Ozone Debug

审计解析器

师成师成· 更新于 2026-09-28· 阅读 3 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

审计解析器(Audit Parser)工具可用于查询 Ozone 审计日志。该工具会在指定路径下创建一个 sqlite 数据库;如果数据库已存在,则不会重复创建。

该数据库仅包含一张名为 audit 的表,其定义如下:

CREATE TABLE IF NOT EXISTS audit (
datetime text,
level varchar(7),
logger varchar(7),
user text,
ip text,
op text,
params text,
result varchar(7),
exception text,
UNIQUE(datetime,level,logger,user,ip,op,params,result))

用法:

ozone debug auditparser <path to db file> [COMMAND] [PARAM]

将审计日志加载到数据库:

ozone debug auditparser <path to db file> load <path to audit log>

load 命令会创建上文所述的审计表。

要运行自定义只读查询:

ozone debug auditparser <path to db file> query <select query enclosed within double quotes>

审计解析器(Audit Parser)自带一组模板(最常用的查询)。

要运行模板查询:

ozone debug auditparser <path to db file> template <templateName>

以下模板可用:

模板名称说明SQL
top5users前 5 名用户select user,count(*) as total from audit group by user order by total DESC limit 5
top5cmds前 5 个命令select op,count(*) as total from audit group by op order by total DESC limit 5
top5activetimebyseconds按秒分组的前 5 个活跃时间select substr(datetime,1,charindex(',',datetime)-1) as dt,count(*) as thecount from audit group by dt order by thecount DESC limit 5

下一页 >>

评论

登录后参与评论

正在加载评论…