<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[沧海一粟]]></title> 
<link>http://www.dzhope.com/index.php</link> 
<description><![CDATA[Web系统架构与服务器运维,php开发]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[沧海一粟]]></copyright>
<item>
<link>http://www.dzhope.com/post//</link>
<title><![CDATA[Nginx/Apache日志分析脚本 ]]></title> 
<author>jed &lt;jed521@163.com&gt;</author>
<category><![CDATA[服务器技术]]></category>
<pubDate>Sat, 04 Jun 2011 04:33:25 +0000</pubDate> 
<guid>http://www.dzhope.com/post//</guid> 
<description>
<![CDATA[ 
	1,查看apache进程:<br/><div class="code"><br/>ps aux &#124; grep httpd &#124; grep -v grep &#124; wc -l<br/></div><br/>2,查看80端口的tcp连接:<br/><div class="code"><br/>netstat -tan &#124; grep &quot;ESTABLISHED&quot; &#124; grep &quot;:80&quot; &#124; wc -l<br/></div><br/><br/>3,通过日志查看当天ip连接数，过滤重复:<br/><div class="code"><br/>cat access_log &#124; grep &quot;20/Oct/2008&quot; &#124; awk &#039;&#123;print $2&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr<br/></div><br/><br/>4,当天ip连接数最高的ip都在干些什么(原来是蜘蛛):<br/><div class="code"><br/>cat access_log &#124; grep &quot;20/Oct/2008:00&quot; &#124; grep &quot;122.102.7.212&quot; &#124; awk &#039;&#123;print $8&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr &#124; head -n 10<br/></div><br/>5,当天访问页面排前10的url:<br/><div class="code"><br/>cat access_log &#124; grep &quot;20/Oct/2008:00&quot; &#124; awk &#039;&#123;print $8&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr &#124; head -n 10<br/></div><br/>6,用tcpdump嗅探80端口的访问看看谁最高<br/><div class="code"><br/>tcpdump -i eth0 -tnn dst port 80 -c 1000 &#124; awk -F&quot;.&quot; &#039;&#123;print $1&quot;.&quot;$2&quot;.&quot;$3&quot;.&quot;$4&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr<br/></div><br/><br/>接着从日志里查看该ip在干嘛:<br/><div class="code"><br/>cat access_log &#124; grep 122.102.7.212&#124; awk &#039;&#123;print $1&quot;&#92;t&quot;$8&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr &#124; less<br/></div><br/><br/>7,查看某一时间段的ip连接数:<br/><div class="code"><br/>grep &quot;2006:0&#91;7-8&#93;&quot; www20060723.log &#124; awk &#039;&#123;print $2&#125;&#039; &#124; sort &#124; uniq -c&#124; sort -nr &#124; wc -l<br/></div><br/>&nbsp;&nbsp;<br/>==============================nginx<br/><div class="code"><br/>log_format main &#039;&#91;$time_local&#93; $remote_addr $status $request_time $body_bytes_sent &quot;$request&quot; &quot;$http_referer&quot;&#039;;<br/>access_log&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;/data0/logs/access.log&nbsp;&nbsp;main;<br/></div><br/><br/> <br/><br/> <br/><br/>格式如下：<br/><div class="code"><br/>&#91;21/Mar/2011:11:52:15 +0800&#93; 58.60.188.61 200 0.265 28 &quot;POST /event/time HTTP/1.1&quot; &quot;http://host/loupan/207846/feature&quot;<br/></div><br/><br/><br/>通过日志查看当天ip连接数，过滤重复<br/><div class="code"><br/>cat access.log &#124; grep &quot;20/Mar/2011&quot; &#124; awk &#039;&#123;print $3&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr<br/></div><br/>38 112.97.192.16<br/>&nbsp;&nbsp;&nbsp;&nbsp; 20 117.136.31.145<br/>&nbsp;&nbsp;&nbsp;&nbsp; 19 112.97.192.31<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;3 61.156.31.20<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;2 209.213.40.6<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 222.76.85.28<br/><br/> <br/><br/>当天访问页面排前10的url:<br/><div class="code"><br/>cat access.log &#124; grep &quot;20/Mar/2011&quot; &#124; awk &#039;&#123;print $8&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr &#124; head -n 10<br/></div><br/><br/> <br/><br/>找出访问次数最多的10个IP<br/><div class="code"><br/>awk &#039;&#123;print $3&#125;&#039; access.log &#124;sort &#124;uniq -c&#124;sort -nr&#124;head<br/></div><br/><br/>&nbsp;&nbsp;10680 10.0.21.17<br/>&nbsp;&nbsp; 1702 10.0.20.167<br/>&nbsp;&nbsp;&nbsp;&nbsp;823 10.0.20.51<br/>&nbsp;&nbsp;&nbsp;&nbsp;504 10.0.20.255<br/>&nbsp;&nbsp;&nbsp;&nbsp;215 58.60.188.61<br/>&nbsp;&nbsp;&nbsp;&nbsp;192 183.17.161.216<br/>&nbsp;&nbsp;&nbsp;&nbsp; 38 112.97.192.16<br/>&nbsp;&nbsp;&nbsp;&nbsp; 20 117.136.31.145<br/>&nbsp;&nbsp;&nbsp;&nbsp; 19 112.97.192.31<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;6 113.106.88.10<br/><br/> <br/><br/> <br/><br/>找出某天访问次数最多的10个IP<br/><div class="code"><br/>cat /tmp/access.log &#124; grep &quot;20/Mar/2011&quot; &#124;awk &#039;&#123;print $3&#125;&#039;&#124;sort &#124;uniq -c&#124;sort -nr&#124;head<br/></div><br/>&nbsp;&nbsp;&nbsp;&nbsp; 38 112.97.192.16<br/>&nbsp;&nbsp;&nbsp;&nbsp; 20 117.136.31.145<br/>&nbsp;&nbsp;&nbsp;&nbsp; 19 112.97.192.31<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;3 61.156.31.20<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;2 209.213.40.6<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 222.76.85.28<br/><br/> <br/><br/> <br/><br/><br/>当天ip连接数最高的ip都在干些什么:<br/><div class="code"><br/>cat access.log &#124; grep &quot;10.0.21.17&quot; &#124; awk &#039;&#123;print $8&#125;&#039; &#124; sort &#124; uniq -c &#124; sort -nr &#124; head -n 10<br/></div><br/>224 /test/themes/default/img/logo_index.gif<br/>&nbsp;&nbsp;&nbsp;&nbsp;224 /test/themes/default/img/bg_index_head.jpg<br/>&nbsp;&nbsp;&nbsp;&nbsp;224 /test/themes/default/img/bg_index.gif<br/>&nbsp;&nbsp;&nbsp;&nbsp;219 /test/vc.php<br/>&nbsp;&nbsp;&nbsp;&nbsp;219 /<br/>&nbsp;&nbsp;&nbsp;&nbsp;213 /misc/js/global.js<br/>&nbsp;&nbsp;&nbsp;&nbsp;211 /misc/jsext/popup.ext.js<br/>&nbsp;&nbsp;&nbsp;&nbsp;211 /misc/js/common.js<br/>&nbsp;&nbsp;&nbsp;&nbsp;210 /sladmin/home<br/>&nbsp;&nbsp;&nbsp;&nbsp;197 /misc/js/flib.js<br/><br/> <br/><br/><br/>找出访问次数最多的几个分钟<br/><div class="code"><br/> awk &#039;&#123;print $1&#125;&#039; access.log &#124; grep &quot;20/Mar/2011&quot; &#124;cut -c 14-18&#124;sort&#124;uniq -c&#124;sort -nr&#124;head<br/></div><br/>&nbsp;&nbsp;&nbsp;&nbsp; 24 16:49<br/>&nbsp;&nbsp;&nbsp;&nbsp; 19 16:17<br/>&nbsp;&nbsp;&nbsp;&nbsp; 16 16:51<br/>&nbsp;&nbsp;&nbsp;&nbsp; 11 16:48<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;4 16:50<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;3 16:52<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 20:09<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 20:05<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 20:03<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1 19:55<br/><br/><br/>Tags - <a href="http://www.dzhope.com/tags/apache/" rel="tag">apache</a> , <a href="http://www.dzhope.com/tags/nginx/" rel="tag">nginx</a> , <a href="http://www.dzhope.com/tags/%25E7%25BD%2591%25E7%25AB%2599%25E6%2597%25A5%25E5%25BF%2597/" rel="tag">网站日志</a>
]]>
</description>
</item><item>
<link>http://www.dzhope.com/post//#blogcomment</link>
<title><![CDATA[[评论] Nginx/Apache日志分析脚本 ]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.dzhope.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>