我正在尝试将IP地址从文件写入另一个文件,如果它们使用以下代码发生超过30次:
#!/usr/bin/python
#open the auth.log file
myFile = open('auth.log','r')
myTxtFile = open('blacklist2.txt','w') #open the Security_Test.txt for writing later
myTxtFile.write('The IP Addresses with more than 30 Attacks are:\n') #prints out a line of text ready for the outcome
ip_attacks = {}
count_attacks = 0
#go through each line of the file and return it to the variable line
for line in myFile.readlines():
#get the IP address
#we are working backwards to avoid the difference of the length of the NT logs
attack_ip = list_of_line[-4]
attack_ip_list= attack_ip.split('port')
attack_address = attack_ip_list[0]
if 'Failed password for' in line:
#print '\'',attack_address,'\''
if ip_attacks.has_key(attack_address):
count_attacks = ip_attacks[attack_address]
count_attacks = count_attacks +1
ip_attacks[attack_address] = count_attacks
#zero out the temporary counter as a precaution
count_attacks =0
else:
ip_attacks[attack_address] = 1
if count_attacks > 30:
myTxtFile.write(ip_attacks)
但它不会写入文本文件,唯一写入文本文件的是第一行'超过30次攻击的IP地址是:'我在这里做错了什么不是允许我将ip_address从文件写入另一个文件??
来自日志文件的示例行:
Feb 5 08:25:47 j4-be02 sshd[2130]: Failed password for root from 5.199.133.223 port 50259 ssh2
Feb 5 08:25:55 j4-be02 sshd[2133]: Failed password for root from 5.199.133.223 port 57329 ssh2
答案 0 :(得分:1)
您的代码错误,因为您将count_attacks
重置为零。我相信你希望你的if语句是:
if ip_attacks[attack_address] > 30:
myTxtFile.write(ip_attacks)
而不是:
if count_attacks > 30:
myTxtFile.write(ip_attacks)
修改强> 顺便说一句。我相信这3行:
count_attacks = ip_attacks[attack_address]
count_attacks = count_attacks +1
ip_attacks[attack_address] = count_attacks
可以替换为:
ip_attacks[attack_address] += 1
编辑:问题的完整解决方案:
#!/usr/bin/python
from collections import defaultdict
#open the auth.log file
myFile = open('auth.log','r')
myTxtFile = open('blacklist2.txt','w') #open the Security_Test.txt for writing later
myTxtFile.write('The IP Addresses with more than 30 Attacks are:\n') #prints out a line of text ready for the outcome
ip_attacks = defaultdict(int)
count_attacks = 0
#go through each line of the file and return it to the variable line
for line in myFile.readlines():
#get the IP address
#we are working backwards to avoid the difference of the length of the NT logs
attack_ip = list_of_line[-4]
attack_ip_list= attack_ip.split('port')
attack_address = attack_ip_list[0]
if 'Failed password for' in line:
#print '\'',attack_address,'\''
ip_attacks[attack_address] += 1
for key, value in ip_attacks.iteritems():
if value > 30:
myTxtFile.write(key)