blob: 43f90f8a24a25cfe660c471d04122633384df392 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
|
#!/usr/local/bin/php-cgi -q
<?php
/*
* filterparser.php
*
* part of pfSense (https://www.pfsense.org)
* Copyright (c) 2009-2016 Electric Sheep Fencing, LLC
* All rights reserved.
*
* Originally based on m0n0wall (http://m0n0.ch/wall)
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
/*
* A quick CLI log parser.
* Examples:
* clog /var/log/filter.log | tail -50 | /usr/local/www/filterparser.php
* clog -f /var/log/filter.log | /usr/local/www/filterparser.php
*/
include_once("functions.inc");
include_once("filter_log.inc");
$log = fopen("php://stdin", "r");
$lastline = "";
while (!feof($log)) {
$line = fgets($log);
$line = rtrim($line);
$flent = parse_firewall_log_line(trim($line));
if ($flent != "") {
$flags = (($flent['proto'] == "TCP") && !empty($flent['tcpflags'])) ? ":" . $flent['tcpflags'] : "";
echo "{$flent['time']} {$flent['act']} {$flent['realint']} {$flent['proto']}{$flags} {$flent['src']} {$flent['dst']}\n";
$flent = "";
}
}
fclose($log); ?>
|