Initial cross-server log inventory + anomaly scan

- 10 hosts (mo1, ams, ams2, ro1, ca1, ca2, ca3, fr1, sony, termux)
- discover-logs.sh: portable inventory (Linux/FreeBSD/Termux)
- scan-anomalies.sh: ERROR/WARN/CRITICAL counts + journalctl + kubectl
- run-all.sh: parallel SSH fan-out
- build-summary.py: aggregates into reports/SUMMARY.md
- 5 HIGH-severity findings identified on ro1 (apache scanner traffic, mount_monitor warnings)
This commit is contained in:
2026-04-10 21:49:17 +00:00
parent cabf4c587f
commit e96a8b03fc
26 changed files with 1636 additions and 1 deletions

31
logs/inventory/ams.csv Normal file
View File

@@ -0,0 +1,31 @@
"/var/log/auth.log",626832,"","auth.log"
"/var/log/auth.log.0.bz2",76694,"","auth.log.0.bz2"
"/var/log/auth.log.1.bz2",78966,"","auth.log.1.bz2"
"/var/log/auth.log.2.bz2",73297,"","auth.log.2.bz2"
"/var/log/auth.log.3.bz2",75151,"","auth.log.3.bz2"
"/var/log/auth.log.4.bz2",76408,"","auth.log.4.bz2"
"/var/log/auth.log.5.bz2",75882,"","auth.log.5.bz2"
"/var/log/auth.log.6.bz2",76375,"","auth.log.6.bz2"
"/var/log/borg-backup.log",6198346,"","borg-backup.log"
"/var/log/daemon.log",2515,"","daemon.log"
"/var/log/daemon.log.0.bz2",266,"","daemon.log.0.bz2"
"/var/log/debug.log",121837,"","debug.log"
"/var/log/debug.log.0.bz2",55238,"","debug.log.0.bz2"
"/var/log/debug.log.1.bz2",58823,"","debug.log.1.bz2"
"/var/log/debug.log.2.bz2",57540,"","debug.log.2.bz2"
"/var/log/debug.log.3.bz2",49217,"","debug.log.3.bz2"
"/var/log/debug.log.4.bz2",48300,"","debug.log.4.bz2"
"/var/log/debug.log.5.bz2",48508,"","debug.log.5.bz2"
"/var/log/debug.log.6.bz2",48756,"","debug.log.6.bz2"
"/var/log/devd.log",58,"","devd.log"
"/var/log/dmesg.today",277,"","dmesg.today"
"/var/log/dmesg.yesterday",140,"","dmesg.yesterday"
"/var/log/mail-archive.log",209,"","mail-archive.log"
"/var/log/messages",350286,"","messages"
"/var/log/ppp.log",58,"","ppp.log"
"/var/log/redis/redis.log",28083,"","redis"
"/var/log/utx.log",2028,"","utx.log"
"/var/log/utx.log.0",17784,"","utx.log.0"
"/var/log/utx.log.1",480176,"","utx.log.1"
"/var/log/utx.log.2",11336,"","utx.log.2"
"/var/log/wg-restart.log",1689,"","wg-restart.log"
1 /var/log/auth.log 626832 auth.log
2 /var/log/auth.log.0.bz2 76694 auth.log.0.bz2
3 /var/log/auth.log.1.bz2 78966 auth.log.1.bz2
4 /var/log/auth.log.2.bz2 73297 auth.log.2.bz2
5 /var/log/auth.log.3.bz2 75151 auth.log.3.bz2
6 /var/log/auth.log.4.bz2 76408 auth.log.4.bz2
7 /var/log/auth.log.5.bz2 75882 auth.log.5.bz2
8 /var/log/auth.log.6.bz2 76375 auth.log.6.bz2
9 /var/log/borg-backup.log 6198346 borg-backup.log
10 /var/log/daemon.log 2515 daemon.log
11 /var/log/daemon.log.0.bz2 266 daemon.log.0.bz2
12 /var/log/debug.log 121837 debug.log
13 /var/log/debug.log.0.bz2 55238 debug.log.0.bz2
14 /var/log/debug.log.1.bz2 58823 debug.log.1.bz2
15 /var/log/debug.log.2.bz2 57540 debug.log.2.bz2
16 /var/log/debug.log.3.bz2 49217 debug.log.3.bz2
17 /var/log/debug.log.4.bz2 48300 debug.log.4.bz2
18 /var/log/debug.log.5.bz2 48508 debug.log.5.bz2
19 /var/log/debug.log.6.bz2 48756 debug.log.6.bz2
20 /var/log/devd.log 58 devd.log
21 /var/log/dmesg.today 277 dmesg.today
22 /var/log/dmesg.yesterday 140 dmesg.yesterday
23 /var/log/mail-archive.log 209 mail-archive.log
24 /var/log/messages 350286 messages
25 /var/log/ppp.log 58 ppp.log
26 /var/log/redis/redis.log 28083 redis
27 /var/log/utx.log 2028 utx.log
28 /var/log/utx.log.0 17784 utx.log.0
29 /var/log/utx.log.1 480176 utx.log.1
30 /var/log/utx.log.2 11336 utx.log.2
31 /var/log/wg-restart.log 1689 wg-restart.log