R
RobO
Greetings,
Anybody willing to lend me a helping hand?
I am trying to split IP addresses from ports and count the destination
ports with the most hits and source IP addresses with the most hits
from log files.
For example the line below shows a log entry:
##################
#2005-06-13 00:19:03 Local5.Info 10.3.1.1 %SEC-6-IPACCESSLOGP: list
INGRESS1 denied udp 202.97.175.52(4864) -> xxx.xxx.xxx.xxx(1434), 1
packet
##################
As you can see port 1434/udp is being logged as destination port, is it
possible(sure it is) to count the matching ports and return the most
hit ports in the logfile?
The log file is tab seperated and I can count the matching IP addresses
when it is an ICMP log and the IP addresses are on their own, as below.
##################
#2005-06-13 00:17:27 Local5.Info 10.3.1.1 %SEC-6-IPACCESSLOGDP: list
INGRESS1 denied icmp 81.139.2.31 -> xxx.xxx.xxx.xxx (3/13), 1 packet
##################
But with the IP_ADDRESS(port) log entry I am stupified as to how to
separate them and count.
Hope this makes sense!
Any help will be greatly appreciated and thanks in advance.
Rob
Anybody willing to lend me a helping hand?
I am trying to split IP addresses from ports and count the destination
ports with the most hits and source IP addresses with the most hits
from log files.
For example the line below shows a log entry:
##################
#2005-06-13 00:19:03 Local5.Info 10.3.1.1 %SEC-6-IPACCESSLOGP: list
INGRESS1 denied udp 202.97.175.52(4864) -> xxx.xxx.xxx.xxx(1434), 1
packet
##################
As you can see port 1434/udp is being logged as destination port, is it
possible(sure it is) to count the matching ports and return the most
hit ports in the logfile?
The log file is tab seperated and I can count the matching IP addresses
when it is an ICMP log and the IP addresses are on their own, as below.
##################
#2005-06-13 00:17:27 Local5.Info 10.3.1.1 %SEC-6-IPACCESSLOGDP: list
INGRESS1 denied icmp 81.139.2.31 -> xxx.xxx.xxx.xxx (3/13), 1 packet
##################
But with the IP_ADDRESS(port) log entry I am stupified as to how to
separate them and count.
Hope this makes sense!
Any help will be greatly appreciated and thanks in advance.
Rob