mirror of
https://github.com/vimagick/dockerfiles.git
synced 2025-04-15 11:47:09 +02:00
update
This commit is contained in:
parent
3ee3b32c6e
commit
9781eaacff
@ -12,9 +12,11 @@ bro:
|
|||||||
command: bro -i eth0
|
command: bro -i eth0
|
||||||
volumes:
|
volumes:
|
||||||
- ./logs:/opt/bro/logs
|
- ./logs:/opt/bro/logs
|
||||||
net: host
|
net: container:shadowsocks_shadowsocks_1
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> We are going to monitor `shadowsocks` which is a socks5 server.
|
||||||
|
|
||||||
## up and running
|
## up and running
|
||||||
|
|
||||||
```
|
```
|
||||||
@ -23,6 +25,13 @@ $ cd ~/fig/bro/
|
|||||||
$ docker-compose up -d
|
$ docker-compose up -d
|
||||||
|
|
||||||
$ docker exec -it bro_bro_1 bash
|
$ docker exec -it bro_bro_1 bash
|
||||||
>>> tail -n +1 -f http.log | bro-cut -d ts user_agent
|
>>> cat dns.log | bro-cut query | sort | uniq -c | sort -nr | head -5
|
||||||
|
10 www.youtube.com
|
||||||
|
3 twitter.com
|
||||||
|
2 www.google.com
|
||||||
|
1 www.baidu.com
|
||||||
|
1 www.facebook.com
|
||||||
>>> exit
|
>>> exit
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> Don't be evil!
|
||||||
|
@ -3,4 +3,4 @@ bro:
|
|||||||
command: bro -i eth0
|
command: bro -i eth0
|
||||||
volumes:
|
volumes:
|
||||||
- ./logs:/opt/bro/logs
|
- ./logs:/opt/bro/logs
|
||||||
net: host
|
net: container:shadowsocks_shadowsocks_1
|
||||||
|
Loading…
x
Reference in New Issue
Block a user