ããã«ã¡ã¯
Mikrotikã«ãŒã¿ãŒçšã®ãããã¯ãŒã¯ãã©ãã£ãã¯ã¡ã¿ããŒã¿ã³ã¬ã¯ã·ã§ã³ãµãŒããŒãç°¡åãã€èªç¶ã«æ§æã§ããããšããäŒãããããšæããŸãã
ç®çïŒç®æšã¯ã詳现ãªåæã®ããã«ããåãã ããã¡ã€ã¢ãŠã©ãŒã«ãã°ãããŒã¿ããŒã¹ã«ä¿åããããšã§ãã
æå³ïŒ rsyslogd v8以éã®æ°ããLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯ãã¹ãŠå®è£
ã«é©ããŠããŸããããããææ¡ãããæ§æã¯v7ã§ãæ©èœããŸãã DBMSãå¿
èŠã§ããmariadbãéžæããŸããã ããŒã¿ããŒã¹ã®æé·ã¯ãèšé²ãããã«ãŒã«ã®æ°ãšã¯ç°ãªããŸãããã©ã€ãã®ãµã€ãºã¯ä»»æã§ãããããç§ã®å Žåã30ã40ã®ã«ãŒã«ãèšé²ãããŸããããã¯1æ¥ãããçŽ12äžè¡ã§ãã ã€ã³ããã¯ã¹ãå«ãããŒã¿ããŒã¹ã䜿çšããæã«ã3.8 GBã«å¢å ããŸããã
ã¡ã«ããºã ïŒã«ãŒã¿ãŒã¯UDPçµç±ã§ãã°ããªã¢ãŒããµãŒããŒã«éä¿¡ããŸãã æ£èŠè¡šçŸã䜿çšããŠãrsyslogãµãŒããŒã¯äžèŠãªæ
å ±ã®æååãåé€ããSQLæ¿å
¥ãçæããŠDBMSã«éä¿¡ããŸãã DBMSã¯ãæ¿å
¥åã«ããªã¬ãŒã䜿çšããŠãrsyslogã§è§£æã§ããªãã£ããã£ãŒã«ãã®è¿œå ã®ã¯ãªãŒãã³ã°ãšåé¢ãå®è¡ããŸãã
RSYSLOGãæ§æãã
ãã¡ã€ã«/etc/rsyslog.confã®ç·šé
ããã«æ¬¡ã®è¡ã远å ããŸãã
module(load="ommysql") module(load="imudp") input(type="imudp" port="514")
ãããã£ãŠãå¿
èŠãªã¢ãžã¥ãŒã«ãããŒããã514 UDPããŒããéããŸãã
Mikrotikããã®ãã°ã®è¡ã¯æ¬¡ã®ããã«ãªããŸãã
20180927155341 BLOCKSMKNETS forward: in:ether6 - LocalTORF out:VLAN55 - RT_INET, src-mac 00:15:17:31:b8:d7, proto TCP (SYN), 192.168.0.234:2457->192.168.6.14:65535, len 60
ã芧ã®ããã«ãããŒã¿ããŒã¹ã«ä¿åããããã®äœåãªãã®ãšæç¢ºãªéžæã¯å°é£ã§ãã
çè«çã«ã¯ããã®ãããªããŒã¿ã远å ããå¿
èŠããããŸãã
20180927155341 ether6 VLAN5 192.168.0.234 2457 192.168.6.14 65535 00:15:17:31:b8:d7 TCP SYN forward BLOCKSMKNETS 60
rsyslogã1ã€ã ã䜿çšããŠãã®ãããªè¡ãååŸã§ããŸããã§ããã Rsyslogã¬ã®ã¥ã©ãŒã¯POSIX ERE / BREã䜿çšãããããlookaheadãlookbehindãªã©ã®æ©èœãé©çšããæ¹æ³ã¯ãããŸããã
ã¬ã®ã¥ã©ãŒããããã°ããŠè©Šãããšãã§ããããŒã«ããããŸããããŒããã¢ãã¬ã¹ããåé¢ããããã€ã³ã¿ãŒãã§ãŒã¹ã®ååãinïŒãoutïŒããåé¢ãããã§ããŸãã äžéšã®ã¹ããŒãããã³dportãããã³ã«ãæ¬ èœããŠããããšã«æ³šæããŠãã ããã
äžè¬ã«ãç§ã®åºåã¯æ¬¡ã®ããã«ãªããŸããã
20180927155341 in:ether6 out:VLAN5 192.168.0.234:2457 192.168.6.14:65535 00:15:17:31:b8:d7 TCP (SYN) forward BLOCKSMKNETS 60
rsyslogã®åžžé£ã調çããæ¹æ³ã«é¢ããããã¥ã¡ã³ã
ããããŸãã
æåŸã®ãã©ãŒã ã§ã¯ãMikrotik /etc/rsyslog.d/20-remote.confãããã°ãåä¿¡ããããã®æ§æãã¡ã€ã«ã¯æ¬¡ã®ããã«ãªããŸãã
$template tpl_traflog,"insert into traflog.traffic (datetime, inif, outif, src, dst, smac, proto, flags, chain, logpref, len) values ('%timereported:::date-mysql%', '%msg:R,ERE,0,DFLT,0:in:[a-zA-Z]+[0-9]+|in:<[a-zA-Z]+-[a-zA-Z]+>--end%', '%msg:R,ERE,0,BLANK,0:out:[a-zA-Z]+[0-9]+|out:<[a-zA-Z]+-[a-zA-Z]+>--end%', '%msg:R,ERE,0,DFLT,0:([0-9]+\.){3}[0-9]+[:]?([0-9]+)?--end%', '%msg:R,ERE,0,DFLT,1:([0-9]+\.){3}[0-9]+[:]?([0-9]+)?--end%', '%msg:R,ERE,0,BLANK:([0-f]+:){5}[0-f]+--end%', '%msg:R,ERE,0,BLANK:\b[AX]{3,4}\b--end%', '%msg:R,ERE,0,BLANK:\([AZ]+\)|\(([AZ]+\,){1,3}[AZ]+\)--end%', '%msg:R,ERE,0,DFLT:[ax]+--end%', '%msg:F,32:2%', '%msg:R,ERE,0,DFLT:[0-9]+$--end%' )",SQL if ($fromhost-ip == '192.168.0.230') and ($syslogtag contains "firewall") then {action(type="ommysql" server="localhost" serverport="3306" db="traflog" uid="rsyslogger" pwd="rsyslogger" template="tpl_traflog") stop}
æåã®è¡ã®ãã³ãã¬ãŒãïŒãã³ãã¬ãŒãïŒã®èª¬æã¯ãDBMSã«è»¢éããSQLã³ãŒãã®è¡ã§ãã
2è¡ç®ã¯ãã¢ã¯ã·ã§ã³ãçºçããæ¡ä»¶ãã€ãŸãDBMSã®ã¬ã³ãŒãã§ãã
æ¡ä»¶ã¯æ¬¡ã®ããã«ãªããŸãïŒãã°ãœãŒã¹= 192.168.0.230ïŒ
if ($fromhost-ip == '192.168.0.230')
ïŒãããŠãmsgè¡ã«ãfirewallããå«ãŸããå ŽåïŒããã³ïŒ$ syslogtagã«ãfirewallããå«ãŸããïŒïŒãã¢ãžã¥ãŒã«ã䜿çšããå Žåæ¥ç¶ãã©ã¡ãŒã¿ãŒã䜿çšããommysqlïŒ
then {action(type="ommysql" server="localhost" serverport="3306" db="traflog" uid="rsyslogger" pwd="..."
ïŒãã³ãã¬ãŒãtpl_traflogïŒ
template="tpl_traflog")
ïŒããã®åŸãè¡ã®ãããªãåŠçã忢ããŸãïŒ
stop}
ïŒã
ããªãã®å ŽåãäœããããŸããããªãå¯èœæ§ããããŸããããã¯ãã€ã³ã¿ãŒãã§ãŒã¹ã®ååãŸãã¯ãã°æ¥é èŸãããããäœãä»ã®ãã®ãããããŸããã ãããã°ã®ããã«ã次ã®ããšãè¡ãã2è¡ç®ã«ã³ã¡ã³ããä»ããæ°ãããã³ãã¬ãŒããš2ã€ã®æ°ããæ¡ä»¶ã远å ããŸãã
$template tpl_traflog_test,"%timereported:::date-mysql% %msg:R,ERE,0,DFLT,0:in:[a-zA-Z]+[0-9]+|in:<[a-zA-Z]+-[a-zA-Z]+>--end% %msg:R,ERE,0,BLANK,0:out:[a-zA-Z]+[0-9]+|out:<[a-zA-Z]+-[a-zA-Z]+>--end% %msg:R,ERE,0,DFLT,0:([0-9]+\.){3}[0-9]+[:]?([0-9]+)?--end% %msg:R,ERE,0,DFLT,1:([0-9]+\.){3}[0-9]+[:]?([0-9]+)?--end% %msg:R,ERE,0,BLANK:([0-f]+:){5}[0-f]+--end% %msg:R,ERE,0,BLANK:\b[AX]{3,4}\b--end% %msg:R,ERE,0,BLANK:\([AZ]+\)|\(([AZ]+\,){1,3}[AZ]+\)--end% %msg:R,ERE,0,DFLT:[ax]+--end% %msg:F,32:2% %msg:R,ERE,0,DFLT:[0-9]+$--end%\n" if ($fromhost-ip == '192.168.0.230') then {action(type="omfile" file="/var/log/remote/192.168.0.230.log" )} if ($fromhost-ip == '192.168.0.230') then {action(type="omfile" file="/var/log/remote/192.168.0.230.log" template="tpl_traflog_test" ) stop}
ãã¬ãŒãåèµ·åããŸãã
tpl_traflog_testãã³ãã¬ãŒãã¯tpl_traflogã«äŒŒãŠããŸãããSQL INSERTã¯ãããŸããã
æåã®æ¡ä»¶ã¯ããã³ãã¬ãŒããæå®ãããŠããªããããæªåŠçã®è¡ïŒ
msgïŒ
ããã¡ã€ã«/var/log/remote/192.168.0.230.logã«è¿œå ããŸãã
2çªç®ã®æ¡ä»¶ã¯ãåŠçãããè¡ãåããã¡ã€ã«ã«è¿œå ããŸãã
ãããã£ãŠãæ¯èŒããæ¹ã䟿å©ã§ãã
次ã«ãããŒã¿ããŒã¹ãæºåããŸãã
DBãæºåããŸã
DBMSèšå®ãäžããŸããããã§ã¯ãã¹ãŠãæšæºã§ãã
mysqlã³ã³ãœãŒã«ãèµ·åããŠã次ã®ã³ãŒããå®è¡ããŸãã
ãŠãŒã¶ãŒã¯ããŒãã«ã®æºåãã§ããŸããã
ããã§ããªã¬ãŒã远å ããŸãããã¬ãŒãããŒãããã¢ãã¬ã¹ãåé¢ããã®ã«å€±æããããšãå®è¡ããã€ã³ã¿ãŒãã§ã€ã¹ã®ååãæ¶å»ãããã©ã°ããè§ãã£ããåé€ããŸãã
REGEXP_REPLACEã¯ãå°æ°ç¹ã®æ¬¡ã®2çªç®ã®ãã©ã¡ãŒã¿ãŒïŒéåžžã®å£ç¯ïŒãæ€çŽ¢ããããã3çªç®ã®ãã©ã¡ãŒã¿ãŒã«çœ®ãæããŸãããã®å ŽåãåŒçšç¬Šã§å²ãŸããŠããªããããæ€åºããããã®ãåã«åé€ããŸãã
ãã¬ãŒãè¡ãæ¹æ³ãšåæ§ã«ããã¹ãæ¿å
¥ãäœæããŸãããã
äœãèµ·ãã£ãã®ãèŠãŠã¿ãŸãããïŒ
select * from tarffic;
ãã¹ãŠãæ£ããå Žåã¯ã次ã«é²ã¿ãŸãã ããã§ãªãå Žåã¯ãééããæ¢ããŠããŸãã
å°ãªããšã1ã€ã®ã€ã³ããã¯ã¹ã远å ããŸãã ç§ã¯ã€ã³ããã¯ã¹ãäœæãããã¹ã¿ãŒã§ã¯ãããŸããããçè§£ããŠããããã«ãmysqlã§ã¯ãç°ãªãã¯ãšãªã«ç°ãªãçµåãã£ãŒã«ããæã€ã€ã³ããã¯ã¹ã䜿çšããæ¹ãæ£ããã§ãããªããªãã1ã€ã®ã¯ãšãªã¯1ã€ã®ã€ã³ããã¯ã¹ãã䜿çšã§ããªãããã§ãïŒãŸãã¯ééã£ãŠããŸããïŒïŒã çè§£ããããããªãã®è£éã§ãããããŠãã ããã
ç§ã¯é »ç¹ã«ç¹å®ã®ãã¬ãã£ãã¯ã¹ã§ãªã¯ãšã¹ããäœæããå¿
èŠãããããããã®ã€ã³ããã¯ã¹ã远å ããŸããã
ã§ãã
ã«ãŒã¿ãŒã§ã®éä¿¡ãéå§ãããªã¢ãŒããã°ãµãŒããŒã®èšå®ãšã¢ã¯ã·ã§ã³ã远å ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®1ã€ã«ãã°ãªãã·ã§ã³ã远å ãã24æå以å
ã®ãã¬ãã£ãã¯ã¹ã远å ããå¿
èŠããããŸãã
Mikrotikã³ã³ãœãŒã«ã§ã¯ã次ã®ããã«ãªããŸãã
/system logging action set 3 remote=192.168.0.94 src-address=192.168.0.230 add name=remote2 remote=192.168.0.19 syslog-facility=local6 target=remote /system logging add action=remote topics=error,account,critical,event,info add action=remote2 topics=firewall /ip firewall filter ... add action=drop chain=input comment="drop ssh brute forcers" dst-port=22,8291 log=yes log-prefix=DROP_SSH_BRUTE protocol=tcp src-address-list=ssh_blacklist ...
ããã§ã192.168.0.230ã¯ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ã192.168.0.19ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãã°ã®ãã°ãµãŒããŒã®ã¢ãã¬ã¹ã192.168.0.94ã¯å¥ã®ãã°ãµãŒããŒã§ããMikrotikã·ã¹ãã ãã°ããããŸãããä»ã¯å¿
èŠãããŸããã ã»ããã¢ããã¯remote2ã§ãã
次ã«ããã¡ã€ã«ã®å
容ã確èªããŸãã
tail -f /var/log/remote/192.168.0.230.log
ãã¡ãããã«ãŒã«ãéåžžã«é »ç¹ã«ããªã¬ãŒãããªãéããã«ãŒã¿ãŒããã®è¡ã¯ãã¡ã€ã«ã«æ¿å
¥ããå¿
èŠããããŸãã
äžéšã®ãã£ãŒã«ããæ¬ èœããŠããå Žåãã€ãŸããã·ãŒã±ã³ã¹datetimeãinifãoutifãsrcãdstãsmacãprotoãflagsãchainãlogprefãlenãåŸã«ç¶ããªãå Žåã¯ããã¬ãŒã®ãããã°ãã³ãã¬ãŒãã®ãã©ã¡ãŒã¿ãŒã倿ŽããŠãBLANKãDLFTã«çœ®ãæããããšãã§ããŸãã æ¬¡ã«ããã£ãŒã«ãã空ã§ãã代ããã«ãããã€ãã®æåã衚瀺ãããŸããã©ã®æåããã§ã«èšæ¶ãããŠãããã¯èŠããŠããŸããã ãããçºçããå Žåãéåžžã®ã¹ã±ãžã¥ãŒã«ã«äœãåé¡ããããä¿®æ£ããå¿
èŠããããŸãã
ãã¹ãŠãæ£åžžã«å®äºãããããã¹ãæ¡ä»¶ãšãã³ãã¬ãŒãããªãã«ããŸãã
ãŸãã以äžã®/etc/rsyslog.d/ã§ããã©ã«ãã®èšå®ãå®è¡ããå¿
èŠããããŸãããªã¢ãŒããã°ãã·ã¹ãã ãã°/ var / log / messageã«æ³šãããªãããã«ã50-default.confã«ååã倿ŽããŸãã
ãã¬ãŒãåèµ·åããŸãã
ããŒã¿ããŒã¹ããã£ã±ãã«ãªããŸã§å°ãåŸ
ã¡ãŸãããã ãã®åŸãéžæãéå§ã§ããŸãã
äŸã®ããã®ããã€ãã®ã¯ãšãªïŒããŒã¿ããŒã¹ã®ãµã€ãºãšè¡æ°ã確èªããã«ã¯ïŒ MariaDB [traflog]> select table_schema as "database", round(sum(data_length + index_length)/1024/1024,2) as "size Mb", TABLE_ROWS as "count rows" from information_schema.tables group by table_schema; +
1ãæã§çŽ4GBãæé·ããŸãããããã°ã«èšé²ããããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®æ°ãšããããã£ã«äŸåããŸã
ãã°ã«èšé²ããããã¬ãã£ãã¯ã¹ã®æ°ãã°ã«èšé²ããããã¬ãã£ãã¯ã¹ã®æ°ã¯ã«ãŒã«ã®æ°ãšçãããããŸãããäžéšã®ã«ãŒã«ã¯1ã€ã®ãã¬ãã£ãã¯ã¹ã§æ©èœããŸãããããã§ãåèšãã¬ãã£ãã¯ã¹ã®æ°ã¯ããã€ã§ããïŒ ãããŠããããã®ããã«ããã€ã®ã«ãŒã«ãäœæãããŸãããïŒïŒ
MariaDB [traflog]> select logpref,count(logpref) from traffic group by logpref order by count(logpref) desc; +
ACCEPT_TORF_INETãå
é ã«ç«ã¡ãŸãããã®ãã¬ãã£ãã¯ã¹ã«ãããããŒã«ã«ãããã¯ãŒã¯ããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ãããã¹ãŠã®äººãèŠã€ããããšãã§ãããããã³ã«ãšããŒããèšé²ãããæãæ¥ãŠäžéšã®ã¢ã¯ã»ã¹ãéããããŸãã ãã°ã«é¢ããä»åŸã®äœæ¥ã®åç
§ããŒã¿ããããŸãã
SMTPã¹ãã¢ãªãŒããŒä»æ¥èª°ãsmtpãµãŒããŒã«ã¢ã¯ã»ã¹ããããšããããèŠãŠã¿ãŸãããã
MariaDB [traflog]> select src,count(dport) from traffic where logpref='SMTP_DNAT' and datetime > '2018101600000000' group by src order by count(dport) desc limit 10; +
仿¥ãããŒã191.96.249.92ãåè
ã§ããããšã¯æããã§ãã 圌ããŸã èšé²ãããŠããã«ãŒã«ãèŠãŠã¿ãŸãããïŒ
MariaDB [traflog]> select src,dport,count(dport),logpref from traffic where src='191.96.249.92' group by logpref order by count(dport) desc; +
ããã¯smtpã®ã¿ã«ç¹åããŠããããã¹ã¯ãŒããæšæž¬ããããšãããããŽããéãããšããããããããã®1ïŒ
çšåºŠã§ãæ®ãã¯æµŽå Žã«è¡ããŸããã
ãªã¯ãšã¹ãã«ã¯10ââåããããŸãããããã¯éåžžã«å€ããçŸåšã®ã€ã³ããã¯ã¹ã¯ããã«é©ããŠããªããããªã¯ãšã¹ããåå®åŒåããããšã¯ã§ããŸãããããã«ã€ããŠã¯èª¬æããŸããã
å°æ¥çã«ã¯ãWebã€ã³ã¿ãŒãã§ãŒã¹ãæšæºã®ã¯ãšãªãšãã©ãŒã ã«ãã蟌ãããšãèšç»ãããŠããŸãã
ãã¯ãã«ãäžããããŠããŸãããã®èšäºã圹ã«ç«ã€ããšãé¡ã£ãŠããŸãã
ã¿ããªããããšãïŒ
åç
§ïŒRsyslogããã¥ã¡ã³ãMySQLããã¥ã¡ã³ãMikrotikãã®ã³ã°ããã¥ã¡ã³ãLORã³ãã¥ããã£ã®
ãã³ããããããšã
ãUPD.1ããŒã¿ããŒã¹ã«ãã©ã°ãã£ãŒã«ãã远å ãããSYNãFINããã£ããããããšã§æ¥ç¶æéã远跡ã§ããããã«ãªããŸããã
rsyslogã¬ã®ã¥ã©ãŒã®ããã€ãã®ãã°ãšmysqlããªã¬ãŒãä¿®æ£ããŸããã
äžæè°ãªããšã«ãããã©ã«ãã®defconfïŒdrop invalidã«ãŒã«ã¯TCPæ¥ç¶ã®ãã¹ãŠã®æçµãã±ãããããããããŸãããã®çµæãç§åŠã§æ¥ç¶ãéããããšãããã¹ãŠã®ããŒãã¯å€±æããããã€ãã®FINãéä¿¡ããŸãã ããã¯æ£ããã§ããïŒ
ACKãFINãã©ã°ã䜿çšããTCPãã©ããŒãµã«ãèš±å¯ããã«ãŒã«ã远å ããŸããã
SQLã¹ãã€ã©ãŒã®äžã§ãéå»5åéã®TCPæ¥ç¶ã®æéã瀺ãæé
connections_listïŒïŒ DROP PROCEDURE IF EXISTS connections_list; DELIMITER // CREATE PROCEDURE connections_list() BEGIN DECLARE logid BIGINT UNSIGNED; DECLARE done INT DEFAULT FALSE; DECLARE datefin DATETIME; DECLARE datesyn DATETIME; DECLARE conntime TIME; DECLARE connsport INT; DECLARE conndport INT; DECLARE connsrc VARCHAR(21); DECLARE conndst VARCHAR(21); DECLARE cur CURSOR FOR SELECT id,datetime,src,sport,dst,dport FROM conn_syn_fin WHERE flags='SYN'; DECLARE CONTINUE HANDLER FOR NOT FOUND SET done=TRUE; DROP TABLE IF EXISTS conn_syn_fin; DROP TABLE IF EXISTS connless; CREATE temporary TABLE connless(datestart DATETIME,dateend DATETIME,duration TIME,src VARCHAR(21),sport INT,dst VARCHAR(21),dport INT); CREATE temporary TABLE conn_syn_fin (SELECT * from traffic WHERE datetime > now() - interval 5 minute and src in (select src from traffic where datetime > now() - interval 5 minute and logpref='TCP_FIN' and flags like '%FIN%') and (flags like '%SYN%' or flags like '%FIN%') order by id); OPEN cur; read_loop: LOOP FETCH cur INTO logid,datesyn,connsrc,connsport,conndst,conndport; IF done THEN LEAVE read_loop; END IF; set datefin=(SELECT datetime FROM conn_syn_fin WHERE id>logid and src=connsrc and sport=connsport and flags like '%FIN%' and dst=conndst and dport=conndport limit 1); set conntime=(SELECT timediff(datefin,datesyn)); INSERT INTO connless (datestart,dateend,duration,src,sport,dst,dport) value (datesyn,datefin,conntime,connsrc,connsport,conndst,conndport); END LOOP; CLOSE cur; select * from connless; END; // DELIMITER ;
æé ã®çµæã2ã€ã®äžæããŒãã«ãäœæãããŸãã
conn_syn_finããŒãã«ã«ã¯ãSYNããã³FINãã©ã°ãæã€ãã°ãšã³ããªãå«ãŸãããã®ããŒãã«ã®ã«ãŒãœã«ã䜿çšããŠæ€çŽ¢ãå®è¡ãããŸãã
connlessããŒãã«ã«ã¯ãæ¥ç¶ã®ãªã¹ããå«ãŸããŠãããéããŠããç¶æ
ãšå®äºããŠããç¶æ
ãå®äºããç¶æ
ã®æéã¯ããããéããŠããç¶æ
ããªã
çŸåšã®æå»ãã5åãåŒãããµã³ããªã³ã°æéã«æ³šæããŠãã ããã ç§ã®èŠæ±ã¯é
ãã§ãã ãã£ãããšã«ãŒãœã«æ€çŽ¢ãå®è¡ãã1ç§ãããçŽ10ã¬ã³ãŒããåŠçããããããæ¹æ³ã§é«éåããããšããŸããããå®è¡æéã¯åžžã«ã»ãŒåãã§ãã
ãŸãããã®æé ã¯ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã®ã¿ãç®çãšããŠããŸãã ç¹å®ã®src / sport / dst / dportãéžæããå¿
èŠãããå Žåã¯ãããã«äŒŒãå¥ã®æé ãäœæããããšããå§ãããŸãã SQLãã¹ã¿ãŒã®å Žåãã¯ãšãªãããé©åã«äœæã§ããŸãã
connections_listïŒïŒãåŒã³åºããŸãã MariaDB [traflog]> call connections_list(); +
æé ãå®äºãããšãäžæããŒãã«
conn_syn_finãš
connlessãæ®ããŸããçããããã®ãä¿¡é Œã§ããªããã®ãèŠã€ãã£ãå Žåã¯ããããã詳现ã«ç¢ºèªã§ããŸãã æé ãéå§ãããšãå€ãããŒãã«ãåé€ãããæ°ããããŒãã«ã衚瀺ãããŸãã ééããèŠã€ãããæžããŠãã ããã