SELECT version() AS version
SELECT routine_schema from INFORMATION_SCHEMA.routines where routine_name = 'wfwl_inet_pton'
SELECT count(*) FROM webfwlog.services LIMIT 1
SHOW COLUMNS FROM webfwlog.hostnames LIKE 'ip_addr';
SELECT definition FROM webfwlog.reports WHERE code ='basic'
SELECT oob_family FROM ulogd.ulog LIMIT 1;
SELECT ip_saddr_bin FROM ulogd.ulog LIMIT 1;
SHOW COLUMNS FROM ulogd.ulog LIKE 'ip_saddr_bin';
SHOW COLUMNS FROM ulogd.ulog LIKE 'icmp_gateway';
SELECT local_time FROM ulogd.ulog LIMIT 1
SELECT oob_family FROM ulogd.ulog LIMIT 1
SELECT _id FROM ulogd.ulog LIMIT 1
SELECT mac_str FROM ulogd.ulog LIMIT 1
SELECT last_accessed FROM webfwlog.reports
UPDATE webfwlog.reports SET last_accessed = 1781134212 WHERE code = 'basic'
SHOW COLUMNS FROM ulogd.ulog;
CREATE TEMPORARY TABLE webfwlog.allrows AS
SELECT
	CAST('ulogd.ulog' AS char(32)) AS sname,
	t.ip_saddr_bin AS `ip_saddr`,
	t.ip_daddr_bin AS `ip_daddr`,
	t.*
FROM ulogd.ulog AS t

WHERE 	    (t.oob_time_sec IS NOT NULL AND t.oob_time_sec>=1780984800)
	AND (t.oob_time_sec IS NOT NULL AND t.oob_time_sec<=1781134212)
	AND (t.ip_protocol<>6 OR (t.tcp_syn OR t.tcp_fin OR t.tcp_ack OR t.tcp_rst OR t.tcp_psh OR t.tcp_urg))
SHOW COLUMNS FROM ulogd.ulog;
CREATE TEMPORARY TABLE webfwlog.tmp_output AS
SELECT
	count(*) AS `count_t`,
	count(*) AS `Count`,
	oob_prefix AS `Label`,
	CASE WHEN t.ip_protocol=6  THEN 'tcp'
	     WHEN t.ip_protocol=17 THEN 'udp'
	     WHEN t.ip_protocol=1  THEN 'icmp'
	     WHEN t.ip_protocol=58 THEN 'ipv6-icmp'
	     ELSE t.ip_protocol
	END
	AS `Proto`,
	wfwl_inet_ntop(t.oob_family, ip_saddr_bin) AS `Source IP`,
	wfwl_inet_ntop(t.oob_family, ip_daddr_bin) AS `Destination IP`,
	CASE WHEN t.ip_protocol=6  THEN tcp_dport
	     WHEN t.ip_protocol=17 THEN udp_dport
	     ELSE 65536
	END
	AS `Dest Port`,
	if(t.ip_protocol<>6,'',
	  if(tcp_syn AND NOT (tcp_urg OR tcp_psh OR tcp_rst OR tcp_ack OR tcp_fin),' SYN  ',
	    concat(
	    if( tcp_syn, 's', '-'),
	    if( tcp_ack, 'a', '-'),
	    if( tcp_fin, 'f', '-'),
	    if( tcp_rst, 'r', '-'),
	    if( tcp_psh, 'p', '-'),
	    if( tcp_urg, 'u', '-'))))
	AS `Options` 

FROM webfwlog.allrows t


GROUP BY 	`Label`,
	t.ip_protocol,
	ip_saddr_bin,
	ip_daddr_bin,
	`Dest Port`,
	`Options` 

ORDER BY 	t.ip_protocol DESC,
	`Dest Port` ASC,
	ip_saddr_bin ASC 
;
SELECT count(*) AS `count` FROM webfwlog.allrows
SELECT sum(`count_t`) AS `count` FROM webfwlog.tmp_output
SELECT count(*) AS `count` FROM webfwlog.tmp_output
CREATE TEMPORARY TABLE webfwlog.output AS
	SELECT * FROM webfwlog.tmp_output LIMIT 0, 20;
DROP TABLE webfwlog.tmp_output;
SELECT * FROM webfwlog.output
Firewall Log Report

Firewall Log Report


Packet Logged since Yesterday

Home  Edit this report 
Count Label Proto Source IP Destination IP Dest Port Options
14 INVALID ipv6-icmp ::0.4.0.0 2001:470:f1c4:1::42
3 INVALID ipv6-icmp ::2:0:4:0 2001:470:f1c4:1::42
1 INVALID ipv6-icmp ::c0:7597:6c55:0 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 0:0:ac2:493f:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 0:0:507f:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 0:0:5e7f:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 0:0:ce0a:b0fa:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 0:0:e77f:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp f:6ac6:9605:3761:3330:3220:466f:756e 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 27:e040:ee7e:da61:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:8d3:a203:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:1f6b:a800:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:2008:1f03:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:29bc:c700:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:2fd5:f702:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:3eb4:6a01:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:80b7:9e02:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:9059:7d01:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:a4f2:d900:: 2001:470:f1c4:1::42
1 INVALID ipv6-icmp 29:8132:300:0:ab0f:c802:: 2001:470:f1c4:1::42
<< [1] 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 > >>
Rows 1 to 20 of 42704 displayed
106416 logged entries matched

Query time was 2 Seconds.
Report time was 0 Seconds.
Total time was 2 Seconds.

DROP TABLE webfwlog.output
DROP TABLE webfwlog.allrows

Generated by webfwlog 1.1.3