- 论坛徽章:
- 32
|
本帖最后由 yestreenstars 于 2013-07-31 10:12 编辑
- [root@localhost ~]# awk 'NF{s1=gensub(/.*\] ([^=]*)IN=([^ ]*) OUT=([^ ]*).*SRC=([^ ]*) DST=([^ ]*).*PROTO=([^ ]*).*/,"\\1;\\2;\\3;\\4;\\5;\\6;",1);s2=/SPT/?gensub(/.*SPT=([^ ]*).*/,"\\1",1):"";s3=/DPT/?gensub(/.*DPT=([^ ]*).*/,"\\1",1):"";printf "%s %s %s %s%s;%s\n",$3,$2,$1,s1,s2,s3}!NF' i
- 19:56:52 12 Nov Warning;em0;eth0;222.171.89.16;49.137.111.136;ICMP;;
- 08:35:51 00 Aug That's odd;em0;eth0;142.53.155.238;252.1.134.24;ICMP;;
- 11:47:48 21 Jun Look into this ;em1;eth0;50.219.1.59;56.95.45.60;UDP;16351;15354
- 19:17:12 15 Apr MISSIVE ;em0;eth1;225.17.31.15;201.90.116.37;TCP;5351;24612
- 12:12:51 17 Jun That's odd;em1;;110.213.149.228;237.146.122.240;ICMP;;
- [root@localhost ~]#
复制代码 |
|