Split info from auth.log into several parts:
folder="/_logs/"
date >> ${folder}ip_illegal.log
date > ${folder}ip_failed.log
grep -E "invalid user" /var/log/auth*log* | awk '{ print $11, $13 , $15 }' | uniq >> ${folder}ip_invalid_user.log
grep Failed /var/log/auth*log* | awk '{ print $0 }' | uniq >> ${folder}ip_failed.log
grep refused /var/log/auth*log* | awk '{ print $1 $2 $10 }' | uniq > ${folder}ip_refused.log
grep su /var/log/auth*log* | awk '$5 ~/su/{ print $0 }' > ${folder}ip_su.log
grep -v CRON /var/log/auth*.log | grep -v Failed > ${folder}ip_logins.log
grep Illegal /var/log/auth*.log >${folder}ip_illegal_logins.log