Using a queried value to query... I think.

 
Thread Tools Search this Thread
Special Forums UNIX and Linux Applications Using a queried value to query... I think.
# 1  
Old 12-16-2009
MySQL Using a queried value to query... I think.

Hi,

One of our FTP servers is constantly under attack. I'm putting the output from the servers log file into a database. What I'm doing now is querying for anything hitting the server on port 21 in the last minute. Any single IP that has too high of a count within that minute is blocked. What I'd like to do is... In addition to gathered IP addresses hitting on port 21. Make sure that there are no hits from those IP addreses to the passive ports on our server. This would help eliminate false positives as much as I can.

The question is can I do this in a single statement?

The current statement is this:
Code:
"SELECT log_src_ip FROM traffic_log WHERE \
         (log_dst_ip = 'our.ftp.server.address' AND \
         log_dst_pt='21' AND \
         log_time > DATE_SUB(NOW(),INTERVAL $block_time second) \
         ORDER BY log_time ASC;"

Thanks,

MPH
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Shell Script to execute Oracle query taking input from a file to form query

Hi, I need to query Oracle database for 100 users. I have these 100 users in a file. I need a shell script which would read this User file (one user at a time) & query database. For instance: USER CITY --------- ---------- A CITY_A B CITY_B C ... (2 Replies)
Discussion started by: DevendraG
2 Replies

2. UNIX for Dummies Questions & Answers

Query

Hi, I have a script to remove null values from a file. Could any one explain how this is working? :confused: while read f do echo process $f gawk... (0 Replies)
Discussion started by: abhi_n123
0 Replies

3. Shell Programming and Scripting

want to query : YES or NO

hi i want to make script. where i want to query from the user yes or no exp: do you want to proceed : y for yes n for NO. how this is possible in unix (3 Replies)
Discussion started by: dodasajan
3 Replies

4. Shell Programming and Scripting

Query Oracle tables and return values to shell script that calls the query

Hi, I have a requirement as below which needs to be done viz UNIX shell script (1) I have to connect to an Oracle database (2) Exexute "SELECT field_status from table 1" query on one of the tables. (3) Based on the result that I get from point (2), I have to update another table in the... (6 Replies)
Discussion started by: balaeswari
6 Replies

5. Shell Programming and Scripting

add the output of a query to a variable to be used in another query

I would like to use the result of a query in another query. How do I redirect/add the output to another variable? $result = odbc_exec($connect, $query); while ($row = odbc_fetch_array($result)) { echo $row,"\n"; } odbc_close($connect); ?> This will output hostnames: host1... (0 Replies)
Discussion started by: hazno
0 Replies

6. UNIX for Dummies Questions & Answers

Need Help on query

I just started to learn unix - need help to write a script to query a logfile and produce the results that contains a specific word "alarm" for a period from X day to Y day. I really have no idea how to begin - :( please help... ____________________________________________________ #... (1 Reply)
Discussion started by: snipfer
1 Replies

7. Shell Programming and Scripting

query.....

hi friends i want to know details of `exec` exact use of this command ..... actually i went through the man page but i didn`t get the satisfactory ...conclusion.... thaks in advance.... (1 Reply)
Discussion started by: newson
1 Replies

8. Shell Programming and Scripting

query

I have converted data written on excel sheet in unix through shell & perl prg now the problem is I want that if starting columns of the xls sheet is Blank than when data is converted into unix then it should appear with this '|' sign. but it appearing like this: hfgg|tytt| but I want like... (2 Replies)
Discussion started by: akash
2 Replies

9. UNIX for Dummies Questions & Answers

query

hi, how can i do the following..... i have file containing followig a k 10000 b c 200000 d e 50 a j 40 how can i list all rows containg last value more than 1000? and how can i find number of blank rows in the file? THANKS! regards vivek (2 Replies)
Discussion started by: vivekshankar
2 Replies
Login or Register to Ask a Question
jwhois(1)						      General Commands Manual							 jwhois(1)

NAME
jwhois - client for the whois service SYNOPSIS
jwhois [ OPTIONS ]... [ QUERY ] DESCRIPTION
jwhois searches Whois servers for the object on the command line. The host to query is taken from a global configuration file, a configuration file specified on the command line, or selected directly on the command line. OPTIONS
--version display version, authors and licensing information. --help display a short help text. -c FILE --config=FILE uses FILE as a configuration file instead of the default. -h HOST --host=HOST overrides any hosts in the configuration file and queries HOST directly. -p PORT --port=PORT specifies a port number to use when querying a HOST. -f --force-lookup forces a query to be made to a host even if a current object is available from the cache. -v --verbose outputs verbose debugging information while running (use this before sending a bugreport to ensure that it's indeed a bug and not a misconfiguration). You can increase the verbosity by giving several verbose commands to jwhois, such as -vv. -n --no-redirect disable features that redirect queries from one server to another. -s --no-whoisservers disable the built-in support for whois-servers.net. -a --raw send query verbatim to receiving hosts instead of rewriting them according to the configuration. -i --display-redirections display every step in a redirection (default is to display only the last answer). -d --disable-cache completely disable both reading and writing to cache. -r --rwhois force the query to use the rwhois protocoll instead of HTTP or whois. --rwhois-display=DISPLAY asks receiving rwhois servers to display the results in the DISPLAY display instead of the default dump display. --rwhois-limit=LIMIT asks receiving rwhois servers to limit their responses to LIMIT matches. RIPE EXTENSIONS To use the options specified in RIPE Document 157, you need to change the format of the query slightly. If you were to search for all entries in the RIPE database which lists the admin-c, tech-c or zone-c as CO19-RIPE, you could use the following command syntax: jwhois -h whois.ripe.net -- -i admin-c,tech-c,zone-c CO19-RIPE -- is used to separate the RIPE options from the jwhois options. SEE ALSO
whois(1) GNU
November 2001 jwhois(1)