IIS 日志分析
查看哪個(gè)IP訪問量大,訪問了什么地址,大可以看到攻擊者IP:
select c-ip,count(c-ip) AS allcount,cs-uri-stem,cs-uri-query,cs(User-Agent) from#IISW3C# WHERE to_string(date,'yyyy-MM-dd') = '2011-11-15' groupby c-ip,cs-uri-stem,cs-uri-query,cs(User-Agent) order by allcount desc
分析IIS某端口日志:
SELECT * FROM #IISW3C# WHERE s-port = 80 AND to_string(date,'yyyy-MM-dd') > '2014-06-01'
參考:
http://cancait.blog.163.com/blog/static/213357442011101613934464/
浙公網(wǎng)安備 33010602011771號(hào)