【Mod_security⑧】攻撃元IPごとの発生回数をカウントしファイル出力

mkdir -p /usr/local/mod_security_summary/statistic/client/`date +%Y%m%d`
find /usr/local/mod_security_summary/`date +%Y%m%d`/ -type f | xargs grep REQUEST_HEADERS:Host | grep ModSecurity: | cut -d ""]"" -f 10,4 | tr -d ""\""[clientdata "" | sed s/]/,/g > /usr/local/mod_security_summary/statistic/client/`date +%Y%m%d`/No8
cat /usr/local/mod_security_summary/statistic/client/`date +%Y%m%d`/No8 | while read line;do severity=$line; echo -n ""$severity"""","";grep $severity /usr/local/mod_security_summary/statistic/client/`date +%Y%m%d`/No8 | wc -l ; done | sort | uniq | sed  '1s/^/date,host,client,count\n/'  | sed "s/^/`date +%Y%m%d`,/g"

コメント

タイトルとURLをコピーしました