在 Debian 上,Apache 日志通常位于:
/var/log/apache2/access.log/var/log/apache2/error.log“过滤日志内容”常见有几种场景,下面按用途给你最实用的做法。
grep "192.168.1.100" /var/log/apache2/access.log
grep -v "192.168.1.100" /var/log/apache2/access.log
/admin 的日志grep "GET /admin" /var/log/apache2/access.log
.php 文件的请求grep "\.php" /var/log/apache2/access.log
grep " 404 " /var/log/apache2/access.log
grep " 500 " /var/log/apache2/access.log
Apache 日志中状态码前后有空格,用
" 404 "更精确
Debian Apache 日志默认格式包含时间,例如:
[10/Oct/2024:14:32:01 +0000]
grep "10/Oct/2024" /var/log/apache2/access.log
grep "10/Oct/2024:14:" /var/log/apache2/access.log
awk 做高级过滤(推荐)awk '{print $1, $7}' /var/log/apache2/access.log
awk '{print $1}' /var/log/apache2/access.log | sort | uniq -c | sort -nr | head
grep " 404 " /var/log/apache2/access.log | awk '{print $7}' | sort | uniq -c | sort -nr
tail -f /var/log/apache2/access.log | grep "192.168.1.100"
或只看错误:
tail -f /var/log/apache2/error.log
logrotate(.gz 日志)旧日志可能是:
/var/log/apache2/access.log.1.gz
zcat /var/log/apache2/access.log.1.gz | grep "404"
apachectl / journalctl(错误日志)如果是 systemd:
journalctl -u apache2
只看错误:
journalctl -u apache2 | grep error
如果你能说明 你想过滤什么(如:屏蔽蜘蛛、查攻击、看某用户、分析性能),我可以直接给你一条精准命令。