日志分析
Last updated
Last updated
# 定位IP
$ grep "Failed password for root" /var/log/secure | awk '{print $11}' | sort | uniq -c | sort -
# 查看爆破的字典
$ grep "Failed password" /var/log/secure|perl -e 'while($_=<>){ /for(.*?) from/; print "$1\n";}'| uniq -c | sort -nr$ grep "Accepted " /var/log/secure | awk '{print $11}' | sort | uniq -c | sort -nr | more
# 登录成功的日期、用户名、IP:
$ grep "Accepted " /var/log/secure | awk '{print $1,$2,$3,$9,$11}'# 添加用户
$ grep "useradd" /var/log/secure
# 删除用户
$ grep "userdel" /var/log/secure$ more /var/log/yum.log