- 10 hosts (mo1, ams, ams2, ro1, ca1, ca2, ca3, fr1, sony, termux) - discover-logs.sh: portable inventory (Linux/FreeBSD/Termux) - scan-anomalies.sh: ERROR/WARN/CRITICAL counts + journalctl + kubectl - run-all.sh: parallel SSH fan-out - build-summary.py: aggregates into reports/SUMMARY.md - 5 HIGH-severity findings identified on ro1 (apache scanner traffic, mount_monitor warnings)
26 lines
663 B
Plaintext
26 lines
663 B
Plaintext
=== Anomaly scan: ams2.3z8.pw (2026-04-10T21:45:59Z) ===
|
|
|
|
--- recent log files (mtime < 7d) ---
|
|
/var/log/borg/cron.log errors=1 warns=0 size=265522
|
|
> M /etc/periodic/security/520.pfdenied
|
|
|
|
--- /var/log disk usage ---
|
|
7.7M /var/log
|
|
68K /var/log/auth.log.6.bz2
|
|
72K /var/log/auth.log.0.bz2
|
|
72K /var/log/auth.log.3.bz2
|
|
72K /var/log/auth.log.4.bz2
|
|
72K /var/log/auth.log.5.bz2
|
|
76K /var/log/bsdinstall_log
|
|
84K /var/log/maillog.2.bz2
|
|
160K /var/log/cron
|
|
628K /var/log/borg
|
|
640K /var/log/maillog
|
|
672K /var/log/debug.log
|
|
704K /var/log/auth.log
|
|
704K /var/log/daemon.log
|
|
704K /var/log/messages
|
|
1.6M /var/log/letsencrypt
|
|
|
|
--- top 15 largest files under /var/log ---
|