Answer the question
In order to leave comments, you need to log in
Are there convenient squid log readers?
Good day to all. I ask for advice, maybe someone has already solved a similar problem?
There is a task: it is necessary to have information, what sites and pages on the network are visited by users? The key is the fact that you need to look not only for sites, but also for pages on these sites.
Example.
https://qna.habr.com/
https://www.google.com/
https://www.opennet.ru/
This is what the manager does not like. But... A
utility for tracking user activity in windows
https://www.google.com/search?q=nDPI&oq=nDPI&aqs=e...
https://www.opennet.ru/prog/info/3752 .shtml is
fine.
What has been done for this: CentOS7, squid, sarg are raised. Added "strip_query_terms off" parameter to squid.conf.
As a result, not all sites have a full url. As an example.
1627440748.901 86682 192.168.0.168 TCP_TUNNEL/200 6102 CONNECT azwcus1-client-s.gateway.messenger.live.com:443 - HIER_DIRECT/52.159.49.199 -
1627440748.955 0 192.168.0.194 TCP_MEM_HIT/200 4833 GET http://tile-service.weather.microsoft.com/ru-RU/livetile/preinstall? - HIER_NONE/- text/xml
1627440749.198 10025 192.168.0.200 TCP_TUNNEL/200 5775 CONNECT cdn01.nativeroll.tv:443 - HIER_DIRECT/92.223.99.99 -
1627440749.421 2843 192.168.0.200 TCP_TUNNEL/200 4711 CONNECT moe.video:443 - HIER_DIRECT/92.223.103.64 -
1627440749.515 3892 192.168.0.200 TCP_TUNNEL/200 4711 CONNECT moe.video:443 - HIER_DIRECT/92.223.103.64 -
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question