Gotta
catch 'em all (not Pokemon, spam)...
Sniffer caught all of them today:
gawk
"$0 ~ /.+From: .+To: .+IP: 200\.49\.[3|4|5]/ {print $3}" dec0617.log
>temp.txt
fgrep
-ftemp.txt dec0617.log | fgrep "Total weight"
If
your volume is quite high, that second line, instead of showing all the total
weights for the netblocks in question, could instead show which lines sniffer
didn't hit on:
fgrep
-ftemp.txt dec0617.log | fgrep "Total weight" | fgrep -v
"SNIFFER"
Andrew 8)
|
Title: Message
- RE: [sniffer] Spam blocks loading m... Chuck Schick
- Re[2]: [sniffer] Spam blocks l... Pete McNeil
- Re: [sniffer] Spam blocks loading m... Darrell (supp...@invariantsystems.com)
- Re: [sniffer] Spam blocks loading m... Darrell (supp...@invariantsystems.com)
- Re: [sniffer] Spam blocks load... Scott Fisher
- RE: [sniffer] Spam blocks loading m... Colbeck, Andrew
- RE: [sniffer] Spam blocks loading m... Colbeck, Andrew
- Re[2]: [sniffer] Spam blocks l... Pete McNeil
- RE: [sniffer] Spam blocks loading m... Michael Hardrick
- RE: Re[2]: [sniffer] Spam blocks lo... Colbeck, Andrew
- RE: [sniffer] Spam blocks loading m... Colbeck, Andrew