When auditctl -s shows a larger lost value than the previous sample, the Linux Audit trail already has a gap. Those discarded records cannot be recovered by emptying the queue, restarting auditd, or increasing -b. The safe response is to preserve the loss boundary, find why records ...
kex_exchange_identification: read: Connection reset by peer does not prove an SSH password, key or account problem. When the server log also reports beginning MaxStartups throttling or dropped pre-authentication connections, OpenSSH is refusing some new handshakes because too many connections have not authenticated yet.
Existing administrator sessions can remain ...