ÕûÀíһЩ³£Ó÷ÖÎöÍøÕ¾µÄСÃüÁî·½±ã´ó¼ÒÅÅÕÏ£¬ÄÚÈݾùÀ´Ô´ÓÚÍøÂç¡£
Èç¹ûÄãÊdzõѧÕß¹ØÓÚAWKÓ¦Óü¼ÇÉÇë²ÎÕÕÂÛ̳µÄ½Å±¾±à³Ì°æ¿é£¬
Èç¹ûÄãÊÇÀÏÊÖ£¬Ê²Ã´ºÃµÄÃüÁ»òÕß±Øɱ¼¼»¶Ó¸úÌù£¬·á¸»´ËÌù£¡
ϵͳÁ¬½Ó״̬ƪ£º
1.²é¿´TCPÁ¬½Ó״̬
netstat -nat |awk '{print $6}'|sort|uniq -c|sort -rn
netstat -n | awk '/^tcp/ {++S[$NF]};END {for(a in S) print a, S[a]}' »ò
netstat -n | awk '/^tcp/ {++state[$NF]}; END {for(key in state) print key,"\t",state[key]}'
netstat -n | awk '/^tcp/ {++arr[$NF]};END {for(k in arr) print k,"\t",arr[k]}'
netstat -n |awk '/^tcp/ {print $NF}'|sort|uniq -c|sort -rn
netstat -ant | awk '{print $NF}' | grep -v '[a-z]' | sort | uniq -c
2.²éÕÒÇëÇóÊýÇë20¸öIP£¨³£ÓÃÓÚ²éÕÒ¹¥À´Ô´£©£º
netstat -anlp|grep 80|grep tcp|awk '{print $5}'|awk -F: '{print $1}'|sort|uniq -c|sort -nr|head -n20
netstat -ant |awk '/:80/{split($5,ip,":");++A[ip[1]]}END{for(i in A) print A[i],i}' |sort -rn|head -n20
3.ÓÃtcpdumpÐá̽80¶Ë¿ÚµÄ·ÃÎÊ¿´¿´Ë×î¸ß
tcpdump -i eth0 -tnn dst port 80 -c 1000 | awk -F"." '{print $1"."$2"."$3"."$4}' | sort | uniq -c | sort -nr |head -20
4.²éÕҽ϶àtime_waitÁ¬½Ó
netstat -n|grep TIME_WAIT|awk '{print $5}'|sort|uniq -c|sort -rn|head -n20
5.ÕÒ²é½Ï¶àµÄSYNÁ¬½Ó
netstat -an | grep SYN | awk '{print $5}' | awk -F: '{print $1}' | sort | uniq -c | sort -nr | more
6.¸ù¾Ý¶Ë¿ÚÁнø³Ì
netstat -ntlp | grep 80 | awk '{print $7}' | cut -d/ -f1
ÍøÕ¾ÈÕÖ¾·ÖÎöƪ1£¨Apache£©£º
1.»ñµÃ·ÃÎÊÇ°10λµÄipµØÖ·
cat access.log|awk '{print $1}'|sort|uniq -c|sort -nr|head -10
cat access.log|awk '{counts[$(11)]+=1}; END {for(url in counts) print counts[url], url}'
2.·ÃÎÊ´ÎÊý×î¶àµÄÎļþ»òÒ³Ãæ,È¡Ç°20
cat access.log|awk '{print $11}'|sort|uniq -c|sort -nr|head -20
3.Áгö´«Êä×î´óµÄ¼¸¸öexeÎļþ£¨·ÖÎöÏÂÔØÕ¾µÄʱºò³£Óã©
cat access.log |awk '($7~/\.exe/){print $10 " " $1 " " $4 " " $7}'|sort -nr|head -20
4.ÁгöÊä³ö´óÓÚ200000byte(Ô¼200kb)µÄexeÎļþÒÔ¼°¶ÔÓ¦Îļþ·¢Éú´ÎÊý
cat access.log |awk '($10 > 200000 && $7~/\.exe/){print $7}'|sort -n|uniq -c|sort -nr|head -100
5.Èç¹ûÈÕÖ¾×îºóÒ»ÁмǼµÄÊÇÒ³ÃæÎļþ´«Êäʱ¼ä£¬ÔòÓÐÁгöµ½¿Í»§¶Ë×îºÄʱµÄÒ³Ãæ
cat access.log |awk '($7~/\.php/){print $NF " " $1 " " $4 " " $7}'|sort -nr|head -100
6.Áгö×î×îºÄʱµÄÒ³Ãæ(³¬¹ý60ÃëµÄ)µÄÒÔ¼°¶ÔÓ¦Ò³Ãæ·¢Éú´ÎÊý
cat access.log |awk '($NF > 60 && $7~/\.php/){print $7}'|sort -n|uniq -c|sort -nr|head -100
7.Áгö´«Êäʱ¼ä³¬¹ý 30 ÃëµÄÎļþ
cat access.log |awk '($NF > 30){print $7}'|sort -n|uniq -c|sort -nr|head -20
8.ͳ¼ÆÍøÕ¾Á÷Á¿£¨G)
cat access.log |awk '{sum+=$10} END {print sum/1024/1024/1024}'
9.ͳ¼Æ404µÄÁ¬½Ó
awk '($9 ~/404/)' access.log | awk '{print $9,$7}' | sort
10. ͳ¼Æhttp status.
cat access.log |awk '{counts[$(9)]+=1}; END {for(code in counts) print code, counts[code]}'
cat access.log |awk '{print $9}'|sort|uniq -c|sort -rn
10.Ö©Öë·ÖÎö
²é¿´ÊÇÄÄЩ֩ÖëÔÚץȡÄÚÈÝ¡£
/usr/sbin/tcpdump -i eth0 -l -s 0 -w - dst port 80 | strings | grep -i user-agent | grep -i -E 'bot|crawler|slurp|spider'
ÍøÕ¾ÈÕ·ÖÎö2(Squidƪ£©
2.°´Óòͳ¼ÆÁ÷Á¿
zcat
squid_access.log.tar.gz| awk '{print $10,$7}' |awk 'BEGIN{FS="[
/]"}{trfc[$4]+=$1}END{for(domain in trfc){printf
"%s\t%d\n",domain,trfc[domain]}}'
ЧÂʸü¸ßµÄperl°æ±¾Çëµ½´ËÏÂÔØ:http://docs.linuxtone.org/soft/tools/tr.pl
Êý¾Ý¿âƪ
1.²é¿´Êý¾Ý¿âÖ´ÐеÄsql
/usr/sbin/tcpdump
-i eth0 -s 0 -l -w - dst port 3306 | strings | egrep -i
'SELECT|UPDATE|DELETE|INSERT|SET|COMMIT|ROLLBACK|CREATE|DROP|ALTER|CALL'
ϵͳDebug·ÖÎöƪ
1.µ÷ÊÔÃüÁî
strace -p pid
2.¸ú×ÙÖ¸¶¨½ø³ÌµÄPID
gdb -p pid
¸ü¶àµÄÇë²Î¿¼£º
http://bbs.linuxtone.org/forum-14-1.html
ÍƼöÐÅÏ¢
- linuxÃüÁîѧϰ±Ê¼Ç£¨11£©£ºnlÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨5£©£ºrmÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨4£©£ºmkdirÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨1£©£ºlsÃüÁî
- ½«CentosµÄyumÔ´¸ü»»Îª¹úÄڵİ¢ÀïÔÆÔ´
- ʹÓÃNginxÌí¼Óheader·ÀÖ¹ÍøÒ³±»frame
- linuxϼÓËÙscp´«Êä´óÎļþµÄËÙ¶È
- linuxϵͳÉ϶ÔnginxÈÕÖ¾·Ö¸î´¦Àí
- lnmp/nginxϵͳÕæÕýÓÐЧµÄͼƬ·ÀµÁÁ´ÍêÕûÉèÖÃÏê½â
- Í»ÆÆÊ®Íò²¢·¢µÄNginxµÄÅäÖü°ÓÅ»¯
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- ²éÕÒ²¢É¾³ý.svnĿ¼Îļþ
- redis ÆßÖÖÊý¾ÝÀàÐ͵ÄʹÓó¡¾°
- linux ÏÂÎļþ¸´ÖƵ½windowsÏÂÂÒÂëµÄ½â¾ö°ì·¨
- nginx³öÏÖ502 upstream sent too big he....
- linuxÏÂsudoÅäÖÃÏê½â
- linuxÃüÁîѧϰ±Ê¼Ç£¨15£©£ºtailÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨14£©£ºheadÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨13£©£ºlessÃüÁî
- linuxÃüÁîѧϰ±Ê¼Ç£¨12£©£ºmoreÃüÁî
- ¼ÓÃÜËã·¨±È½Ï3DES AES RSA ECC MD5 SHA1µÈ
ÆÀÂÛ