| Line 1... |
Line 1... |
| 1 |
#!/bin/bash
|
1 |
#!/bin/bash
|
| 2 |
# $Id: alcasar-activity_report.sh 3252 2025-02-21 18:40:30Z rexy $
|
2 |
# $Id: alcasar-activity_report.sh 3267 2025-04-13 22:05:45Z rexy $
|
| 3 |
#
|
3 |
#
|
| 4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
| 5 |
# We read configuration files and logs to create cool charts.
|
5 |
# We read configuration files and logs to create cool charts.
|
| 6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
| 7 |
|
7 |
|
| Line 75... |
Line 75... |
| 75 |
echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../../../css/report.css\">" >> $HTML_REPORT
|
75 |
echo "<link rel=\"stylesheet\" type=\"text/css\" href=\"../../../css/report.css\">" >> $HTML_REPORT
|
| 76 |
echo "<script src=\"../../../js/Chart.bundle.min.js\"></script>" >> $HTML_REPORT
|
76 |
echo "<script src=\"../../../js/Chart.bundle.min.js\"></script>" >> $HTML_REPORT
|
| 77 |
echo "<script src=\"../../../js/jquery.min.js\"></script>" >> $HTML_REPORT
|
77 |
echo "<script src=\"../../../js/jquery.min.js\"></script>" >> $HTML_REPORT
|
| 78 |
echo "</head>" >> $HTML_REPORT
|
78 |
echo "</head>" >> $HTML_REPORT
|
| 79 |
echo "<body>" >> $HTML_REPORT
|
79 |
echo "<body>" >> $HTML_REPORT
|
| - |
|
80 |
echo "<h1><center>ALCASAR</center></h1>" >> $HTML_REPORT
|
| 80 |
echo "<h1><center>Rapport d'activité ALCASAR</center></h1>" >> $HTML_REPORT
|
81 |
echo "<h2><center>Rapport d'activité hebdomadaire</center></h2>" >> $HTML_REPORT
|
| 81 |
echo "<h2><center>$(grep ^ORGANISM= $CONF_FILE | cut -d'=' -f2-)</center></h2>" >> $HTML_REPORT
|
82 |
echo "<h2><center>$(grep ^ORGANISM= $CONF_FILE | cut -d'=' -f2-)</center></h2>" >> $HTML_REPORT
|
| 82 |
echo "<i><p style=\"text-align: right;\">Date de création $(date +%F)</p></i>" >> $HTML_REPORT
|
83 |
echo "<i><p style=\"text-align: right;\">Date de création $(date +%F)</p></i>" >> $HTML_REPORT
|
| 83 |
echo "<font size=\"1\">" >> $HTML_REPORT
|
84 |
echo "<font size=\"1\">" >> $HTML_REPORT
|
| 84 |
|
85 |
|
| 85 |
######################TABINFO######################
|
86 |
######################TABINFO######################
|
| Line 143... |
Line 144... |
| 143 |
VALUE=$(who -b | cut -d' ' -f12-)
|
144 |
VALUE=$(who -b | cut -d' ' -f12-)
|
| 144 |
echo ${LINE_HTML/XXREBOOTXX/$VALUE} >> $HTML_REPORT
|
145 |
echo ${LINE_HTML/XXREBOOTXX/$VALUE} >> $HTML_REPORT
|
| 145 |
|
146 |
|
| 146 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJCLAMAVXX' | wc -l)" -eq 1 ]
|
147 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJCLAMAVXX' | wc -l)" -eq 1 ]
|
| 147 |
then
|
148 |
then
|
| 148 |
VALUE=$(date -d "$(rpm -qa --queryformat "%{installtime} %{name}\n" | grep -E "clamav-db" | cut -d' ' -f1 )" "+%Y-%m-%d %H:%M:%S")
|
149 |
# VALUE=$(date -d "$(rpm -qa --queryformat "%{installtime} %{name}\n" | grep -E "clamav-db" | cut -d' ' -f1 )" "+%Y-%m-%d %H:%M:%S")
|
| - |
|
150 |
VALUE="disabled"
|
| 149 |
echo ${LINE_HTML/XXMAJCLAMAVXX/$VALUE} >> $HTML_REPORT
|
151 |
echo ${LINE_HTML/XXMAJCLAMAVXX/$VALUE} >> $HTML_REPORT
|
| 150 |
echo
|
152 |
|
| 151 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJBLXX' | wc -l)" -eq 1 ]
|
153 |
elif [ "$(echo $LINE_HTML | grep 'XXMAJBLXX' | wc -l)" -eq 1 ]
|
| 152 |
then
|
154 |
then
|
| 153 |
VALUE=$(cat /etc/e2guardian/lists/blacklists/README | grep 'Last version' | cut -d' ' -f4-6)
|
155 |
VALUE=$(stat -c %y /etc/e2guardian/lists/blacklists/README | cut -d' ' -f1)
|
| 154 |
echo ${LINE_HTML/XXMAJBLXX/$VALUE} >> $HTML_REPORT
|
156 |
echo ${LINE_HTML/XXMAJBLXX/$VALUE} >> $HTML_REPORT
|
| 155 |
|
157 |
|
| 156 |
elif [ "$(echo $LINE_HTML | grep 'XXRPMXX' | wc -l)" -eq 1 ]
|
158 |
elif [ "$(echo $LINE_HTML | grep 'XXRPMXX' | wc -l)" -eq 1 ]
|
| 157 |
then
|
159 |
then
|
| 158 |
#show every ALCASAR RPM updated since X day ago
|
160 |
#show every ALCASAR RPM updated since X day ago
|
| 159 |
#get timestamp of X day ago. Then we get every packets which have been updated since this date.
|
161 |
#get timestamp of X day ago. Then we get every packets which have been updated since this date.
|
| 160 |
if [ "$(rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | wc -l)" -gt 1 ]
|
162 |
if [ "$(rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | wc -l)" -gt 1 ]
|
| 161 |
then
|
163 |
then
|
| 162 |
PACKAGE='php|apache|iptables|unbound|radius|nfdump|e2guardian|clamav|ulogd|chilli|fail2ban|openssh|ipt-netflow|wget|mariadb|gnupg|openssl'
|
- |
|
| 163 |
rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | grep -E "$PACKAGE" | while read RPM_ALCASAR
|
164 |
rpm -qa --queryformat '%{installtime} %{name} %{version}\n' | awk -v seuil="$SECS_AGO" '$1 > seuil' | sort -n | while read RPM_ALCASAR
|
| 164 |
do
|
165 |
do
|
| 165 |
RPM_TIMESTAMP=$(echo $RPM_ALCASAR | cut -d' ' -f1)
|
166 |
RPM_TIMESTAMP=$(echo $RPM_ALCASAR | cut -d' ' -f1)
|
| 166 |
RPM_DATE=$(date -d "@$(echo $RPM_TIMESTAMP)" "+%Y-%m-%d %H:%M:%S")
|
167 |
RPM_DATE=$(date -d "@$(echo $RPM_TIMESTAMP)" "+%Y-%m-%d %H:%M:%S")
|
| 167 |
RPM_NAME=$(echo $RPM_ALCASAR | cut -d' ' -f2)
|
168 |
RPM_NAME=$(echo $RPM_ALCASAR | cut -d' ' -f2)
|
| 168 |
RPM_VERSION=$(echo $RPM_ALCASAR | cut -d' ' -f3)
|
169 |
RPM_VERSION=$(echo $RPM_ALCASAR | cut -d' ' -f3)
|
| Line 292... |
Line 293... |
| 292 |
echo $LINE_JS >> $HTML_REPORT
|
293 |
echo $LINE_JS >> $HTML_REPORT
|
| 293 |
fi
|
294 |
fi
|
| 294 |
done
|
295 |
done
|
| 295 |
echo "</script>" >> $HTML_REPORT
|
296 |
echo "</script>" >> $HTML_REPORT
|
| 296 |
else
|
297 |
else
|
| 297 |
echo "<h3>Aucune activité de la Blacklist depuis l'installation.</h3>" >> $HTML_REPORT
|
298 |
echo "<BR><h3>Aucun site bloqué par la blacklist depuis l'installation.</h3>" >> $HTML_REPORT
|
| 298 |
fi
|
299 |
fi
|
| 299 |
|
300 |
|
| 300 |
|
301 |
|
| 301 |
|
302 |
|
| 302 |
######################Unbound BLACKLIST######################
|
303 |
######################Unbound BLACKLIST######################
|
| Line 395... |
Line 396... |
| 395 |
echo $LINE_JS >> $HTML_REPORT
|
396 |
echo $LINE_JS >> $HTML_REPORT
|
| 396 |
fi
|
397 |
fi
|
| 397 |
done
|
398 |
done
|
| 398 |
echo "</script>" >> $HTML_REPORT
|
399 |
echo "</script>" >> $HTML_REPORT
|
| 399 |
else
|
400 |
else
|
| 400 |
echo "<h3>Aucune activité de la Blacklist cette semaine.</h3>" >> $HTML_REPORT
|
401 |
echo "<BR><h3>Aucun site bloqué par la Blacklist cette semaine.</h3>" >> $HTML_REPORT
|
| 401 |
fi
|
402 |
fi
|
| 402 |
|
403 |
|
| - |
|
404 |
###################### ALCASAR : FAIL2BAN ######################
|
| - |
|
405 |
echo "Get fail2ban log of the week"
|
| - |
|
406 |
|
| - |
|
407 |
ROWS=""
|
| - |
|
408 |
dateDaysAgo_formatted=$(date --date="$MAX_DAY_AGO days ago" +'%Y-%m-%d %H:%M:%S,%N' | rev | cut -c 7- | rev)
|
| - |
|
409 |
while read -r log ; do
|
| - |
|
410 |
log_datas=($log)
|
| - |
|
411 |
log_date="${log_datas[0]} ${log_datas[1]}"
|
| - |
|
412 |
log_type=${log_datas[4]:1:-1}
|
| - |
|
413 |
log_ip=${log_datas[6]}
|
| - |
|
414 |
log_date_formatted=$(date -d "$log_date" +"%x %X")
|
| - |
|
415 |
|
| - |
|
416 |
ROWS="$ROWS<tr><td>$log_date_formatted</td><td>$log_ip</td><td>$log_type</td></tr>"
|
| - |
|
417 |
done < <(grep " Ban " /var/log/fail2ban.log | sort -r | awk -v dateDaysAgo="$dateDaysAgo_formatted" '($1 " " $2) >= dateDaysAgo')
|
| - |
|
418 |
|
| - |
|
419 |
if [ -z "$ROWS" ]; then
|
| - |
|
420 |
ROWS="<tr><td colspan=\"3\" style=\"text-align: center;\">Aucune adresse IP bloquée</td></tr>"
|
| - |
|
421 |
fi
|
| - |
|
422 |
|
| - |
|
423 |
#Create html document
|
| - |
|
424 |
echo "<BR><h3>Adresse(s) IP bloquée(s) (Fail2Ban)</h3>" >> $HTML_REPORT
|
| - |
|
425 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| - |
|
426 |
echo "<thead><tr><th>Date</th><th>Adresse IP</th><th>Règle</th></tr></thead><tbody>" >> $HTML_REPORT
|
| - |
|
427 |
echo $ROWS >> $HTML_REPORT
|
| - |
|
428 |
echo "</tbody></table>" >> $HTML_REPORT
|
| - |
|
429 |
|
| 403 |
######################VIRUS THREAT######################
|
430 |
######################VIRUS THREAT######################
|
| 404 |
echo "Create AV logs since the installation of ALCASAR"
|
431 |
echo "Create AV logs since the installation of ALCASAR"
|
| 405 |
|
432 |
|
| 406 |
#decompress every logs, if they exist
|
433 |
#decompress every logs, if they exist
|
| 407 |
if [ "$(ls -1 /var/log/clamav/clamd.log.*.gz 2>/dev/null | wc -l)" -ge 1 ]
|
434 |
if [ "$(ls -1 /var/log/clamav/clamd.log.*.gz 2>/dev/null | wc -l)" -ge 1 ]
|
| 408 |
then
|
435 |
then
|
| 409 |
gunzip -d clamd.log.*.gz
|
436 |
gunzip -d clamd.log.*.gz
|
| 410 |
fi
|
- |
|
| 411 |
for FILE in /var/log/clamav/clamd.log*
|
437 |
for FILE in /var/log/clamav/clamd.log*
|
| 412 |
do
|
- |
|
| 413 |
while read LINE_AV
|
- |
|
| 414 |
do
|
438 |
do
|
| - |
|
439 |
while read LINE_AV
|
| - |
|
440 |
do
|
| 415 |
if [ "`echo $LINE_AV|grep -c FOUND`" == 1 ]
|
441 |
if [ "`echo $LINE_AV|grep -c FOUND`" == 1 ]
|
| 416 |
then
|
442 |
then
|
| 417 |
Y=$(echo $LINE_AV | cut -d' ' -f5)
|
443 |
Y=$(echo $LINE_AV | cut -d' ' -f5)
|
| 418 |
M=$(echo $LINE_AV | cut -d' ' -f2)
|
444 |
M=$(echo $LINE_AV | cut -d' ' -f2)
|
| 419 |
D=$(echo $LINE_AV | cut -d' ' -f3)
|
445 |
D=$(echo $LINE_AV | cut -d' ' -f3)
|
| 420 |
H=$(echo $LINE_AV | cut -d' ' -f4)
|
446 |
H=$(echo $LINE_AV | cut -d' ' -f4)
|
| 421 |
CURRENT_TS=$(date -d "$M $D $Y $H" +"%s")
|
447 |
CURRENT_TS=$(date -d "$M $D $Y $H" +"%s")
|
| 422 |
echo $CURRENT_TS >> $TMP_AV
|
448 |
echo $CURRENT_TS >> $TMP_AV
|
| 423 |
fi
|
449 |
fi
|
| 424 |
done < $FILE
|
450 |
done < $FILE
|
| 425 |
done
|
451 |
done
|
| - |
|
452 |
fi
|
| 426 |
if [ -e $TMP_AV ]
|
453 |
if [ -e $TMP_AV ]
|
| 427 |
then
|
454 |
then
|
| 428 |
ENABLE_AV=1
|
455 |
ENABLE_AV=1
|
| 429 |
DATE_END=$(cat $TMP_AV | sort -n | head -1)
|
456 |
DATE_END=$(cat $TMP_AV | sort -n | head -1)
|
| 430 |
for TS in $(seq $C_TS -$STEP_TS $DATE_END)
|
457 |
for TS in $(seq $C_TS -$STEP_TS $DATE_END)
|
| Line 498... |
Line 525... |
| 498 |
echo $LINE_JS >> $HTML_REPORT
|
525 |
echo $LINE_JS >> $HTML_REPORT
|
| 499 |
fi
|
526 |
fi
|
| 500 |
done
|
527 |
done
|
| 501 |
echo "</script>" >> $HTML_REPORT
|
528 |
echo "</script>" >> $HTML_REPORT
|
| 502 |
else
|
529 |
else
|
| 503 |
echo "<h3>Aucune menace virale.</h3>" >> $HTML_REPORT
|
530 |
echo "<BR><h3>Aucune détection de menace virale.</h3>" >> $HTML_REPORT
|
| 504 |
fi
|
531 |
fi
|
| 505 |
|
532 |
|
| 506 |
|
533 |
|
| 507 |
######################ALCASAR : DAILY USE######################
|
534 |
######################ALCASAR : DAILY USE######################
|
| 508 |
echo "Get daily use connection of the week"
|
535 |
echo "Get daily use connection of the week"
|
| 509 |
|
536 |
|
| 510 |
echo "<h3>Statistiques volumétrie connexions</h3>" >> $HTML_REPORT
|
537 |
echo "<BR><h3>Statistiques des connexions</h3>" >> $HTML_REPORT
|
| 511 |
|
538 |
|
| 512 |
#create new htdigest user to consult statistique of ACC
|
539 |
#create new htdigest user to consult statistique of ACC
|
| 513 |
#if user does not exist, we create him
|
540 |
#if user does not exist, we create him
|
| 514 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -lt 1 ]
|
541 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -lt 1 ]
|
| 515 |
then
|
542 |
then
|
| Line 520... |
Line 547... |
| 520 |
chmod 640 $DIR_KEY/key_*
|
547 |
chmod 640 $DIR_KEY/key_*
|
| 521 |
fi
|
548 |
fi
|
| 522 |
|
549 |
|
| 523 |
#get stats.php from ACC
|
550 |
#get stats.php from ACC
|
| 524 |
wget -q -nv --user $tmp_account --password $password https://alcasar/acc/manager/htdocs/stats.php -O $TMP_STATS --no-check-certificate
|
551 |
wget -q -nv --user $tmp_account --password $password https://alcasar/acc/manager/htdocs/stats.php -O $TMP_STATS --no-check-certificate
|
| 525 |
|
- |
|
| 526 |
#clean this file to include it in html report.
|
552 |
#clean this file to include it in html report.
|
| 527 |
DELIM_1="<td colspan=10 height=20><img src=\"images\/pixel.gif\"><\/td>"
|
553 |
DELIM_1="<font color=\"darkblue\">"
|
| 528 |
DELIM_2="<\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <\/td><\/tr> <\/table> <p>"
|
554 |
DELIM_2="<\/div"
|
| 529 |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" | tail -n+3 | head -n-2 >> $TMP_STATS_2
|
555 |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" | tail -n+2 | head -n-1 >> $TMP_STATS_2
|
| 530 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT
|
556 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT
|
| 531 |
|
557 |
|
| 532 |
#we delete our user if he still exists
|
558 |
#we delete our user if he still exists
|
| 533 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -ge 1 ]
|
559 |
if [ "$(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l)" -ge 1 ]
|
| 534 |
then
|
560 |
then
|
| 535 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager
|
561 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager
|
| 536 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager
|
562 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager
|
| 537 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all
|
563 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all
|
| 538 |
fi
|
564 |
fi
|
| 539 |
|
565 |
|
| 540 |
|
- |
|
| 541 |
###################### ALCASAR : LOG ACCESS ######################
|
566 |
###################### ALCASAR : LOG ACCESS ######################
|
| 542 |
echo "Get ACC log access of the week"
|
567 |
echo "Get ACC log access of the week"
|
| 543 |
|
568 |
|
| 544 |
ROWS=""
|
569 |
ROWS=""
|
| 545 |
while read -r access ; do
|
570 |
while read -r access ; do
|
| Line 559... |
Line 584... |
| 559 |
if [ -z "$ROWS" ]; then
|
584 |
if [ -z "$ROWS" ]; then
|
| 560 |
ROWS="<tr><td colspan=\"4\" style=\"text-align: center;\">Aucune connexion</td></tr>"
|
585 |
ROWS="<tr><td colspan=\"4\" style=\"text-align: center;\">Aucune connexion</td></tr>"
|
| 561 |
fi
|
586 |
fi
|
| 562 |
|
587 |
|
| 563 |
# Create HTML document
|
588 |
# Create HTML document
|
| 564 |
echo "<h3>Connexion à l'ALCASAR Control Center (ACC)</h3>" >> $HTML_REPORT
|
589 |
echo "<BR><h3>Connexion à l'ALCASAR Control Center (ACC)</h3>" >> $HTML_REPORT
|
| 565 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
590 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| 566 |
echo "<thead><tr><th>Date</th><th>Utilisateur</th><th>Adresse IP</th><th>Agent</th></tr></thead><tbody>" >> $HTML_REPORT
|
591 |
echo "<thead><tr><th>Date</th><th>Utilisateur</th><th>Adresse IP</th><th>Agent</th></tr></thead><tbody>" >> $HTML_REPORT
|
| 567 |
echo "$ROWS" >> $HTML_REPORT
|
592 |
echo "$ROWS" >> $HTML_REPORT
|
| 568 |
echo "</tbody></table>" >> $HTML_REPORT
|
593 |
echo "</tbody></table>" >> $HTML_REPORT
|
| 569 |
|
594 |
|
| Line 573... |
Line 598... |
| 573 |
|
598 |
|
| 574 |
ROWS=""
|
599 |
ROWS=""
|
| 575 |
EXTIF=$(grep ^EXTIF= $CONF_FILE | cut -d'=' -f2)
|
600 |
EXTIF=$(grep ^EXTIF= $CONF_FILE | cut -d'=' -f2)
|
| 576 |
|
601 |
|
| 577 |
while read -r entry; do
|
602 |
while read -r entry; do
|
| 578 |
year=$(echo "$entry" | sed -n 's/.*"year": \([0-9]*\).*/\1/p')
|
603 |
year=$(echo "$entry" | grep -oP '(?<=<year>).*(?=</year>)')
|
| 579 |
month=$(echo "$entry" | sed -n 's/.*"month": \([0-9]*\).*/\1/p')
|
604 |
month=$(echo "$entry" | grep -oP '(?<=<month>).*(?=</month>)')
|
| 580 |
day=$(echo "$entry" | sed -n 's/.*"day": \([0-9]*\).*/\1/p')
|
605 |
day=$(echo "$entry" | grep -oP '(?<=<day>).*(?=</day>)')
|
| 581 |
rx=$(echo "$entry" | sed -n 's/.*"rx": \([0-9]*\).*/\1/p')
|
606 |
rx=$(echo "$entry" | grep -oP '(?<=<rx>).*(?=</rx>)')
|
| 582 |
tx=$(echo "$entry" | sed -n 's/.*"tx": \([0-9]*\).*/\1/p')
|
607 |
tx=$(echo "$entry" | grep -oP '(?<=<tx>).*(?=</tx>)')
|
| 583 |
if [ -n "$year" ]; then
|
608 |
if [ -n "$year" ]; then
|
| 584 |
date_year=$year
|
609 |
date_year=$year
|
| 585 |
fi
|
610 |
fi
|
| 586 |
if [ -n "$month" ]; then
|
611 |
if [ -n "$month" ]; then
|
| 587 |
if [ $month -le 9 ]; then
|
- |
|
| 588 |
date_month="0$month"
|
- |
|
| 589 |
else
|
- |
|
| 590 |
date_month=$month
|
612 |
date_month=$month
|
| 591 |
fi
|
- |
|
| 592 |
fi
|
613 |
fi
|
| 593 |
if [ -n "$day" ]; then
|
614 |
if [ -n "$day" ]; then
|
| 594 |
if [ $day -le 9 ]; then
|
- |
|
| 595 |
date_day="0$day"
|
- |
|
| 596 |
else
|
- |
|
| 597 |
date_day=$day
|
615 |
date_day=$day
|
| 598 |
fi
|
- |
|
| 599 |
fi
|
616 |
fi
|
| 600 |
if [ -n "$rx" ]; then
|
617 |
if [ -n "$rx" ]; then
|
| 601 |
day_rx=$rx
|
618 |
day_rx=`echo "$rx" | numfmt --to iec`
|
| 602 |
fi
|
619 |
fi
|
| 603 |
if [ -n "$tx" ]; then
|
620 |
if [ -n "$tx" ]; then
|
| 604 |
day_tx=$tx
|
621 |
day_tx=`echo "$tx" | numfmt --to iec`
|
| 605 |
fi
|
622 |
fi
|
| 606 |
if [ -n "$date_year" ] && [ -n "$date_month" ] && [ -n "$date_day" ] && [ -n "$day_rx" ] && [ -n "$day_tx" ]; then
|
623 |
if [ -n "$date_year" ] && [ -n "$date_month" ] && [ -n "$date_day" ] && [ -n "$day_rx" ] && [ -n "$day_tx" ]; then
|
| 607 |
day_date="$date_day$date_month$date_year"
|
624 |
day_date="$date_day-$date_month-$date_year"
|
| 608 |
day_total=$((day_rx * day_tx))
|
625 |
rxtx=$((rx + tx))
|
| - |
|
626 |
day_total=`echo "$rxtx" | numfmt --to iec`
|
| 609 |
ROWS="$ROWS<tr><td>$day_date</td><td>$day_rx</td><td>$day_tx</td><td>$day_total</td></tr>"
|
627 |
ROWS="$ROWS<tr><td>$day_date</td><td>$day_rx</td><td>$day_tx</td><td>$day_total</td></tr>"
|
| 610 |
date_month=""
|
628 |
date_month=""
|
| 611 |
date_day=""
|
629 |
date_day=""
|
| 612 |
date_year=""
|
630 |
date_year=""
|
| 613 |
fi
|
631 |
fi
|
| 614 |
done < <(vnstat -i $EXIT_IF --json d -b $(date --date="7 days ago" "+%Y-%m-%d") | python -m json.tool | sed -n 's/.*"day": \([0-9]*\).*/\1/p')
|
632 |
done < <(vnstat -i $EXTIF --days --begin $(date --date "Sunday - 6 days" +"%Y-%m-%d") --xml d | grep id= | tr -d ' '| rev | cut -c7- | rev)
|
| 615 |
if [ -z "$ROWS" ]; then
|
633 |
if [ -z "$ROWS" ]; then
|
| 616 |
ROWS="<tr><td colspan=\"4\" style=\"text-align: center;\">Aucun jour capturé</td></tr>"
|
634 |
ROWS="<tr><td colspan=\"4\" style=\"text-align: center;\">Aucun jour capturé</td></tr>"
|
| 617 |
fi
|
635 |
fi
|
| 618 |
|
636 |
|
| 619 |
# Create html document
|
637 |
# Create html document
|
| 620 |
echo "<h3>Trafic global</h3>" >> $HTML_REPORT
|
638 |
echo "<BR><h3>Trafic global</h3>" >> $HTML_REPORT
|
| 621 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
639 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| 622 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
640 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
| 623 |
echo "$ROWS" >> $HTML_REPORT
|
641 |
echo "$ROWS" >> $HTML_REPORT
|
| 624 |
echo "</tbody></table>" >> $HTML_REPORT
|
642 |
echo "</tbody></table>" >> $HTML_REPORT
|
| 625 |
|
643 |
|
| 626 |
|
- |
|
| 627 |
###################### ALCASAR : FAIL2BAN ######################
|
- |
|
| 628 |
echo "Get fail2ban log of the week"
|
- |
|
| 629 |
|
- |
|
| 630 |
ROWS=""
|
- |
|
| 631 |
dateDaysAgo_formatted=$(date --date="$MAX_DAY_AGO days ago" +'%Y-%m-%d %H:%M:%S,%N' | rev | cut -c 7- | rev)
|
- |
|
| 632 |
while read -r log ; do
|
- |
|
| 633 |
log_datas=($log)
|
- |
|
| 634 |
log_date="${log_datas[0]} ${log_datas[1]}"
|
- |
|
| 635 |
log_type=${log_datas[4]:1:-1}
|
- |
|
| 636 |
log_ip=${log_datas[6]}
|
- |
|
| 637 |
log_date_formatted=$(date -d "$log_date" +"%x %X")
|
- |
|
| 638 |
|
- |
|
| 639 |
ROWS="$ROWS<tr><td>$log_date_formatted</td><td>$log_ip</td><td>$log_type</td></tr>"
|
- |
|
| 640 |
done < <(grep " Ban " /var/log/fail2ban.log | sort -r | awk -v dateDaysAgo="$dateDaysAgo_formatted" '($1 " " $2) >= dateDaysAgo')
|
- |
|
| 641 |
|
- |
|
| 642 |
if [ -z "$ROWS" ]; then
|
- |
|
| 643 |
ROWS="<tr><td colspan=\"3\" style=\"text-align: center;\">Aucune adresse IP bloquée</td></tr>"
|
- |
|
| 644 |
fi
|
- |
|
| 645 |
|
- |
|
| 646 |
#Create html document
|
- |
|
| 647 |
echo "<h3>Adresse(s) IP bloquée(s) (Fail2Ban)</h3>" >> $HTML_REPORT
|
- |
|
| 648 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
- |
|
| 649 |
echo "<thead><tr><th>Date</th><th>Adresse IP</th><th>Règle</th></tr></thead><tbody>" >> $HTML_REPORT
|
- |
|
| 650 |
echo $ROWS >> $HTML_REPORT
|
- |
|
| 651 |
echo "</tbody></table>" >> $HTML_REPORT
|
- |
|
| 652 |
|
- |
|
| 653 |
|
- |
|
| 654 |
######################HTML END######################
|
644 |
######################HTML END######################
|
| 655 |
|
645 |
|
| 656 |
#Execute our javascript function to print charts
|
646 |
#Execute our javascript function to print charts
|
| 657 |
echo "<script>window.onload = function() {" >> $HTML_REPORT
|
647 |
echo "<script>window.onload = function() {" >> $HTML_REPORT
|
| 658 |
#BL since installation
|
648 |
#BL since installation
|