F
F
Fetur2017-09-16 22:59:20
linux
Fetur, 2017-09-16 22:59:20

How to collect server request statistics?

Hello everyone, I have my own server, but I don’t know who is breaking into me. The last time a Turk was trying to find a pma.

95.85.107.128 - - [16/Sep/2017:21:24:14 +0300] "GET /phpMyAdmin-2.6.0-beta2/ HTTP/1.1" 404 461 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:17 +0300] "GET /phpMyAdmin-2.6.0-rc1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:19 +0300] "GET /phpMyAdmin-2.6.0-rc2/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:22 +0300] "GET /phpMyAdmin-2.6.0-rc3/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:33 +0300] "GET /phpMyAdmin-2.6.0/ HTTP/1.1" 404 455 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:45 +0300] "GET /phpMyAdmin-2.6.0-pl1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:48 +0300] "GET /phpMyAdmin-2.6.0-pl2/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:54 +0300] "GET /phpMyAdmin-2.6.0-pl3/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:24:59 +0300] "GET /phpMyAdmin-2.6.1-rc1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:01 +0300] "GET /phpMyAdmin-2.6.1-rc2/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:07 +0300] "GET /phpMyAdmin-2.6.1/ HTTP/1.1" 404 455 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:18 +0300] "GET /phpMyAdmin-2.6.1-pl1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:24 +0300] "GET /phpMyAdmin-2.6.1-pl2/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:29 +0300] "GET /phpMyAdmin-2.6.1-pl3/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:31 +0300] "GET /phpMyAdmin-2.6.2-rc1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
94.23.1.215 - - [16/Sep/2017:21:25:37 +0300] "GET /CFIDE/administrator/ HTTP/1.1" 404 514 "-" "-"
95.85.107.128 - - [16/Sep/2017:21:25:38 +0300] "GET /phpMyAdmin-2.6.2-beta1/ HTTP/1.1" 404 461 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:43 +0300] "GET /phpMyAdmin-2.6.2-rc1/ HTTP/1.1" 404 459 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
95.85.107.128 - - [16/Sep/2017:21:25:45 +0300] "GET /phpMyAdmin-2.6.2/ HTTP/1.1" 404 455 "http://88.99.177.120/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"

And then, I came in out of pure coincidence out of curiosity.
I would like to find a program with a convenient view of who, where and what time they went. At the same time, I would like to have statistics not just from Apache requests, but attempts to connect via ssh, ftp, webdav, the last five logged in.
Is it possible to organize it somehow?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
Dimonchik, 2017-09-16
@Fetur

https://www.fail2ban.org/wiki/index.php/Main_Page
if you want your own, then you can play with clickhouse or with ELK

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question