mirror of
https://github.com/OISF/suricata.git
synced 2026-05-28 04:32:12 -04:00
parent
64b7965ca1
commit
cf790def8e
2 changed files with 6 additions and 4 deletions
|
|
@ -248,8 +248,8 @@ SID201=$(jq -c 'select(.alert.signature_id==201)' ./eve.json | wc -l)
|
|||
SID202=$(jq -c 'select(.alert.signature_id==202)' ./eve.json | wc -l)
|
||||
echo "SID201 $SID201 SID202 $SID202"
|
||||
|
||||
ACCEPTED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.ips.accepted')
|
||||
BLOCKED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.ips.blocked')
|
||||
ACCEPTED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.firewall.accepted')
|
||||
BLOCKED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.firewall.blocked')
|
||||
KERNEL_PACKETS=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.capture.kernel_packets')
|
||||
echo "ACCEPTED $ACCEPTED BLOCKED $BLOCKED KERNEL_PACKETS $KERNEL_PACKETS"
|
||||
|
||||
|
|
@ -303,6 +303,7 @@ fi
|
|||
echo "* dumping some stats..."
|
||||
cat ./eve.json | jq -c 'select(.http)'|tail -n1|jq
|
||||
cat ./eve.json | jq -c 'select(.stats)|.stats.ips'|tail -n1|jq
|
||||
cat ./eve.json | jq -c 'select(.stats)|.stats.firewall'|tail -n1|jq
|
||||
cat ./eve.json | jq -c 'select(.stats)|.stats.capture'|tail -n1|jq
|
||||
echo "* dumping some stats... done"
|
||||
|
||||
|
|
|
|||
|
|
@ -268,8 +268,8 @@ SID201=$(jq -c 'select(.alert.signature_id==201)' ./eve.json | wc -l)
|
|||
SID202=$(jq -c 'select(.alert.signature_id==202)' ./eve.json | wc -l)
|
||||
echo "SID201 $SID201 SID202 $SID202"
|
||||
|
||||
ACCEPTED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.ips.accepted')
|
||||
BLOCKED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.ips.blocked')
|
||||
ACCEPTED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.firewall.accepted')
|
||||
BLOCKED=$(jq -c 'select(.event_type == "stats")' ./eve.json | tail -n1 | jq '.stats.firewall.blocked')
|
||||
echo "ACCEPTED $ACCEPTED BLOCKED $BLOCKED"
|
||||
|
||||
if [ $ACCEPTED -eq 0 ]; then
|
||||
|
|
@ -317,6 +317,7 @@ fi
|
|||
|
||||
echo "* dumping some stats..."
|
||||
cat ./eve.json | jq -c 'select(.http)'|tail -n1|jq
|
||||
cat ./eve.json | jq -c 'select(.stats)|.stats.firewall'|tail -n1|jq
|
||||
cat ./eve.json | jq -c 'select(.stats)|.stats.ips'|tail -n1|jq
|
||||
echo "* dumping some stats... done"
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue