1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103
|
#!/usr/bin/perl
$Detail = $ENV{'LOGWATCH_DETAIL_LEVEL'};
$IgnoreUnmatched = $ENV{'vsftpd_ignore_unmatched'};
$TotalBytesOut = 0;
$TotalBytesIn = 0;
while (defined($ThisLine = <STDIN>)) {
if ( ( $ThisLine =~ /CONNECT/ ) or
( $ThisLine =~ /MKDIR/ ) ){
# We don't care about these
} elsif ( ($IP,$Email) = ( $ThisLine =~ /OK LOGIN: Client \"(.*)\", anon password \"(.*)\"$/ ) ) {
$Temp = " (" . $IP . "): " . $Email . " - ";
$AnonLogins{$Temp}++;
} elsif ( ($PID, $User,$IP) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] OK LOGIN: Client \"(.*)\"$/ ) ) {
$Temp = " (" . $IP . "): " . $User . " - ";
$UserLogins{$Temp}++;
} elsif ( ($PID,$User,$IP) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] FAIL LOGIN: Client \"(.*)\"$/ ) ) {
$Temp = " (" . $IP . "): " . $User . " - ";
$FailedLogins{$Temp}++;
} elsif ( ($PID,$User,$IP,$FileName,$FileSize) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] OK UPLOAD: Client \"(.*)\", \"(.*)\", ([0123456789]+) bytes/ ) ) {
$Temp = " " . $FileName . " <- " . $IP . " (User: " . $User . ")\n";
$TotalBytesIn+= $FileSize;
push @UploadedFiles,$Temp;
} elsif ( ($PID,$User,$IP,$FileName,$FileSize) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] FAIL UPLOAD: Client \"(.*)\", \"(.*)\", ([0123456789]+) bytes/ ) ) {
$Temp = " " . $FileName . " <- " . $IP . " (User: " . $User . ")\n";
$TotalBytesIn+= $FileSize;
push @FailedUploadedFiles,$Temp;
} elsif ( ($PID,$User,$IP,$FileName,$FileSize) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] OK DOWNLOAD: Client \"(.*)\", \"(.*)\", ([0123456789]+) bytes/ ) ) {
$Temp = " " . $FileName . " -> " . $IP . " (User: " . $User . ")\n";
$TotalBytesOut+= $FileSize;
push @DownloadedFiles,$Temp;
} elsif ( ($PID,$User,$IP,$FileName,$FileSize) = ( $ThisLine =~ /\[(.*)\] \[(.*)\] FAIL DOWNLOAD: Client \"(.*)\", \"(.*)\", ([0123456789]+) bytes/ ) ) {
$Temp = " " . $FileName . " -> " . $IP . " (User: " . $User . ")\n";
$TotalBytesOut+= $FileSize;
push @FailedDownloadedFiles,$Temp;
} else {
# Report any unmatched entries...
push @OtherList,$ThisLine;
}
}
if ( (keys %AnonLogins) and ($Detail >= 5) ) {
print "\nAnonymous FTP Logins:\n";
foreach $ThisOne (keys %AnonLogins) {
print $ThisOne . $AnonLogins{$ThisOne} . " Time(s)\n";
}
}
if (keys %UserLogins) {
print "\nUser FTP Logins:\n";
foreach $ThisOne (keys %UserLogins) {
print $ThisOne . $UserLogins{$ThisOne} . " Time(s)\n";
}
}
if (keys %FailedLogins) {
print "\nFailed FTP Logins:\n";
foreach $ThisOne (keys %FailedLogins) {
print $ThisOne . $FailedLogins{$ThisOne} . " Time(s)\n";
}
}
$TotalKBytesOut = int $TotalBytesOut/1024;
$TotalKBytesIn = int $TotalBytesIn/1024;
$TotalMBytesOut = int $TotalKBytesOut/1024;
$TotalMBytesIn = int $TotalKBytesIn/1024;
if ( ( $#UploadedFiles >= 0 ) or
( $#FailedUploadedFiles >= 0 ) ) {
if ( $#UploadedFiles >= 0) {
print "\nIncoming FTP Files:\n";
print @UploadedFiles;
}
if ( $#FailedUploadedFiles >= 0) {
print "\nFailed Uploads\n";
print @FailedUploadedFiles;
}
print "\nTOTAL KB IN: " . $TotalKBytesIn . "KB (" . $TotalMBytesIn . "MB)\n";
}
if ( ( $#DownloadedFiles >= 0 ) or
( $#FailedDownloadedFiles >=0 ) ) {
if ( $#DownloadedFiles >= 0) {
print "\nOutgoing FTP Files:\n";
print @DownloadedFiles;
}
if ( $#FailedDownloadedFiles >= 0) {
print "\nFailed Downloads\n";
print @FailedDownloadedFiles;
}
print "\nTOTAL KB OUT: " . $TotalKBytesOut . "KB (" . $TotalMBytesOut . "MB)\n";
}
if (($#OtherList >= 0) and (not $IngoreUnmatched)){
print "\n**Unmatched Entries**\n";
print @OtherList;
}
exit(0);
# vi: shiftwidth=3 tabstop=3 et
|