Ozone Debug
审计解析器
登录后可跨设备保存划线和私人笔记登录
审计解析器(Audit Parser)工具可用于查询 Ozone 审计日志。该工具会在指定路径下创建一个 sqlite 数据库;如果数据库已存在,则不会重复创建。
该数据库仅包含一张名为 audit 的表,其定义如下:
CREATE TABLE IF NOT EXISTS audit (
datetime text,
level varchar(7),
logger varchar(7),
user text,
ip text,
op text,
params text,
result varchar(7),
exception text,
UNIQUE(datetime,level,logger,user,ip,op,params,result))用法:
ozone debug auditparser <path to db file> [COMMAND] [PARAM]将审计日志加载到数据库:
ozone debug auditparser <path to db file> load <path to audit log>load 命令会创建上文所述的审计表。
要运行自定义只读查询:
ozone debug auditparser <path to db file> query <select query enclosed within double quotes>审计解析器(Audit Parser)自带一组模板(最常用的查询)。
要运行模板查询:
ozone debug auditparser <path to db file> template <templateName>以下模板可用:
| 模板名称 | 说明 | SQL |
|---|---|---|
| top5users | 前 5 名用户 | select user,count(*) as total from audit group by user order by total DESC limit 5 |
| top5cmds | 前 5 个命令 | select op,count(*) as total from audit group by op order by total DESC limit 5 |
| top5activetimebyseconds | 按秒分组的前 5 个活跃时间 | select substr(datetime,1,charindex(',',datetime)-1) as dt,count(*) as thecount from audit group by dt order by thecount DESC limit 5 |
评论
登录后参与评论
正在加载评论…
KnowForge