3,7 → 3,7 |
# |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d). |
# We read configuration files and logs to create cool charts. |
# Written by Raphaël PION & Rexy |
# Written by Raphaël PION, Rexy & Tom HOUDAYER |
|
# files |
DIR_TMP="/var/tmp" |
561,6 → 561,105 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all |
fi |
|
|
###################### ALCASAR : LOG ACCESS ###################### |
echo "Get ACC log access of the week" |
#create html document |
echo "<h3>Connexion à l'ALCASAR Control Center (ACC)</h3>" >> $HTML_REPORT |
|
#create new htdigest user to consult statistique of ACC |
#if user does not exist, we create him |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -lt 1 ] |
then |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_only_manager |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_manager |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_all |
chown -R root:apache $DIR_KEY |
chmod 640 $DIR_KEY/key_* |
fi |
|
#get admin_log.php from ACC |
wget -q -nv --user $tmp_account --password $password "https://alcasar/acc/admin_log.php?startTime=$SECS_AGO" -O $TMP_STATS --no-check-certificate |
|
#clean this file to include it in html report. |
DELIM_1="<table class=\"table table-striped\">" |
DELIM_2="<\/table>" |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" > $TMP_STATS_2 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT |
|
#we delete our user if he still exists |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -ge 1 ] |
then |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all |
fi |
|
|
###################### ALCASAR : GLOBAL TRAFFIC ###################### |
echo "Get Global traffic of the last 30 days" |
|
ROWS="" |
EXTIF=$(cat /usr/local/etc/alcasar.conf | grep EXTIF | cut -d'=' -f2) |
for day in $(vnstat --exportdb -i $EXTIF | grep '^d;' | sort -t";" -k3 -r); do |
day_datas=(${day//;/ }) |
day_date=${day_datas[2]} |
day_rxMio=${day_datas[3]} |
day_txMio=${day_datas[4]} |
day_rxKio=${day_datas[5]} |
day_txKio=${day_datas[6]} |
day_act=${day_datas[7]} |
|
if [ $day_act -ne 1 ]; then |
continue |
fi |
|
if [ $day_date -lt $SECS_AGO ]; then |
break |
fi |
|
day_dateFormated=$(date -d @$day_date +%x) |
day_rx=$(($day_rxMio * 1048576 + $day_rxKio * 1024)) |
day_tx=$(($day_txMio * 1048576 + $day_txKio * 1024)) |
day_total=$(($day_rx + $day_tx)) |
day_rxFormated=$(numfmt --from=iec --to=iec --suffix=B $day_rx) |
day_txFormated=$(numfmt --from=iec --to=iec --suffix=B $day_tx) |
day_totalFormated=$(numfmt --from=iec --to=iec --suffix=B $day_total) |
|
ROWS="$ROWS<tr><td>$day_dateFormated</td><td>$day_rxFormated</td><td>$day_txFormated</td><td>$day_totalFormated</td></tr>" |
done |
|
# Create html document |
echo "<h3>Trafic global</h3>" >> $HTML_REPORT |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT |
echo $ROWS >> $HTML_REPORT |
echo "</tbody></table>" >> $HTML_REPORT |
|
|
###################### ALCASAR : FAIL2BAN ###################### |
echo "Get fail2ban log of the week" |
|
# Create html document |
echo "<h3>Adresse(s) IP bloquée(s) (Fail2Ban)</h3>" >> $HTML_REPORT |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT |
echo "<thead><tr><th>Date</th><th>Adresse IP</th><th>Règle</th></tr></thead><tbody>" >> $HTML_REPORT |
|
DATE_1_WEEK_AGO=$(date --date="$MAX_DAY_AGO days ago" +'%Y-%m-%d %H:%M:%S,%N' | rev | cut -c 7- | rev) |
# TODO: awk compare date [$1] AND hour [$2] (currently only date is compared) |
grep " Ban " /var/log/fail2ban.log | sort -r | awk '$1 >= "$DATE_1_WEEK_AGO"' | while read -r log ; do |
log_datas=($log) |
log_date="${log_datas[0]} ${log_datas[1]}" |
log_type=${log_datas[4]:1:-1} |
log_ip=${log_datas[6]} |
log_dateFormated=$(date -d "$log_date" +"%x %X") |
|
echo "<tr><td>$log_dateFormated</td><td>$log_ip</td><td>$log_type</td></tr>" >> $HTML_REPORT |
done |
|
echo "</tbody></table>" >> $HTML_REPORT |
|
|
######################FIN HTML###################### |
|
#Execute our javascript function to print charts |