Integrate locations
This commit is contained in:
1 parent
aa9b16088e
commit
89138887cc
4 files changed
+69
-66
No files matched your search
@@ -1,17 +1,33 @@
|
||||
#!/usr/bin/env python3
|
||||
import sqlite3, datetime
|
||||
import sqlite3
|
||||
from datetime import datetime
|
||||
|
||||
DB = "sshd_failures.db"
|
||||
db = sqlite3.connect("sshd_failures.db")
|
||||
|
||||
db = sqlite3.connect(DB)
|
||||
|
||||
for ip, count, last_ts in db.execute("""
|
||||
SELECT ip, COUNT(*), MAX(ts)
|
||||
FROM failures
|
||||
GROUP BY ip
|
||||
ORDER BY COUNT(*) DESC
|
||||
for row in db.execute("""
|
||||
SELECT
|
||||
g.country,
|
||||
COUNT(*) AS total,
|
||||
MAX(f.ts) AS last_seen,
|
||||
(
|
||||
SELECT f2.ip
|
||||
FROM failures f2
|
||||
JOIN ip_geo g2 ON f2.ip = g2.ip
|
||||
WHERE g2.country = g.country
|
||||
GROUP BY f2.ip
|
||||
ORDER BY COUNT(*) DESC
|
||||
LIMIT 1
|
||||
) AS top_ip
|
||||
FROM failures f
|
||||
JOIN ip_geo g ON f.ip = g.ip
|
||||
GROUP BY g.country
|
||||
ORDER BY total DESC
|
||||
"""):
|
||||
last = datetime.datetime.fromtimestamp(last_ts)
|
||||
print(f"{ip:40} {count:5} last={last}")
|
||||
country, total, last_seen, top_ip = row
|
||||
|
||||
if last_seen:
|
||||
last_seen = datetime.fromtimestamp(last_seen)
|
||||
|
||||
print(f"{country:25} {total:6} top_ip={top_ip:18} last={last_seen}")
|
||||
|
||||
db.close()
|
||||
Reference in new issue
Block a user