshould-i-force-specific-ssh-ciphers-and-macsu003c-strongu003e\">5. u003cstrongu003eShould I force specific SSH ciphers and MACs?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Modern OpenSSH defaults are secure. Only pin Ciphers\/MACs\/KexAlgorithms if required by compliance or to drop legacy clients intentionally. Over-restriction can break automation and older systems; test thoroughly before enforcing.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Monitoring and securing SSH on a Linux server means continuously watching SSH logs for suspicious activity, enforcing key-based authentication, restricting [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":16678,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":79,"footnotes":""},"categories":[350,2259],"tags":[],"class_list":["post-14331","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-kb-linux"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=14331"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14331\/revisions"}],"predecessor-version":[{"id":23330,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14331\/revisions\/23330"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/16678"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=14331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=14331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=14331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}