配置了ulog,我想自动用一个日志分析工具,查了一下,觉得Lire用来生成ulog的日志报表应该挺合适的。常规的lire生成报表命令是:
lr_log2report --output html iptables /var/log/ulog/syslogemu.log traffic_log
可惜,lire本身并不支持ulog的日志格式,看来有空有必要看看lire如何添加新的日志分析格式:
http://download.logreport.org/pub/current/doc/dev-manual/pr01s02.html
目前Lire支持的日志格式如下:
#lr_log2report --help dlf-converters
Available DLF converters:
argomail argomail log file
bind8_named bind8_named log file
bind8_query bind8_query log file
bind9_query bind9_query log file
cisco_ios cisco_ios log file
combined combined log file
common common log file
cups_pagelog CUPS printer server page log
dbmail dbmail log file
exim exim log file
iis_ftp Microsoft IIS ftp log
ipchains IPchains firewall log
ipfilter ipf firewall log
iptables Iptables firewall log
isdnlog isdnlog log file
lprng_account LPRNG printer server page log
modgzip modgzip log file
ms_isa ms_isa log file
mysql mysql log file
nms nms log file
nmsmmp nmsmmp log file
nmsstore nmsstore log file
pgsql pgsql log file
pix pix log file
postfix postfix log file
qmail qmail log file
referer referer log file
s1ms s1ms log file
sendmail sendmail log file
snort SNORT network sniffer log
spamassassin spamassassin log file
squid_access Squid proxy access log
syslog syslog log file
tinydns tinydns log file
w3c_extended w3c_extended log file
watchguard Watchguard firewall log
welf welf log file
welf_proxy welf_proxy log file
xferlog xferlog log file
Lire支持的日志报表文件格式:
#lr_log2report --help output-formats
Available output formats:
dvi DVI
excel95 Excel95 Spreadsheet
html (X)HTML
latex LaTeX
pdf PDF
ps PostScript
txt Plain Text
xml XML
Lire支持的日志报表格式:
#lr_log2report --help report-templates
Available report templates:
database_default
dialup_default
dns_default
dnszone_default
email_default
empty
firewall_default
ftp_default
msgstore_default
print_default
proxy_default
spamfilter_default
syslog_default
www_default