For those that might not be handy with the unix util's you can grab a copy of DLAnalyzer "lite" which is free that will do this type of reporting including analyzing multiple days worth of logs at a time.

Darrell
------------------------------------------------------------------------
Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers.



Colbeck, Andrew writes:


On another list there was a request for a simple quick way (and free?)
to find out how many viruses Declude Virus has caught.


This will do the trick, but of course it depends on what you're *really*
after:


gawk "$4 ~ /Scanner/" vir0307.log

Awk will then check column 4 in the file for a regular expression that
matches "Scanner" and output the whole line.


You could count the lines in Awk and output the total, but then that
would probably require a little bit more than you want to learn, so just
tack on an easy utility to do that total for you:


gawk "$4 ~ /Scanner/" vir0307.log | wc -l

Andrew 8)

p.s. On my system, I mostly see NetSky, then MyDoom, then IFrame
exploits.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to