ChamplainTechJournals/db-security-sec300/week4.md
2025-04-19 23:42:08 -04:00

475 B

Week4

Log analysis

  • sudo nano /etc/mysql/mysql.conf.d/mysqld.cnf

image

  • Display failed connect logs, display only date, time, and user
cat /var/log/mysql/query.log | awk -F"[[:space:]T]+" '/Access denied/ {print $1,$2,$9}'
  • Display successful connect logs, display only date, time, and user
cat /var/log/mysql/query.log | awk -F"[[:space:]T]+" '/Connect/ {print $1,$2,$5}' | grep -v 'Access'