| Line 1... |
Line 1... |
| 1 |
#!/bin/bash
|
1 |
#!/bin/bash
|
| 2 |
# $Id: alcasar-activity_report.sh 2190 2017-04-28 21:38:49Z tom.houdayer $
|
2 |
# $Id: alcasar-activity_report.sh 2209 2017-05-06 18:25:36Z tom.houdayer $
|
| 3 |
#
|
3 |
#
|
| 4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
4 |
# Create an activity report for ALCASAR every week (sunday at 5.35 pm --> see cron.d).
|
| 5 |
# We read configuration files and logs to create cool charts.
|
5 |
# We read configuration files and logs to create cool charts.
|
| 6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
6 |
# Written by Raphaël PION, Rexy & Tom HOUDAYER
|
| 7 |
|
7 |
|
| Line 313... |
Line 313... |
| 313 |
echo $LINE_JS >> $HTML_REPORT
|
313 |
echo $LINE_JS >> $HTML_REPORT
|
| 314 |
fi
|
314 |
fi
|
| 315 |
done
|
315 |
done
|
| 316 |
echo "</script>" >> $HTML_REPORT
|
316 |
echo "</script>" >> $HTML_REPORT
|
| 317 |
else
|
317 |
else
|
| 318 |
echo "<h3>Aucune activité de la Blacklist depuis l'installation.</h3>" >> $HTML_REPORT
|
318 |
echo "<h2>Aucune activité de la Blacklist depuis l'installation.</h2>" >> $HTML_REPORT
|
| 319 |
fi
|
319 |
fi
|
| 320 |
|
320 |
|
| 321 |
|
321 |
|
| 322 |
|
322 |
|
| 323 |
######################DNSMASQ BLACKLIST######################
|
323 |
######################DNSMASQ BLACKLIST######################
|
| Line 418... |
Line 418... |
| 418 |
echo $LINE_JS >> $HTML_REPORT
|
418 |
echo $LINE_JS >> $HTML_REPORT
|
| 419 |
fi
|
419 |
fi
|
| 420 |
done
|
420 |
done
|
| 421 |
echo "</script>" >> $HTML_REPORT
|
421 |
echo "</script>" >> $HTML_REPORT
|
| 422 |
else
|
422 |
else
|
| 423 |
echo "<h3>Aucune activité de la Blacklist cette semaine.</h3>" >> $HTML_REPORT
|
423 |
echo "<h2>Aucune activité de la Blacklist cette semaine.</h2>" >> $HTML_REPORT
|
| 424 |
fi
|
424 |
fi
|
| 425 |
|
425 |
|
| 426 |
######################VIRUS THREAT######################
|
426 |
######################VIRUS THREAT######################
|
| 427 |
echo "Create AV logs since the installation of ALCASAR"
|
427 |
echo "Create AV logs since the installation of ALCASAR"
|
| 428 |
|
428 |
|
| Line 522... |
Line 522... |
| 522 |
echo $LINE_JS >> $HTML_REPORT
|
522 |
echo $LINE_JS >> $HTML_REPORT
|
| 523 |
fi
|
523 |
fi
|
| 524 |
done
|
524 |
done
|
| 525 |
echo "</script>" >> $HTML_REPORT
|
525 |
echo "</script>" >> $HTML_REPORT
|
| 526 |
else
|
526 |
else
|
| 527 |
echo "<h3>Aucune menace virale.</h3>" >> $HTML_REPORT
|
527 |
echo "<h2>Aucune menace virale.</h2>" >> $HTML_REPORT
|
| 528 |
fi
|
528 |
fi
|
| 529 |
|
529 |
|
| 530 |
|
530 |
|
| 531 |
######################ALCASAR : DAILY USE######################
|
531 |
######################ALCASAR : DAILY USE######################
|
| 532 |
echo "Get daily use connection of the week"
|
532 |
echo "Get daily use connection of the week"
|
| 533 |
#create html document
|
533 |
#create html document
|
| 534 |
echo "<h3>Statistiques volumétrie connexions</h3>" >> $HTML_REPORT
|
534 |
echo "<h2>Statistiques volumétrie connexions</h2>" >> $HTML_REPORT
|
| 535 |
|
535 |
|
| 536 |
#create new htdigest user to consult statistique of ACC
|
536 |
#create new htdigest user to consult statistique of ACC
|
| 537 |
#if user does not exist, we create him
|
537 |
#if user does not exist, we create him
|
| 538 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -lt 1 ]
|
538 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -lt 1 ]
|
| 539 |
then
|
539 |
then
|
| Line 562... |
Line 562... |
| 562 |
fi
|
562 |
fi
|
| 563 |
|
563 |
|
| 564 |
|
564 |
|
| 565 |
###################### ALCASAR : LOG ACCESS ######################
|
565 |
###################### ALCASAR : LOG ACCESS ######################
|
| 566 |
echo "Get ACC log access of the week"
|
566 |
echo "Get ACC log access of the week"
|
| 567 |
#create html document
|
- |
|
| 568 |
echo "<h3>Connexion à l'ALCASAR Control Center (ACC)</h3>" >> $HTML_REPORT
|
- |
|
| 569 |
|
567 |
|
| 570 |
#create new htdigest user to consult statistique of ACC
|
- |
|
| 571 |
#if user does not exist, we create him
|
- |
|
| 572 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -lt 1 ]
|
- |
|
| 573 |
then
|
568 |
ROWS=""
|
| 574 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_only_manager
|
- |
|
| 575 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_manager
|
- |
|
| 576 |
(echo -n "$tmp_account:$realm:" && echo -n "$tmp_account:$realm:$password" | md5sum | awk '{print $1}' ) >> $DIR_KEY/key_all
|
- |
|
| 577 |
chown -R root:apache $DIR_KEY
|
569 |
while read -r access ; do
|
| 578 |
chmod 640 $DIR_KEY/key_*
|
570 |
access_datas=(${access//|||/ })
|
| 579 |
fi
|
- |
|
| 580 |
|
571 |
|
| - |
|
572 |
accces_date_intl=$(echo "${access_datas[0]} ${access_datas[1]}" | sed -E 's@^([0-9]{2})+/+([0-9]{2})+/+([0-9]{4})+@\3-\2-\1@') # Convert date format DD/MM/YYYY to YYYY-MM-DD
|
| - |
|
573 |
access_date=$(date -d "$accces_date_intl" +%s)
|
| 581 |
#get admin_log.php from ACC
|
574 |
access_user=${access_datas[2]}
|
| 582 |
wget -q -nv --user $tmp_account --password $password "https://alcasar/acc/admin_log.php?startTime=$SECS_AGO" -O $TMP_STATS --no-check-certificate
|
575 |
access_ip=${access_datas[3]}
|
| 583 |
|
576 |
|
| 584 |
#clean this file to include it in html report.
|
577 |
if [ $access_date -lt $SECS_AGO ]; then
|
| 585 |
DELIM_1="<table class=\"table table-striped\">"
|
- |
|
| 586 |
DELIM_2="<\/table>"
|
578 |
break
|
| 587 |
cat $TMP_STATS | sed -n "/$DELIM_1/,/$DELIM_2/p" > $TMP_STATS_2
|
- |
|
| 588 |
cat $TMP_STATS_2 | sed -e 's:images/pixel.gif:../../manager/htdocs/images/pixel.gif:g' >> $HTML_REPORT
|
- |
|
| - |
|
579 |
fi
|
| 589 |
|
580 |
|
| 590 |
#we delete our user if he still exists
|
581 |
access_date_formatted=$(date -d @$access_date +"%x %X")
|
| 591 |
if [ $(grep "$tmp_account:" $DIR_KEY/key_only_manager | wc -l) -ge 1 ]
|
- |
|
| 592 |
then
|
582 |
|
| 593 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_only_manager
|
583 |
ROWS="$ROWS<tr><td>$access_date_formatted</td><td>$access_user</td><td>$access_ip</td></tr>"
|
| 594 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_manager
|
584 |
done < <(cat /var/www/html/acc/admin_log.txt | sort -r)
|
| 595 |
$SED "/^$tmp_account:/d" $DIR_KEY/key_all
|
585 |
# TODO: Read archives if necessary
|
| - |
|
586 |
|
| - |
|
587 |
if [ -z "$ROWS" ]; then
|
| - |
|
588 |
ROWS="<tr><td colspan=\"3\" style=\"text-align: center;\">Aucune connexion</td></tr>"
|
| 596 |
fi
|
589 |
fi
|
| 597 |
|
590 |
|
| - |
|
591 |
# Create HTML document
|
| - |
|
592 |
echo "<h2>Connexion à l'ALCASAR Control Center (ACC)</h2>" >> $HTML_REPORT
|
| - |
|
593 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| - |
|
594 |
echo "<thead><tr><th>Date</th><th>Utilisateur</th><th>Adresse IP</th></tr></thead><tbody>" >> $HTML_REPORT
|
| - |
|
595 |
echo $ROWS >> $HTML_REPORT
|
| - |
|
596 |
echo "</tbody></table>" >> $HTML_REPORT
|
| - |
|
597 |
|
| 598 |
|
598 |
|
| 599 |
###################### ALCASAR : GLOBAL TRAFFIC ######################
|
599 |
###################### ALCASAR : GLOBAL TRAFFIC ######################
|
| 600 |
echo "Get Global traffic of the last 30 days"
|
600 |
echo "Get Global traffic of the last 30 days"
|
| 601 |
|
601 |
|
| 602 |
ROWS=""
|
602 |
ROWS=""
|
| 603 |
EXTIF=$(cat /usr/local/etc/alcasar.conf | grep EXTIF | cut -d'=' -f2)
|
603 |
EXTIF=$(cat /usr/local/etc/alcasar.conf | grep '^EXTIF=' | cut -d'=' -f2)
|
| 604 |
for day in $(vnstat --exportdb -i $EXTIF | grep '^d;' | sort -t";" -k3 -r); do
|
604 |
for day in $(vnstat --exportdb -i $EXTIF | grep '^d;' | sort -t";" -k3 -r); do
|
| 605 |
day_datas=(${day//;/ })
|
605 |
day_datas=(${day//;/ })
|
| 606 |
day_date=${day_datas[2]}
|
606 |
day_date=${day_datas[2]}
|
| 607 |
day_rxMio=${day_datas[3]}
|
607 |
day_rxMio=${day_datas[3]}
|
| 608 |
day_txMio=${day_datas[4]}
|
608 |
day_txMio=${day_datas[4]}
|
| Line 616... |
Line 616... |
| 616 |
|
616 |
|
| 617 |
if [ $day_date -lt $SECS_AGO ]; then
|
617 |
if [ $day_date -lt $SECS_AGO ]; then
|
| 618 |
break
|
618 |
break
|
| 619 |
fi
|
619 |
fi
|
| 620 |
|
620 |
|
| 621 |
day_dateFormated=$(date -d @$day_date +%x)
|
621 |
day_date_formatted=$(date -d @$day_date +%x)
|
| 622 |
day_rx=$(($day_rxMio * 1048576 + $day_rxKio * 1024))
|
622 |
day_rx=$(($day_rxMio * 1048576 + $day_rxKio * 1024))
|
| 623 |
day_tx=$(($day_txMio * 1048576 + $day_txKio * 1024))
|
623 |
day_tx=$(($day_txMio * 1048576 + $day_txKio * 1024))
|
| 624 |
day_total=$(($day_rx + $day_tx))
|
624 |
day_total=$(($day_rx + $day_tx))
|
| 625 |
day_rxFormated=$(numfmt --from=iec --to=iec --suffix=B $day_rx)
|
625 |
day_rx_formatted=$(numfmt --from=iec --to=iec --suffix=B $day_rx)
|
| 626 |
day_txFormated=$(numfmt --from=iec --to=iec --suffix=B $day_tx)
|
626 |
day_tx_formatted=$(numfmt --from=iec --to=iec --suffix=B $day_tx)
|
| 627 |
day_totalFormated=$(numfmt --from=iec --to=iec --suffix=B $day_total)
|
627 |
day_total_formatted=$(numfmt --from=iec --to=iec --suffix=B $day_total)
|
| 628 |
|
628 |
|
| 629 |
ROWS="$ROWS<tr><td>$day_dateFormated</td><td>$day_rxFormated</td><td>$day_txFormated</td><td>$day_totalFormated</td></tr>"
|
629 |
ROWS="$ROWS<tr><td>$day_date_formatted</td><td>$day_rx_formatted</td><td>$day_tx_formatted</td><td>$day_total_formatted</td></tr>"
|
| 630 |
done
|
630 |
done
|
| 631 |
|
631 |
|
| - |
|
632 |
if [ -z "$ROWS" ]; then
|
| - |
|
633 |
ROWS="<tr><td colspan=\"4\" style=\"text-align: center;\">Aucun jour capturé</td></tr>"
|
| - |
|
634 |
fi
|
| - |
|
635 |
|
| 632 |
# Create html document
|
636 |
# Create html document
|
| 633 |
echo "<h3>Trafic global</h3>" >> $HTML_REPORT
|
637 |
echo "<h2>Trafic global</h2>" >> $HTML_REPORT
|
| 634 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
638 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| 635 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
639 |
echo "<thead><tr><th>Date</th><th>Entrant</th><th>Sortant</th><th>Total</th></tr></thead><tbody>" >> $HTML_REPORT
|
| 636 |
echo $ROWS >> $HTML_REPORT
|
640 |
echo $ROWS >> $HTML_REPORT
|
| 637 |
echo "</tbody></table>" >> $HTML_REPORT
|
641 |
echo "</tbody></table>" >> $HTML_REPORT
|
| 638 |
|
642 |
|
| 639 |
|
643 |
|
| 640 |
###################### ALCASAR : FAIL2BAN ######################
|
644 |
###################### ALCASAR : FAIL2BAN ######################
|
| 641 |
echo "Get fail2ban log of the week"
|
645 |
echo "Get fail2ban log of the week"
|
| 642 |
|
646 |
|
| 643 |
# Create html document
|
- |
|
| 644 |
echo "<h3>Adresse(s) IP bloquée(s) (Fail2Ban)</h3>" >> $HTML_REPORT
|
- |
|
| 645 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
- |
|
| 646 |
echo "<thead><tr><th>Date</th><th>Adresse IP</th><th>Règle</th></tr></thead><tbody>" >> $HTML_REPORT
|
- |
|
| 647 |
|
647 |
ROWS=""
|
| 648 |
DATE_1_WEEK_AGO=$(date --date="$MAX_DAY_AGO days ago" +'%Y-%m-%d %H:%M:%S,%N' | rev | cut -c 7- | rev)
|
648 |
dateDaysAgo_formatted=$(date --date="$MAX_DAY_AGO days ago" +'%Y-%m-%d %H:%M:%S,%N' | rev | cut -c 7- | rev)
|
| 649 |
# TODO: awk compare date [$1] AND hour [$2] (currently only date is compared)
|
- |
|
| 650 |
grep " Ban " /var/log/fail2ban.log | sort -r | awk '$1 >= "$DATE_1_WEEK_AGO"' | while read -r log ; do
|
649 |
while read -r log ; do
|
| 651 |
log_datas=($log)
|
650 |
log_datas=($log)
|
| 652 |
log_date="${log_datas[0]} ${log_datas[1]}"
|
651 |
log_date="${log_datas[0]} ${log_datas[1]}"
|
| 653 |
log_type=${log_datas[4]:1:-1}
|
652 |
log_type=${log_datas[4]:1:-1}
|
| 654 |
log_ip=${log_datas[6]}
|
653 |
log_ip=${log_datas[6]}
|
| 655 |
log_dateFormated=$(date -d "$log_date" +"%x %X")
|
654 |
log_date_formatted=$(date -d "$log_date" +"%x %X")
|
| 656 |
|
655 |
|
| 657 |
echo "<tr><td>$log_dateFormated</td><td>$log_ip</td><td>$log_type</td></tr>" >> $HTML_REPORT
|
656 |
ROWS="$ROWS<tr><td>$log_date_formatted</td><td>$log_ip</td><td>$log_type</td></tr>"
|
| - |
|
657 |
done < <(grep " Ban " /var/log/fail2ban.log | sort -r | awk -v dateDaysAgo="$dateDaysAgo_formatted" '($1 " " $2) >= dateDaysAgo')
|
| - |
|
658 |
|
| - |
|
659 |
if [ -z "$ROWS" ]; then
|
| - |
|
660 |
ROWS="<tr><td colspan=\"3\" style=\"text-align: center;\">Aucune adresse IP bloquée</td></tr>"
|
| 658 |
done
|
661 |
fi
|
| 659 |
|
662 |
|
| - |
|
663 |
# Create html document
|
| - |
|
664 |
echo "<h2>Adresse(s) IP bloquée(s) (Fail2Ban)</h2>" >> $HTML_REPORT
|
| - |
|
665 |
echo "<table class=\"table table-striped\">" >> $HTML_REPORT
|
| - |
|
666 |
echo "<thead><tr><th>Date</th><th>Adresse IP</th><th>Règle</th></tr></thead><tbody>" >> $HTML_REPORT
|
| - |
|
667 |
echo $ROWS >> $HTML_REPORT
|
| 660 |
echo "</tbody></table>" >> $HTML_REPORT
|
668 |
echo "</tbody></table>" >> $HTML_REPORT
|
| 661 |
|
669 |
|
| 662 |
|
670 |
|
| 663 |
######################FIN HTML######################
|
671 |
######################FIN HTML######################
|
| 664 |
|
672 |
|