+
+ echo "${indent_unit}-->"
+
+ printf '%sUDP: ' "${indent_unit}${indent_unit}"
+ sudo -n netstat -ulnp \
+ | awk 'NR > 2 {print $6}' \
+ | awk -F/ '{print $2}' \
+ | sort -u \
+ | xargs \
+ | column -t
+
+ printf '%sTCP: ' "${indent_unit}${indent_unit}"
+ sudo -n netstat -tlnp \
+ | awk 'NR > 2 {print $7}' \
+ | awk -F/ '{print $2}' \
+ | sort -u \
+ | xargs \
+ | column -t
+
+ echo "${indent_unit}<->"
+
+ printf '%sTCP: ' "${indent_unit}${indent_unit}"
+ sudo -n netstat -tnp \
+ | awk 'NR > 2 && $6 == "ESTABLISHED" {print $7}' \
+ | awk -F/ '{print $2}' \
+ | sort -u \
+ | xargs \
+ | column -t
+
+ # TODO: iptables summary
+}
+
+ssh_invalid_attempts_from() {
+ awk '
+ /: Invalid user/ && $5 ~ /^sshd/ {
+ u=$8
+ addr=$10 == "port" ? $9 : $10
+ max++
+ curr[addr]++
+ }
+
+ END {
+ for (addr in curr)
+ if ((c = curr[addr]) > 1)
+ print c, max, addr
+ }
+ ' \
+ /var/log/auth.log \
+ /var/log/auth.log.1 \
+ | sort -n -k 1 \
+ | bar_gauge -v width="$(stty size | awk '{print $2}')" -v num=1 -v ch_right=' ' -v ch_left=' ' -v ch_blank=' ' \
+ | column -t
+}
+
+loggers() {
+ awk '
+ {
+ split($5, prog, "[")
+ sub(":$", "", prog[1]) # if there were no [], than : will is left behind
+ print prog[1]
+ }' /var/log/syslog /var/log/syslog.1 \
+ | awk '
+ {
+ n = split($1, path, "/") # prog may be in path form
+ prog = path[n]
+ total++
+ count[prog]++
+ }
+
+ END {
+ for (prog in count)
+ print count[prog], total, prog
+ }' \
+ | sort -n -k 1 \
+ | bar_gauge -v num=1 -v ch_right=' ' -v ch_left=' ' -v ch_blank=' ' \
+ | column -t