From: Krzysztof Kowalski Date: 2012-12-09T10:35:00+09:00 Subject: Getting info from array --f46d0444e92b9a7ad304d06174a1 Content-Type: text/plain; charset=ISO-8859-1 Hello there. I would like to make script that gets failed logging attempt ip, when it count that ip tried logging more than 5 times in row script will write new block rule with that ip to ipfilter in freebsd 8. So I like to manage this by getting each line of file with logging attempts to arrays ( it makes array in array). I have a little problem with obtaining array with word "Failed" and passing it to new array with ip's that i would like to block. Next I get every 13th element (which is ipv6 address) and write new rule after counting it with hash. Can someone show me how to make it happend? CODE: #!/usr/local/bin/ruby19 filename = '/var/log/auth.log' falo = String.new File.open(filename) { |f| falo = f.read } words = falo.split('\n') $ ruby19 -v ruby 1.9.3p327 (2012-11-10 revision 37606) [amd64-freebsd8] $ uname -a FreeBSD mc.pl.eu.org 8.3-STABLE FreeBSD 8.3-STABLE #0 r130: Mon Apr 23 17:41:20 IRKST 2012 root@freebsd8-amd64.ispsystem.net:/root/src/roman-sys/amd64/compile/ISPSYSTEM amd64 thanks in advance Krzysztof Kowalski --f46d0444e92b9a7ad304d06174a1 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
Hello there.
I would like to make script that gets failed lo= gging attempt ip, when it count that ip tried logging more than 5 times in = row script will write new block rule with that ip to ipfilter in freebsd 8.=
So I like to manage this by getting each line of file with logging att= empts to arrays ( it makes array in array). I have a little problem with ob= taining array with word "Failed" and passing it to new array with= ip's that i would like to block. Next I get every 13th element (which = is ipv6 address) and write new rule after counting it with hash.
Can someone show me how to make it happend?

C= ODE:
#!/usr/local/bin/ruby19
filename =3D '/va= r/log/auth.log'
falo =3D String.new
File.open(filen= ame) { |f| falo =3D f.read }
words =3D falo.split('\n')

$ ru= by19 -v
ruby 1.9.3p327 (2012-11-10 revision 37606) [amd64-freebsd= 8]
$ uname -a
FreeBSD mc.pl.eu.org 8.3-STABLE FreeBSD 8.3-STABLE #0 r130: Mo= n Apr 23 17:41:20 IRKST 2012 =A0 =A0 root@freebsd8-amd64.ispsystem.net:/roo= t/src/roman-sys/amd64/compile/ISPSYSTEM =A0amd64

thanks in advance
Krzysztof Kowalski
--f46d0444e92b9a7ad304d06174a1--