[[OT]{slightly} One for the command line weenies
|
|
Thread rating:  |
Jim - 28 Sep 2007 13:17 GMT I want to tail the output of a file that looks like this: Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 192.168.2.2:135 in via rl0 Sep 28 12:36:02 wotan kernel: ipfw: 65435 Deny TCP 212.119.162.40:4227 192.168.2.2:135 in via rl0 Sep 28 12:59:02 wotan kernel: ipfw: 65435 Deny TCP 213.150.54.194:4972 192.168.2.2:53 in via rl0 Sep 28 12:59:05 wotan kernel: ipfw: 65435 Deny TCP 213.150.54.194:4972 192.168.2.2:53 in via rl0
(gah! can't turn line wrapping off - that should be four lines)
However, what I want is to have 'tail' only display this:
Sep 28 12:31:32 212.152.232.68:135 Sep 28 12:36:02 212.119.162.40::135 Sep 28 12:59:02 213.150.54.194:53 Sep 28 12:59:05 213.150.54.194:53
In other words, the dat/time, source IP and destination port.
I imagine it's doable via l33t sed and awk skilz, but I wouldn't really know where to begin.
Essentially I'm trying to get the pertinent parts of my security log tail'd out to a serial port and displayed on a 40col Apple //e screen.
Don't ask why. It's sad.
Jim
 Signature http://www.ursaMinorBeta.co.uk SOTTERLEY (n,) Uncovered bit between two shops with awnings, which you have to cross when it's raining.
ric - 28 Sep 2007 13:33 GMT > I want to tail the output of a file that looks like this: > Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 [quoted text clipped - 30 lines] > Uncovered bit between two shops with awnings, which you have to cross when > it's raining. You're piping the activity of your firewall to a spare Apple IIe for GeekPoints (tm), aren't you? Like your style - I'm a firm believer that the more cryptic text scrolling across monochrome monitors you have in an office, the more retro high tech points you score...
Ric
Jim - 28 Sep 2007 13:38 GMT > You're piping the activity of your firewall to a spare Apple IIe for > GeekPoints (tm), aren't you? er...*cough* might be, yes.
> Like your style - I'm a firm believer that the more cryptic text > scrolling across monochrome monitors you have in an office, the more > retro high tech points you score... I'll be using 300 baud for that _authentic_ retro feel. And a green screen.
If I could just get a Beeb serial cable I'd use a Beeb. Lord knows I've got enough of the buggers. Please don't suggest making one - I'm fully prepared to believe it's easy, but the last time I tried to use a soldering iron...well, pain, smoke, people screaming...
Jim
 Signature http://www.ursaMinorBeta.co.uk TAMPA (n.) The sound of a rubber eraser coming to rest after dropping off a desk in a very quiet room.
James Dore - 28 Sep 2007 14:43 GMT > If I could just get a Beeb serial cable I'd use a Beeb. Lord knows I've got > enough of the buggers. Please don't suggest making one - I'm fully prepared > to believe it's easy, but the last time I tried to use a soldering > iron...well, pain, smoke, people screaming... > > Jim You say that as if it were a Bad Thing. I just love the smell of Fear when I power up my two butane powered babies. One for soldering, one with hot-air nozzle to shrink the heat-shrink :->
 Signature james dore IT Officer, New College, Oxford http://www.new.ox.ac.uk/ it-support@new....
Jim - 28 Sep 2007 14:48 GMT >> If I could just get a Beeb serial cable I'd use a Beeb. Lord knows I've got >> enough of the buggers. Please don't suggest making one - I'm fully prepared [quoted text clipped - 6 lines] > when I power up my two butane powered babies. One for soldering, one > with hot-air nozzle to shrink the heat-shrink :-> Sadly in my case it's more to do with the fact that I am the World's Worst Solderer.
Give me two wires to solder together and I'll solder one to a lamp, the other to my nose, the carpet will be on fire...you get the picture.
Jim
 Signature http://www.ursaMinorBeta.co.uk TINGRITH (n.) The feeling of silver paper against your fillings.
James Dore - 28 Sep 2007 15:39 GMT > >> If I could just get a Beeb serial cable I'd use a Beeb. Lord knows I've got > >> enough of the buggers. Please don't suggest making one - I'm fully prepared [quoted text clipped - 12 lines] > Give me two wires to solder together and I'll solder one to a lamp, the > other to my nose, the carpet will be on fire...you get the picture. egad. Have you been let near a barbecue in a built-up area?
 Signature james dore IT Officer, New College, Oxford http://www.new.ox.ac.uk/ it-support@new....
Jim - 28 Sep 2007 15:47 GMT >> > You say that as if it were a Bad Thing. I just love the smell of Fear >> > when I power up my two butane powered babies. One for soldering, one [quoted text clipped - 7 lines] > > egad. Have you been let near a barbecue in a built-up area? Not since Tunguska.
Jim
 Signature http://www.ursaMinorBeta.co.uk NAAS (n.) The windmaking region of Albania where most of the wine that people take to bottle-parties comes from.
rpg - 28 Sep 2007 13:43 GMT > You're piping the activity of your firewall to a spare Apple IIe for > GeekPoints (tm), aren't you? > Like your style - I'm a firm believer that the more cryptic text > scrolling across monochrome monitors you have in an office, the more > retro high tech points you score... har har! I've been doing some perl-ing recently, and when I get the output to scroll in green on a black terminal window I get a lot of 'Matrix' comments.
 Signature In our distant past, most of the tribe huddled round the fire near the mouth of the cave, perhaps some of them performing whatever ritual made dawn come again, while the ur-geek squatted in the darkness at the back of the cave, hacking the wall paintings - Malcolm Ray
Jim - 29 Sep 2007 14:24 GMT > You're piping the activity of your firewall to a spare Apple IIe for > GeekPoints (tm), aren't you? > Like your style - I'm a firm believer that the more cryptic text > scrolling across monochrome monitors you have in an office, the more > retro high tech points you score... And here's the pictures to prove it:
<http://www.UrsaMinorBeta.co.uk/AppleSecLog1.jpg> <http://www.UrsaMinorBeta.co.uk/AppleSecLog2.jpg> <http://www.UrsaMinorBeta.co.uk/Apple2.jpg>
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
zoara - 29 Sep 2007 18:41 GMT > <http://www.UrsaMinorBeta.co.uk/Apple2.jpg> IVAR!
-z-
 Signature No 3G. Fewer megapixels than an N95. Lame.
Jim - 29 Sep 2007 18:43 GMT > > <http://www.UrsaMinorBeta.co.uk/Apple2.jpg> > > IVAR! Damn. Rumbled.
Jim
 Signature Find me at : http://www.ursaminorbeta.co.uk Please help to bring old whisky literature back into print - visit www.ClassicExpressions.co.uk
zoara - 29 Sep 2007 20:06 GMT > > > <http://www.UrsaMinorBeta.co.uk/Apple2.jpg> > > > > IVAR! > > Damn. Rumbled. Nothing to be ashamed of, it's a decent workhorse.
-z-
 Signature No 3G. Fewer megapixels than an N95. Lame.
Peter Ceresole - 29 Sep 2007 21:00 GMT > > > > <http://www.UrsaMinorBeta.co.uk/Apple2.jpg> > > > [quoted text clipped - 3 lines] > > Nothing to be ashamed of, it's a decent workhorse. Explanation? Or is this a private conversation?
 Signature Peter
Jim - 29 Sep 2007 21:45 GMT > > > > > <http://www.UrsaMinorBeta.co.uk/Apple2.jpg> > > > > [quoted text clipped - 5 lines] > > Explanation? Or is this a private conversation? Idea shelving.
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
Jim - 30 Sep 2007 08:54 GMT > > > Nothing to be ashamed of, it's a decent workhorse. > > > > Explanation? Or is this a private conversation? > > Idea shelving. <sigh> IKEA shelving. Scotland won the rugby, so I was a little...happy.
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
Woody - 29 Sep 2007 21:04 GMT > > You're piping the activity of your firewall to a spare Apple IIe for > > GeekPoints (tm), aren't you? [quoted text clipped - 5 lines] > > <http://www.UrsaMinorBeta.co.uk/AppleSecLog1.jpg> I had that modem. That was a long time ago!
 Signature Woody
www.alienrat.com
Jim - 29 Sep 2007 21:45 GMT > > > You're piping the activity of your firewall to a spare Apple IIe for > > > GeekPoints (tm), aren't you? [quoted text clipped - 7 lines] > > I had that modem. That was a long time ago! Which one? There's two there.
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
Woody - 29 Sep 2007 22:29 GMT > > > > You're piping the activity of your firewall to a spare Apple IIe for > > > > GeekPoints (tm), aren't you? [quoted text clipped - 9 lines] > > Which one? There's two there. The real one on the bottom on the left, the nightingale.
 Signature Woody
www.alienrat.com
J.J. O'Shea - 29 Sep 2007 21:15 GMT > <http://www.UrsaMinorBeta.co.uk/AppleSecLog1.jpg> Why do you have a pic of C. Holland & his mother on your desk?
 Signature email to oshea dot j dot j at gmail dot com.
Jim - 29 Sep 2007 21:45 GMT > > <http://www.UrsaMinorBeta.co.uk/AppleSecLog1.jpg> > > Why do you have a pic of C. Holland & his mother on your desk? Do *not* despoil good Cocker Spaniels by association with that...thing.
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
J.J. O'Shea - 29 Sep 2007 22:15 GMT >>> <http://www.UrsaMinorBeta.co.uk/AppleSecLog1.jpg> >> [quoted text clipped - 3 lines] > > Jim Sorry. Couldn't resist. Apologise to the dogs for me.
 Signature email to oshea dot j dot j at gmail dot com.
Jim - 30 Sep 2007 08:54 GMT > Sorry. Couldn't resist. Apologise to the dogs for me. I would but they're no longer with us.
No worries mate.
Jim
 Signature Find me at http://www.ursaminorbeta.co.uk AIM/iChatAV: JCAndrew2 Skype: greyarea
rpg - 28 Sep 2007 13:39 GMT > (gah! can't turn line wrapping off - that should be four lines) > [quoted text clipped - 4 lines] > Sep 28 12:59:02 213.150.54.194:53 > Sep 28 12:59:05 213.150.54.194:53 % tail ipfw.log | awk '{print $1, $2, $3, $10}'
assuming it's ipfw.log that the tail is, um tailing.
 Signature Richard P. Grant 0x5F9559B1 RG Design rpgrant at netspace.net.au http://www.rg-d.com/BioLOG/ i dont know, something like a sound problem wouldnt be a reinstall windows job, a simple driver job more than likely - Iain Dingsdale misses a point
TheMekon - 28 Sep 2007 13:40 GMT > I want to tail the output of a file that looks like this: > Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 [quoted text clipped - 26 lines] > > Jim You can certainly do it with awk. I can't remember how. But the man page and patience should sort it.
Martin - 28 Sep 2007 13:41 GMT > I imagine it's doable via l33t sed and awk skilz, but I wouldn't really know > where to begin. Pipe it to:
awk '{ print $1, $2, $3, $11 }'
Adjust the $11 value if I guessed it incorrectly.
Regards
 Signature Martin
Jim - 28 Sep 2007 13:48 GMT >> I imagine it's doable via l33t sed and awk skilz, but I wouldn't really know >> where to begin. > > Pipe it to: > > awk '{ print $1, $2, $3, $11 }' *Almost*, but that displays the internal IP and port.
The problem is that you've got two IPs with port numbers (source and destination), but I want the _source_ IP and the _destination_ port. And they're not space delimited, sadly.
So, given:
[...] TCP 212.152.232.68:4646 192.168.2.2:135 [...]
--------------------------^ -------------^
I want the first IP and the second port, so 212.152.232.68:135
Jim
 Signature http://www.ursaMinorBeta.co.uk NAAS (n.) The windmaking region of Albania where most of the wine that people take to bottle-parties comes from.
Woody - 28 Sep 2007 13:53 GMT > The windmaking region of Albania where most of the wine that people take to > bottle-parties comes from. there is an area of albania where they make wind?
 Signature Woody
Jim - 28 Sep 2007 13:56 GMT >> The windmaking region of Albania where most of the wine that people take to >> bottle-parties comes from. > > there is an area of albania where they make wind? It's the sausages.
Jim
 Signature http://www.ursaMinorBeta.co.uk KINGSTON BAGPUISE (n.) A forty-year-old sixteen-stone man trying to commit suicide by jogging.
Martin - 28 Sep 2007 14:21 GMT > I want the first IP and the second port, so 212.152.232.68:135 I can see that David has already sorted it out - but my alternative would be the less elegant:
| awk '{ print $1,$2,$3,$10,$11 }'| awk ' BEGIN { FS = ":" } ; { print $1":"$2":"$3,$NF }'
Regards
 Signature Martin
David Sankey - 28 Sep 2007 14:06 GMT > I want to tail the output of a file that looks like this: > Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 [quoted text clipped - 16 lines] > > In other words, the dat/time, source IP and destination port. awk '{sub(/:.*$/,"", $10); sub(/^.*:/,"", $11); print $1, $2, $3, $10, $11}'<<+ Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 192.168.2.2:135 in via rl0 Sep 28 12:36:02 wotan kernel: ipfw: 65435 Deny TCP 212.119.162.40:4227 192.168.2.2:135 in via rl0 Sep 28 12:59:02 wotan kernel: ipfw: 65435 Deny TCP 213.150.54.194:4972 192.168.2.2:53 in via rl0 Sep 28 12:59:05 wotan kernel: ipfw: 65435 Deny TCP 213.150.54.194:4972 192.168.2.2:53 in via rl0 + Sep 28 12:31:32 212.152.232.68 135 Sep 28 12:36:02 212.119.162.40 135 Sep 28 12:59:02 213.150.54.194 53 Sep 28 12:59:05 213.150.54.194 53
Jim - 28 Sep 2007 14:10 GMT >> I want to tail the output of a file that looks like this: >> Sep 28 12:31:32 wotan kernel: ipfw: 65435 Deny TCP 212.152.232.68:4646 [quoted text clipped - 32 lines] > Sep 28 12:59:02 213.150.54.194 53 > Sep 28 12:59:05 213.150.54.194 53 That's the chap! Thanks.
Jim
 Signature http://www.ursaMinorBeta.co.uk HARPENDEN (n.) The coda to a phone conversion, consisting of about eight exchanges, by which people try gracefully to get off the line.
|
|
|