2013-07-05 19:27:43 +08:00
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Description
|
|
|
|
# -----------
|
|
|
|
#
|
|
|
|
# This is one for the system administrator, operation and maintenance.
|
|
|
|
#
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Authors
|
|
|
|
# -------
|
|
|
|
#
|
|
|
|
# * Dongweiming <ciici123@gmail.com>
|
|
|
|
#
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
|
|
|
function retlog() {
|
|
|
|
if [[ -z $1 ]];then
|
|
|
|
echo '/var/log/nginx/access.log'
|
|
|
|
else
|
|
|
|
echo $1
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
alias ping='ping -c 5'
|
2021-03-25 19:08:00 +08:00
|
|
|
alias clr='clear; echo Currently logged in on $TTY, as $USERNAME in directory $PWD.'
|
2018-10-18 01:40:20 +08:00
|
|
|
alias path='print -l $path'
|
2013-07-05 19:27:43 +08:00
|
|
|
alias mkdir='mkdir -pv'
|
|
|
|
# get top process eating memory
|
2020-10-11 20:17:21 +08:00
|
|
|
alias psmem='ps -e -orss=,args= | sort -b -k1 -nr'
|
2021-11-09 16:04:10 +08:00
|
|
|
alias psmem10='ps -e -orss=,args= | sort -b -k1 -nr | head -n 10'
|
2021-12-01 19:20:31 +08:00
|
|
|
# get top process eating cpu if not work try execute : export LC_ALL='C'
|
2020-02-11 04:18:14 +08:00
|
|
|
alias pscpu='ps -e -o pcpu,cpu,nice,state,cputime,args|sort -k1,1n -nr'
|
2021-11-09 16:04:10 +08:00
|
|
|
alias pscpu10='ps -e -o pcpu,cpu,nice,state,cputime,args|sort -k1,1n -nr | head -n 10'
|
2013-07-05 19:27:43 +08:00
|
|
|
# top10 of the history
|
|
|
|
alias hist10='print -l ${(o)history%% *} | uniq -c | sort -nr | head -n 10'
|
|
|
|
|
2022-11-16 02:29:48 +08:00
|
|
|
function ip() {
|
|
|
|
if [ -t 1 ]; then
|
|
|
|
command ip -color "$@"
|
|
|
|
else
|
|
|
|
command ip "$@"
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
2013-07-05 19:27:43 +08:00
|
|
|
# directory LS
|
2022-04-13 19:14:38 +08:00
|
|
|
function dls() {
|
2018-10-18 01:40:20 +08:00
|
|
|
print -l *(/)
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
2022-04-13 19:14:38 +08:00
|
|
|
function psgrep() {
|
2018-10-18 01:40:20 +08:00
|
|
|
ps aux | grep "${1:-.}" | grep -v grep
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
# Kills any process that matches a regexp passed to it
|
2022-04-13 19:14:38 +08:00
|
|
|
function killit() {
|
2013-07-05 19:27:43 +08:00
|
|
|
ps aux | grep -v "grep" | grep "$@" | awk '{print $2}' | xargs sudo kill
|
|
|
|
}
|
|
|
|
|
|
|
|
# list contents of directories in a tree-like format
|
2018-10-18 01:40:20 +08:00
|
|
|
if ! (( $+commands[tree] )); then
|
2022-04-13 19:14:38 +08:00
|
|
|
function tree() {
|
2018-10-18 01:40:20 +08:00
|
|
|
find $@ -print | sed -e 's;[^/]*/;|____;g;s;____|; |;g'
|
|
|
|
}
|
2013-07-05 19:27:43 +08:00
|
|
|
fi
|
|
|
|
|
|
|
|
# Sort connection state
|
2022-04-13 19:14:38 +08:00
|
|
|
function sortcons() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -nat |awk '{print $6}'|sort|uniq -c|sort -rn
|
|
|
|
}
|
|
|
|
|
|
|
|
# View all 80 Port Connections
|
2022-04-13 19:14:38 +08:00
|
|
|
function con80() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -nat|grep -i ":80"|wc -l
|
|
|
|
}
|
|
|
|
|
|
|
|
# On the connected IP sorted by the number of connections
|
2022-04-13 19:14:38 +08:00
|
|
|
function sortconip() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
|
|
|
|
}
|
|
|
|
|
|
|
|
# top20 of Find the number of requests on 80 port
|
2022-04-13 19:14:38 +08:00
|
|
|
function req20() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -anlp|grep 80|grep tcp|awk '{print $5}'|awk -F: '{print $1}'|sort|uniq -c|sort -nr|head -n20
|
|
|
|
}
|
|
|
|
|
|
|
|
# top20 of Using tcpdump port 80 access to view
|
2022-04-13 19:14:38 +08:00
|
|
|
function http20() {
|
2021-11-09 16:04:10 +08:00
|
|
|
sudo tcpdump -i eth0 -tnn dst port 80 -c 1000 | awk -F"." '{print $1"."$2"."$3"."$4}' | sort | uniq -c | sort -nr |head -n 20
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# top20 of Find time_wait connection
|
2022-04-13 19:14:38 +08:00
|
|
|
function timewait20() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -n|grep TIME_WAIT|awk '{print $5}'|sort|uniq -c|sort -rn|head -n20
|
|
|
|
}
|
|
|
|
|
|
|
|
# top20 of Find SYN connection
|
2022-04-13 19:14:38 +08:00
|
|
|
function syn20() {
|
2013-07-05 19:27:43 +08:00
|
|
|
netstat -an | grep SYN | awk '{print $5}' | awk -F: '{print $1}' | sort | uniq -c | sort -nr|head -n20
|
|
|
|
}
|
|
|
|
|
|
|
|
# Printing process according to the port number
|
2022-04-13 19:14:38 +08:00
|
|
|
function port_pro() {
|
2018-10-18 01:40:20 +08:00
|
|
|
netstat -ntlp | grep "${1:-.}" | awk '{print $7}' | cut -d/ -f1
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# top10 of gain access to the ip address
|
2022-04-13 19:14:38 +08:00
|
|
|
function accessip10() {
|
2013-07-05 19:27:43 +08:00
|
|
|
awk '{counts[$(11)]+=1}; END {for(url in counts) print counts[url], url}' "$(retlog)"
|
|
|
|
}
|
|
|
|
|
|
|
|
# top20 of Most Visited file or page
|
2022-04-13 19:14:38 +08:00
|
|
|
function visitpage20() {
|
2021-11-09 16:04:10 +08:00
|
|
|
awk '{print $11}' "$(retlog)"|sort|uniq -c|sort -nr|head -n 20
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# top100 of Page lists the most time-consuming (more than 60 seconds) as well as the corresponding page number of occurrences
|
2022-04-13 19:14:38 +08:00
|
|
|
function consume100() {
|
2021-11-09 16:04:10 +08:00
|
|
|
awk '($NF > 60 && $7~/\.php/){print $7}' "$(retlog)" |sort -n|uniq -c|sort -nr|head -n 100
|
2021-12-01 19:20:31 +08:00
|
|
|
# if django website or other website make by no suffix language
|
2021-11-09 16:04:10 +08:00
|
|
|
# awk '{print $7}' "$(retlog)" |sort -n|uniq -c|sort -nr|head -n 100
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# Website traffic statistics (G)
|
2022-04-13 19:14:38 +08:00
|
|
|
function webtraffic() {
|
2013-07-05 19:27:43 +08:00
|
|
|
awk "{sum+=$10} END {print sum/1024/1024/1024}" "$(retlog)"
|
|
|
|
}
|
|
|
|
|
|
|
|
# Statistical connections 404
|
2022-04-13 19:14:38 +08:00
|
|
|
function c404() {
|
2013-07-05 19:27:43 +08:00
|
|
|
awk '($9 ~/404/)' "$(retlog)" | awk '{print $9,$7}' | sort
|
|
|
|
}
|
|
|
|
|
|
|
|
# Statistical http status.
|
2022-04-13 19:14:38 +08:00
|
|
|
function httpstatus() {
|
2013-07-05 19:27:43 +08:00
|
|
|
awk '{counts[$(9)]+=1}; END {for(code in counts) print code, counts[code]}' "$(retlog)"
|
|
|
|
}
|
|
|
|
|
|
|
|
# Delete 0 byte file
|
2022-04-13 19:14:38 +08:00
|
|
|
function d0() {
|
2018-10-18 01:40:20 +08:00
|
|
|
find "${1:-.}" -type f -size 0 -exec rm -rf {} \;
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# gather external ip address
|
2022-04-13 19:14:38 +08:00
|
|
|
function geteip() {
|
2021-04-23 22:23:26 +08:00
|
|
|
curl -s -S -4 https://icanhazip.com
|
|
|
|
curl -s -S -6 https://icanhazip.com
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
2018-10-25 19:26:22 +08:00
|
|
|
# determine local IP address(es)
|
2022-04-13 19:14:38 +08:00
|
|
|
function getip() {
|
2015-08-27 17:34:53 +08:00
|
|
|
if (( ${+commands[ip]} )); then
|
2018-10-25 19:26:22 +08:00
|
|
|
ip addr | awk '/inet /{print $2}' | command grep -v 127.0.0.1
|
2015-08-26 16:48:01 +08:00
|
|
|
else
|
2018-10-25 19:26:22 +08:00
|
|
|
ifconfig | awk '/inet /{print $2}' | command grep -v 127.0.0.1
|
2015-08-26 16:48:01 +08:00
|
|
|
fi
|
2013-07-05 19:27:43 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
# Clear zombie processes
|
2022-04-13 19:14:38 +08:00
|
|
|
function clrz() {
|
2013-07-05 19:27:43 +08:00
|
|
|
ps -eal | awk '{ if ($2 == "Z") {print $4}}' | kill -9
|
|
|
|
}
|
|
|
|
|
|
|
|
# Second concurrent
|
2022-04-13 19:14:38 +08:00
|
|
|
function conssec() {
|
2013-07-05 19:27:43 +08:00
|
|
|
awk '{if($9~/200|30|404/)COUNT[$4]++}END{for( a in COUNT) print a,COUNT[a]}' "$(retlog)"|sort -k 2 -nr|head -n10
|
|
|
|
}
|