È»¶ø£¬¼´±ãÊÇ×׳µÄϵͳҲ»áÓöµ½ÎÊÌ⣬¶øLinuxÈÕÖ¾ÕýÊÇÎÒÃÇÕï¶Ï¡¢ÅŲéºÍ½â¾öÕâЩÎÊÌâµÄ±¦¹ó×ÊÔ´
±¾ÎÄÖ¼ÔÚÉîÈë̽ÌÖÈçºÎͨ¹ýLinuxÈÕ־ȷÈÏÀ´È·±£ÏµÍ³µÄÎȶ¨ÐԺͰ²È«ÐÔ£¬ÌṩһÌ×ϵͳ»¯µÄ·½·¨ºÍ²ßÂÔ£¬°ïÖúϵͳ¹ÜÀíÔ±ºÍ¿ª·¢ÈËÔ±¸ßЧµØÀûÓÃÈÕÖ¾ÐÅÏ¢
Ò»¡¢LinuxÈÕÖ¾µÄÖØÒªÐÔ LinuxÈÕ־ϵͳÊÇÒ»¸ö·ÖÉ¢µ«¸ß¶È¼¯³ÉµÄÐÅÏ¢¼Ç¼»úÖÆ£¬Ëüº¸ÇÁËϵͳÆô¶¯¡¢½ø³Ì¹ÜÀí¡¢Óû§»î¶¯¡¢Ó²¼þ״̬¡¢ÍøÂçͨÐÅ¡¢°²È«Ê¼þµÈ¶à¸ö·½Ãæ
ÕâЩÈÕÖ¾²»½ö¼Ç¼ÁËϵͳµÄÕý³£ÔËÐÐ״̬£¬¸üÄÜÔÚϵͳ³öÏÖÒ쳣ʱÌṩ¹Ø¼üÏßË÷£¬°ïÖú¶¨Î»ÎÊÌâ¸ùÔ´
ÕýÈ·½â¶ÁºÍ·ÖÎöÈÕÖ¾£¬¶ÔÓÚά»¤ÏµÍ³½¡¿µ¡¢Ô¤·ÀDZÔÚÍþв¡¢¿ìËÙÏìӦͻ·¢Ê¼þ¾ßÓв»¿ÉÌæ´úµÄ×÷ÓÃ
¶þ¡¢LinuxÈÕÖ¾µÄ»ù±¾¼Ü¹¹ LinuxÈÕ־ϵͳÖ÷ÒªÓɼ¸¸öºËÐÄ×é¼þ¹¹³É£º 1.syslogd/rsyslog£º¸ºÔð½ÓÊÕ¡¢´¦ÀíºÍת·¢ÈÕÖ¾ÏûÏ¢
ËüÃÇ¿ÉÒÔ½«ÈÕÖ¾·¢Ë͵½²»Í¬µÄÄ¿µÄµØ£¬ÈçÎļþ¡¢Ô¶³Ì·þÎñÆ÷»ò¿ØÖÆÌ¨
2.journald£ºsystemdµÄÒ»²¿·Ö£¬ÌṩÁ˸üÏȽø¡¢½á¹¹»¯µÄÈÕÖ¾¼Ç¼ÄÜÁ¦
ËüÖ§³ÖʵʱÈÕÖ¾²éѯ¡¢¹ýÂ˺ͳ־û¯´æ´¢£¬¼«´óµØÌá¸ßÁËÈÕÖ¾¹ÜÀíµÄЧÂʺÍÁé»îÐÔ
3.ÈÕÖ¾Îļþ£ºÍ¨³£´æ´¢ÔÚ/var/logĿ¼Ï£¬°üÀ¨ÏµÍ³ÈÕÖ¾(`syslog`»ò`messages`)¡¢ÈÏÖ¤ÈÕÖ¾(`auth.log`)¡¢Ó¦ÓóÌÐòÈÕÖ¾µÈ
Èý¡¢ÈÕ־ȷÈϵĻù±¾²½Öè 1.ÊÕ¼¯ÈÕÖ¾ -±¾µØÊÕ¼¯£ºÖ±½Ó·ÃÎÊ/var/logĿ¼ÏµÄÈÕÖ¾Îļþ
-Ô¶³ÌÊÕ¼¯£ºÀûÓÃrsyslog»ò`syslog-ng`µÈ¹¤¾ßµÄÔ¶³ÌÈÕÖ¾¹¦ÄÜ£¬½«¶à¸ö·þÎñÆ÷µÄÈÕÖ¾¼¯ÖйÜÀí£¬±ãÓÚͳһ·ÖÎö
-ʵʱÊÕ¼¯£ºÍ¨¹ýjournalctlÃüÁî»ò`systemd-journald`µÄAPI£¬ÊµÊ±»ñȡϵͳÈÕÖ¾
2.ÈÕÖ¾·ÖÀàÓëɸѡ -°´ÀàÐÍ·ÖÀà£ºÇø·ÖϵͳÈÕÖ¾¡¢Ó¦ÓóÌÐòÈÕÖ¾¡¢°²È«ÈÕÖ¾µÈ
-°´Ê±¼äɸѡ£ºÕë¶ÔÌØ¶¨Ê±¼ä¶ÎÄÚµÄÈÕÖ¾½øÐзÖÎö£¬ËõСÎÊÌⷶΧ
-°´¹Ø¼ü×ÖËÑË÷£ºÊ¹ÓÃgrep¡¢awk¡¢sedµÈ¹¤¾ß£¬¸ù¾Ý´íÎó´úÂë¡¢½ø³ÌÃû¡¢IPµØÖ·µÈ¹Ø¼ü×Ö½øÐпìËÙ¶¨Î»
3.ÈÕÖ¾½âÎöÓë½â¶Á -Àí½âÈÕÖ¾¸ñʽ£ºÊìϤ²»Í¬ÈÕÖ¾ÎļþµÄ¸ñʽºÍ×ֶκ¬Ò壬Èçʱ¼ä´Á¡¢ÓÅÏȼ¶¡¢ÏûÏ¢ÄÚÈݵÈ
-·ÖÎöÈÕÖ¾ÄÚÈÝ£ºÊ¶±ðÒì³£ÐÐΪ¡¢´íÎóÌáʾ¡¢¾¯¸æÐÅÏ¢µÈ£¬½áºÏϵͳÅäÖúÍÔËÐÐ״̬½øÐÐ×ۺϷÖÎö
-ÀûÓù¤¾ß¸¨Öú£ºÈçlogwatch¡¢`fail2ban`µÈ£¬¿ÉÒÔ×Ô¶¯·ÖÎöÈÕÖ¾²¢Éú³É±¨¸æ£¬Ìá¸ß·ÖÎöЧÂÊ
4.ÎÊÌⶨλÓë½â¾ö -»ùÓÚÈÕÖ¾ÐÅÏ¢£º¸ù¾ÝÈÕÖ¾ÖеĴíÎóÌáʾ£¬¶¨Î»ÎÊÌâ·¢ÉúµÄÄ£¿é»ò×é¼þ
-²éÔÄÎĵµÓëÉçÇø£º²Î¿¼¹Ù·½Îĵµ¡¢FAQ¡¢ÂÛ̳µÈ£¬Ñ°ÕÒÏàËÆÎÊÌâµÄ½â¾ö·½°¸
-Ó¦ÓÃÐÞ¸´´ëÊ©£º¸ù¾Ý·ÖÎö½á¹û£¬µ÷ÕûÅäÖá¢Éý¼¶Èí¼þ¡¢ÐÞ¸´Â©¶´»òÖØÆô·þÎñµÈ
5.ÈÕÖ¾¹éµµÓëÉó¼Æ -¶¨ÆÚ¹éµµ£º½«ÀúÊ·ÈÕÖ¾¹éµµ±£´æ£¬ÒÔ±¸ºóÐøÉ󼯻ò·ÖÎöÐèÒª
-°²È«É󼯣º¶Ô¹Ø¼üÈÕÖ¾½øÐж¨ÆÚÉ󼯣¬¼ì²éÊÇ·ñÓÐδ¾ÊÚȨµÄ·ÃÎÊ»òÒì³£»î¶¯
-ºÏ¹æÐÔ¼ì²é£ºÈ·±£ÈÕÖ¾¹ÜÀí·ûºÏÐÐÒµ°²È«±ê×¼ºÍ·¨¹æÒªÇó
ËÄ¡¢¸ß¼¶ÈÕÖ¾¹ÜÀí²ßÂÔ 1.¼¯Öл¯ÈÕÖ¾¹ÜÀí ÀûÓÃElasticsearch¡¢Logstash¡¢Kibana£¨ELK Stack£©»òGraylogµÈ¿ªÔ´½â¾ö·½°¸£¬ÊµÏÖÈÕÖ¾µÄ¼¯ÖÐÊÕ¼¯¡¢´æ´¢¡¢·ÖÎöºÍ¿ÉÊÓ»¯Õ¹Ê¾
ÕâÓÐÖúÓÚ¿ç¶à¸öϵͳºÍÓ¦ÓóÌÐò½øÐйØÁª·ÖÎö£¬ÌáÉýÎÊÌâ½â¾öµÄЧÂÊ
2.ÖÇÄܸ澯Óë×Ô¶¯»¯ÏìÓ¦ ÅäÖÃÈÕÖ¾¼à¿Ø¹æÔò£¬µ±¼ì²âµ½Ìض¨Ä£Ê½»òãÐÖµ´¥·¢Ê±£¬×Ô¶¯·¢Ë͸澯֪ͨ£¨ÈçÓʼþ¡¢¶ÌÐÅ¡¢SlackµÈ£©£¬²¢¿É´¥·¢Ô¤ÉèµÄ×Ô¶¯»¯½Å±¾»ò¹¤×÷Á÷£¬ÈçÖØÆô·þÎñ¡¢¸ôÀëÊܸÐȾÖ÷»úµÈ
3.ÈÕÖ¾¼ÓÃÜÓëÒþ˽±£»¤ ¶ÔÓÚÃô¸ÐÈÕÖ¾ÐÅÏ¢£¬ÓÈÆäÊÇÉæ¼°Óû§Êý¾Ý¡¢ÃÜÂëµÈ£¬Ó¦ÊµÊ©¼ÓÃÜ´æ´¢ºÍ´«Ê䣬ȷ±£ÈÕÖ¾Êý¾ÝÔÚÊÕ¼¯¡¢´æ´¢ºÍ·ÖÎö¹ý³ÌÖеݲȫÐÔ
4.ÈÕÖ¾ÉúÃüÖÜÆÚ¹ÜÀí ÖÆ¶¨ºÏÀíµÄÈÕÖ¾±£Áô²ßÂÔ£¬Æ½ºâÈÕÖ¾´æ´¢³É±¾ÓëÉó¼ÆÐèÇó
¹ýÆÚÈÕÖ¾Ó¦°²È«É¾³ý»ò¹éµµ£¬±ÜÃâÊý¾Ýй¶·çÏÕ
Î塢ʵ¼ù°¸Àý·ÖÏí °¸ÀýÒ»£ºÏµÍ³ÐÔÄÜϽµÅŲé ijLinux·þÎñÆ÷½üÆÚ³öÏÖÏìÓ¦»ºÂýÏÖÏó£¬Í¨¹ý²é¿´`/var/log/syslog`ºÍ`dmesg`ÈÕÖ¾£¬·¢ÏÖÆµ·±³öÏÖ´ÅÅÌI/O´íÎó
½øÒ»²½¼ì²é´ÅÅ̽¡¿µ×´¿ö£¬È·ÈÏÓ²Å̼´½«Ëð»µ
ͨ¹ý¸ü»»Ó²Å̲¢Öؽ¨RAIDÕóÁУ¬ÎÊÌâµÃÒÔ½â¾ö
°¸Àý¶þ£º°²È«ÈëÇÖ¼ì²â ijWeb·þÎñÆ÷ÔâÊÜSSH±©Á¦ÆÆ½â¹¥»÷£¬`auth.log`ÖмǼÁË´óÁ¿Ê§°ÜµÄµÇ¼³¢ÊÔ
ͨ¹ýÅäÖÃ`fail2ban`£¬×Ô¶¯·â½ûÁ˶à´Î³¢ÊԵǼʧ°ÜµÄIPµØÖ·£¬ÓÐЧ·ÀÓùÁ˹¥»÷
Áù¡¢½áÓï LinuxÈÕ־ȷÈÏÊÇϵͳÔËάºÍ°²È«¹ÜÀíµÄºËÐļ¼ÄÜÖ®Ò»
ͨ¹ýϵͳ»¯¡¢ÖÇÄÜ»¯µÄÈÕÖ¾¹ÜÀí£¬²»½ö¿ÉÒÔÌáÉýϵͳµÄÎȶ¨ÐԺͰ²È«ÐÔ£¬»¹ÄÜÓÅ»¯ÔËάЧÂÊ£¬½µµÍ¹ÊÕϻָ´Ê±¼ä
Ëæ×ż¼ÊõµÄ²»¶Ï½ø²½£¬ÐµÄÈÕÖ¾¹ÜÀíºÍ·ÖÎö¹¤¾ß²»¶ÏÓ¿ÏÖ£¬ÎªÈÕ־ȷÈϹ¤×÷ÌṩÁ˸ü¶à¿ÉÄÜÐÔ
Òò´Ë£¬³ÖÐøÑ§Ï°¡¢Ì½Ë÷ºÍʵ¼ù£¬ÊÇÿһλϵͳ¹ÜÀíÔ±ºÍ¿ª·¢ÈËÔ±µÄ±ØÐÞ¿Î
ÈÃÎÒÃdzä·ÖÀûÓÃLinuxÈÕÖ¾ÕâÒ»±¦¹ó×ÊÔ´£¬Îª¹¹½¨¸ü¼Ó°²È«¡¢¸ßЧµÄ¼ÆËã»·¾³¹±Ï×Á¦Á¿