¡m¤À¨É¡nUbuntu¦w¸ËAdiscon loganalyzer | |
Linux¤W¥i³z¹L¬J¦³ªºrsyslogªA°È¨Ó¦¬®e©Ò¦³ªº³]³Ælog¡A¹F¨ì¶°¤¤ºÞ²z¥Øªº¡A
¦ý¦¬¶°«áªºlog¬O¥H¤å¦rÀɪº¤è¦¡¡A°O¿ý¦b/var/log/syslog¤¤¡A
¨Ã¥¼´£¨Ñ¤@Ó¤ñ¸û¦³¿Ë©M¤OªºUI¤¶±¨Ñ¨Ï¥ÎªÌ¬d¸ß...
n°µ¨ì³o¥\¯à¡A¥i³z¹L§K¶Oªº LogAnalyzer ¨Ó¿é¥Xweb¤¶±¨Ñ¨Ï¥ÎªÌ¾Þ§@¡C
¦ÓLogAnalyzer¬Obase on LAMP Server¡A
©Ò¥H§Ú̪ºLinux¤W¥²»Ý¥ý¸Ë¦nLAMP Server¡AµM«á¦A¨Ó¸ËLogAnalyzer¡C
³oÓ³¡¤Àºô¸ô¤W¬d¨ìªº¤å³¹¤£¤Ö¡A
¶¶¤l´N¥HUbuntu 14.04¬°¥¥x¡A¤]¨Ó¸Õ¸Õloganalyzerªº¦w¸Ë§a¡ã
¦w¸ËLAMP Server
¦bUbuntu¤W¡A§ÚÌ¥i¥H¦bOS¦w¸Ë¶¥¬q¡A´N¤@¨Ö¦w¸ËLAMP Server¡C
¦pªG¦bOS¦w¸Ë¶¥¬q¨Ã¥¼¦w¸ËLAMP Server¡A¨º»ò¥i¦b¦w¸Ë§¹¦¨«á¡A³z¹L¥H¤U«ü¥O³v¤@¦w¸ËLAMP Serverªº¦U¶µªA°È¡C
½Ð°È¥²°O¦ímysqlªºroot±K½X¡I
apt-get install apache2
apt-get install mysql-server
apt-get install php5 libapache2-mod-php5
¦w¸Ë§¹¦¨«á¡A¥i³z¹L¶}±Òweb¶±¨ÓÀˬdapache¬O§_¥¿±`¹B§@¡C
http://apache_server_IP/
PHP¼Ò²Õªº³¡¤À¡A¥i³z¹LPHP¤º«Øfunction phpinfo() ¨ÓÀˬdphp¬O§_¥¿±`¹B§@¡C
vim /var/www/html/info.php
<?php
phpinfo();
?>
http://apache_server_IP/info.php
¦w¸Ërsyslog¬ÛÃö®M¥ó
¦w¸ËGD®M¥ó¡A¥i¥HÅýPHPø»s¹ÏÀÉ¡C
apt-get install php5-gd
¦w¸Ërsyslog¬ÛÃö®M¥ó¡AÅýmysql»Prsyslog¯à°÷³sµ²°_¨Ó¡C
apt-get install rsyslog-mysql rsyslog-relp
³o¶¥¬q·|«Ø¥ß¤@Órsyslogªº¸ê®Æ®w Syslog¡A»Ý¥ý¿é¤Jmysqlªºroot±K½X¥H½T»{¾Ö¦³«Ø¥ßdatabaseªºÅv¡C
µM«á«Ø¥ß¤@²Õrsyslog-mysqlªº±K½X¡A¨Ã½T»{±K½X¡C
§¹¦¨«á¡AÀ˵ømysql¥i¥H¬Ý¨ì¤w«Ø¥ß¤@Ó·sªºdatabase Syslog¡C
³]©wrsyslog
LAMP Server»P¬ÛÃö®M¥ó¸Ë¦n«á¡A±µ¤U¨Ó´N¥i¥H³]©wrsyslog¡A¶}©ñ¥~³¡³]³Æ¼g¤Jlog°T®§¡C
¶}±Ò /etc/rsyslog.conf ³]©wÀÉ¡A¨ú®ø¥H¤UUDP TCP 514ªºµù¥U¡A¤¹³\¥~³¡³]³Æ¥i³z¹LUDP/TCP 514 port¨Ó¼g¤J¡C
# provides UDP syslog reception
$ModLoad imudp
$UDPServerRun 514
# provides TCP syslog reception
$ModLoad imtcp
$InputTCPServerRun 514
¦b³o¶¥¬q§¹¦¨¨Ã«±Òrsyslog server«á¡A¤w¸g¥i¥H¦¬®e¥~³¡³]³Æªºlog¤F¡C
service rsyslog restart
rsyslog±Ä¼Ò²Õ¤Æ³]p¡A°£¤F¥Dn³]©wÀÉ /etc/rsyslog.conf ¥~¡A¨ä¥¦¬ÛÃö³]©wÀɧ¡©ñ¸m¦b¥H¤U¸ô®|¡C
/etc/rsyslog.d/
§ÚÌn¦b¦¹¸ô®|¤¤¼W¥[¤@Ó·sªº³]©w relp.conf¡A¨ä¤º®e¦p¤U¡C
$ModLoad imrelp
$InputRELPServerRun 20514
µM«á©ó¥D³]©wÀÉrsyslog.conf¥[¤J¥H¤U³]©w¡C
$ActionQueueType LinkedList
$ActionQueueFileName dbq
$ActionResumeRetryCount -1
§¹¦¨«á«±Òrsyslog server¡Arsyslog serverªº³]©w¨ì¦¹µ²§ô¡C
¦w¸Ë¤ÀªR®M¥óAdiscon loganalyzer
¦w¸ËAdiscon loganalyzer®É¡A½Ð¥ý¤W Adiscon ºô¯¸½T»{¥Ø«e³Ì·s³Ìéwªºª©¥»¡C
¥H¶¶¤l´ú¸Õªº³oӮɶ¡ÂI¡A³Ì·s³Ìéwªºª©¥»¬O3.6.6¡A©Ò¥H´N¤U¸ü³oª©¥»¨Ó´ú¸Õ§a¡I
¸ÑÀ£«á¡A½Æ»sAdiscon loganalyzer¨ìweb siteªºlogs¥Ø¿ý¤U¡C
tar -xzf loganalyzer-3.6.6.tar.gz
cd loganalyzer-3.6.6
mkdir /var/www/html/logs
cp -R src/* /var/www/html/logs/
cp contrib/* /var/www/html/logs/
cd /var/www/html/logs/
chmod +x configure.sh secure.sh
./configure.sh
§¹¦¨«á¡A¶}±ÒÂsÄý¾¹³s¨ì¥H¤Uºô§}¡A¶i¦æloganalyzerªº¦w¸Ë¡C
http://rsyslog_server_IP/logs/
¦b²Ä3¨BÆJ¡A»Ý°é¿ï¡§Enable User Database¡¨¡A¥´¶}databaseªº²Ó¶µ³]©w¡C
Database Name½Ð¿é¤J Syslog¡A¦³¤j¤p¼gªº®t§O³á¡I
Database User½Ð¿é¤J rsyslog¡A
Database Password½Ð¿é¤J«Ø¥ß Syslog DB®É¡A©Ò¿é¤Jªº±K½X¡A
µM«á¤Ä¿ï¡§Require user to be logged in¡¨ªº Yes ¿ï¶µ¡C
Y¥H¤W³s½u¸ê°T¥¿½T¡A´N¯à¦¨¥\³sµ²mysql¸ê®Æ®w¡A
µM«á¶i¤J²Ä4¨BÆJ¡A³z¹L®M¥óùتºscript«Ø¥ß¸Ó¸ê®Æ®w©Ò»Ýªºtable¡C
¦¨¥\«Ø¥ßtable«á¡A·|Åã¥ÜSQL«ü¥O¤w¦¨¥\°õ¦æ¡A±µ¤U¨Ó·|¶i¦æºÞ²zû±b¸¹ªº«Ø¥ß¤u§@¡C
§Ṳ́]¥i¥H³s¤JmysqlªºSyslog database¡AÀ˵ø³oscript¨s³ºÀ°§Ú̫إߤFþ¨Çtables¡C
±µ¤U¨Ó¦b²Ä6¨BÆJ¡A½Ð¨Ì»Ý¨D«Ø¥ßºÞ²zû±b¸¹¡C
¦b²Ä7¨BÆJ¡ASource Typeªº³¡¤À¡A§ÚÌ¥ýºû«ù¹w³]ªºDiskfile¡A
«Ý¦w¸Ë§¹¦¨«á¦A§ï¬°mysql³sµ²¡A¤ñ¸û¨âºØ¤è¦¡ªº®t²§¡C
¦w¸Ë§¹¦¨«á¡A¦^¨ìloganalyzerªºµn¤J¶±¡A¿é¤Jè¤~«Ø¥ßªººÞ²zû±b¸¹±K½X¡Aµn¤J¯¸¥x¡C
³o®É«o¥X²{¦p¤Uªº¿ù»~¡H
Syslog file is not readable, read access may be denied
¤Wºô¬d¸ß«á¡Aµo²{¬Oapache¤Ö¤F¹ïÀ³admÅv¡AµLªk¥hŪ¨ú/var/log/syslogùتº¤º®e¡I
§âapache¹ïÀ³ªº www-data ªº¨¥÷¥[¤J adm «á¡A½á¤©¨äÅv¡A«±Òapache server¡A³oÓ°ÝÃD´N¥i¥H¸Ñ¨M¤F¡ã
vim /etc/group
adm:x:4:www-data
service apache2 reload
§¹¦¨«á¡A¥i¥H¬Ý¨ìlog¤FC¡I
¦pªG¬O¦]¬°apacheŪ¨ú/var/log/syslogªºÅv°ÝÃD¡A
¨º§ï¥Hmysqlªº¤è¦¡¥hŪ¨úlog¡AÀ³¸Ó´N¤£·|¦³³oÓÅv¤Wªº¿ù»~¤F§a¡H
§ÚÌ¥i¥H¦bAdmin Center¤¤¡A±NSource Type¥Ñ Diskfile §ï¬° mysql °µÓ´ú¸Õ¡C
¦bSource Typeªº³¡¤À§ï¬°MYSQL Native¡A
¦bSelect Viewªº³¡¤Àºû«ùSyslog Fields¡C
µM«á¦bMysql databaseªº³s½u³]©w¡A´N¦p¦P¥ý«e©Ò¿é¤Jªº¸ê°T¡A
Database Name¤@¼Ë¿é¤J Syslog¡A
Database User½Ð¿é¤J rsyslog¡A
Database Password¤@¼Ë¿é¤J«Ø¥ß Syslog DB®É¡A©Ò¿é¤Jªº±K½X¡C
¤ñ¸û¯S§Oªº¬OLog Eventªºrecord¬O©ñ¦b SystemEvents ³oÓtable¤¤¡A§ÚÌn¦b¦¹¼Ð¥Ü²M·¡¡C
Y¿é¤J¸ê°T¥¿½TµL»~¡A¨º»ò´N·|¥X²{ק令¥\ªºµe±¡C
LogAnalyzerªGµM¤]¥i¥H³z¹Lmysql³sµ²¡A¨ú±o¬ÛÃölog¸ê°T¡A¤£·|¦A¥X²{¨ºÓ Syslog file is not readable ªº¿ù»~¤F¡I
¤£¶È¦p¦¹¡Alog¦b¶ë¤Jdatabase®É¡A³£¤w¸g¨Ìlog¯S©Ê¶i¦æ¤ÀªR¡A±N¸ê®Æ¶i¦æ¤Á³Î¶ë¤J¹ïÀ³ªºÄæ¦ì¤¤¡A
¦p¦¹¤@¨Ó¡A¦bLogAnalyzerùØ´N¯àÅã¥Ü¥X§ó¦h¦³¥Îªº¤ÀÃþ¸ê°T¡A³o¬O¥HDiskfile§ìlog©ÒµLªk§e²{ªº®ÄªG¡ã
¦b¨Ï¥Îmysql¨Ó¦¬¶°log«á¡A¬Û¹ïªº /var/log/syslog ùتºlog¸ê°T¤w¸g¤£¬O¨º»ò«n¡C
Y¦¬¶°ªºlog¸ê°T«Ü¦h«Ü¤j¡A¾á¤ßµwºÐ·|Ãz±¼¡A
¨º»ò§ÚÌ¥i¥H½Õ¾ãlogrotateùعïsyslogªº«O¯d¤Ñ¼Æ¡C
syslogªº³]©w¤º®e¬O©w¸q¦b¥H¤U¸ô®|ªº³]©wÀɤ¤¡C
/etc/logrotate.d/rsyslog
¥t¥~¡AY¤@¶}©l¡A¦³¦w¸ËPHPªºGD®M¥óªº¸Ü¡A
¦bLogAnalyzerªº Statistics ¶±¤¤¡A´N¥i¥H¥¿±`ªºÅã¥Ü¬ÛÃö²Îp¹Ïªí¡C
¦Ó¦b³øªíªº³¡¤À¡ALogAnalyzer´£¨Ñ¤F4ºØ³øªí¡C
¤£¹L¥¼¸g¡§Àx¦s³]©w¡¨«e¡A¤£½×þ¤@Ó³øªí¡A³£µLªk¶¶§Q²£¥Í¡I
³øªíªº¡§Àx¦s³]©w¡¨¬yµ{¦p¤U¡A
º¥ý¡A¥ý¨ìReport¤¤ÂI¿ïAdministrate Reports¥\¯à¡C
µM«áÂI¿ï¡§Add Savedreport and save changes¡¨¡A¸õ¨ì³øªí³]©w¶±¡C
½T»{°Ñ¼Æ«á¡A«ö¤U¡§Add Savedreport and save changes¡¨«ö¶s§¹¦¨³øªíªºÀx¦s³]©w¡C
¦^¨ì³øªí¶±¡A³o®É¤wÀx¦sªº³øªí´N·|¥X²{Available Actionsªº¬ÛÃö¥\¯à«ö¶s¡C
ÂI¤Uºñ¦âplay«ö¶s¡A´N¥i¥H²£¥Í¹ïÀ³ªº³øªí¤F¡ã
³Ì«á¡A¦b¦¨¥\¦w¸ËLogAnalyzer«á¡A
½Ð§â /var/www/html/logs ¥Ø¿ý¤Uªº¦w¸ËÀÉ install.php¡Bconfig.php¡Bconfigure.sh ·h¨ì¨ä¥¦¦a¤è©Î§R°£¡A
¥H§K³Q¦³¤ß¤H¤h¡A«·s¾Þ§@³]©w¡A½T«O¦w¥þ¡I
LogAnalyzerªº¬ÛÃö³]©w¨ì¦¹§i¤@¬q¸¨¡ã
°Ñ¦Ò¸ê®Æ
how-to-install-lamp-on-ubuntu
http://fayazsheriff.blogspot.tw/
§K¶OLOG¦øªA¾¹WEBºÞ²z - loganalyzer
LAMP+rsyslog+loganalyzer °µ¨t²Î LOG °O¿ý¤ÀªR
SYSLOG SERVER WITH RSYSLOG AND LOGANALYZER
♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã
If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!
|