#!/usr/bin/env python3 import sqlite3 from datetime import datetime db = sqlite3.connect("sshd_failures.db") for row in db.execute(""" SELECT g.country, COUNT(*) AS total, MAX(f.ts) AS last_seen, ( SELECT f2.ip FROM failures f2 JOIN ip_geo g2 ON f2.ip = g2.ip WHERE g2.country = g.country GROUP BY f2.ip ORDER BY COUNT(*) DESC LIMIT 1 ) AS top_ip FROM failures f JOIN ip_geo g ON f.ip = g.ip GROUP BY g.country ORDER BY total DESC """): country, total, last_seen, top_ip = row if last_seen: last_seen = datetime.fromtimestamp(last_seen) print(f"{country:25} {total:6} top_ip={top_ip:18} last={last_seen}") db.close()