๐ Linux Log ็ฃๆง่ชๅๅ:ๆดๅ GoAccess、Systemd ่ Fail2Ban ๅ ฑ่กจๅๆ
ๅจ Linux ็ณป็ตฑ็ถญ้ไธญ,Log ๅๆๅพๅพๆฑบๅฎไบๅ้กๆๆฅๆ็。 ๆฌ็ฏๆไฝ ๅฆไฝ็ตๅ GoAccess、Systemd ่ Fail2Ban,ๆ้ ไธๅฅ่ชๅๅๅฎๅ จ็ฃๆงๅ ฑ่กจ, ๅณๆ่งๅฏ้ฃ็ท่ก็บ、ๅฐ้ๆกๆ IP ไธฆ็ๆๅฏ่ฆๅๅ่กจๆฟ。
ไธ、็ฐๅข่ๅฎ่ฃ
# ๅฎ่ฃ GoAccess
sudo apt install goaccess -y
# ๅฎ่ฃ Fail2Ban
sudo apt install fail2ban -y
ไบ、ๆดๅ systemd-journal ่ GoAccess
ไฝฟ็จ journalctl ๅฏๅบๆฅ่ชไธฆ่ฎ GoAccess ๅณๆๅๆ:
journalctl -u nginx.service -f | goaccess -o /var/www/html/report.html --log-format=COMBINED
ไธ、็ตๅ Fail2Ban ่่ชๅๅๅฐ้
ๅปบ็ซ่ชๅๅฐ้่้็ฅๆฉๅถ:
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 5
ๅ、่ชๅๅๅ ฑ่กจๆ็จ
้้ systemd timer ๅฎๆ่ผธๅบ GoAccess ๅ ฑ่กจ:
# /etc/systemd/system/goaccess-report.service
[Service]
Type=oneshot
ExecStart=/usr/bin/goaccess /var/log/nginx/access.log -o /var/www/html/report.html --log-format=COMBINED
# /etc/systemd/system/goaccess-report.timer
[Timer]
OnCalendar=hourly
Persistent=true
WantedBy=timers.target
๐ ็ต่ช
็ตๅ GoAccess、systemd ่ Fail2Ban,ไธๅ ่ฝ่ชๅๅๅฎๅ จ็ฃๆง, ๆด่ฝๅฐ็ณป็ตฑ็ถญ้่ฝ็บๆธๆๅ่ๅฏ่ฆๅ็ฎก็, ๆฏไธญๅฐไผๆฅญ่ๅฏฆ้ฉๅฎค็ฐๅขไธญๆๅ ทๆๆฌๆ็็ๆนๆกไนไธ。
๐ ๅปถไผธ้ฑ่ฎ
- ๐ง๐งฑ Linux Proxy Server ๅปบ็ฝฎๆๅญธ
- ๐ง Linux systemd ๆทฑๅ ฅ่งฃๆ่ๅๅๆต็จ็ฎก็
- ๐ Linux Log ๅณๆๅๆ:GoAccess ่ฆ่ฆบๅๅ ฑ่กจ
— WWFandy・็ณป็ตฑ่็ถฒ่ทฏ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ