Lire User's Manual

Joost van Baal

Egon L. Willighagen

Francis J. Lacoste

This manual is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.

This is distributed in the hope that it will be useful, but without any warranty; without even the implied warranty of merchantability or fitness for a particular purpose. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this manual (see COPYING); if not, check with http://www.gnu.org/copyleft/gpl.html or write to the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111, USA.

Revision History
Revision 20020214 $Date: 2002/02/13 21:57:27 $
$Id: user-manual.dbx,v 1.28 2002/02/13 21:57:27 flacoste Exp $

Table of Contents

Preface
What This Book Contains
How Is This Book Organized?
Conventions Used
If You Don't Find Something In This Manual
I. Lire Overview
1. Introducing Lire
What Is Lire?
Supported Systems
Supported Applications
Supported Output Format
What Lire Can't Do
2. Installing Lire
Client Installation
Requirements
Installing
Standalone Installation
Requirements
Installing
Anonimized Client Installation
Requirements
Installing
Responder Installation
Requirements
Installation
Installing Under Exim
Installing Under Postfix
Installing Under qmail
Making The Responder Run At Boot
Configuring Lire Using lr_config
3. Running Lire
Using A Responder
Generating A Report From A Log File
Selecting Output Format
Including Charts in the Report
Sending Anonimized Log Files To A Responder
Processing The Responder's Results
Running Lire In A Server Cluster
Using Mail
Using Syslog
4. Automating Lire
Automatically Processing Log Files Using Cron
Configuring lr_cron
Installing the Cron Job
Automatically Processing Log Files Through A Responder
Automatically Processing Log Files In A Server Farm
5. Customizing Lire's Reports
The Report's Configuration File
Selecting Subreports
Reordering The Subreports
Changing Parameters
Using Subreports On Filtered Input
II. Reports Reference
6. Database Reports
Supported Log Format
MySQL's Log
Reports' Descriptions and Configuration
Actions By Period Database Report
Most Active Users Database Report
Most Accessed Databases Database Report
Queries By Type
Filters' Descriptions and Configuration
7. DNS Reports
Supported Log Format
Bind8 Query Log
Bind9 Query Log
Reports' Descriptions and Configuration
Top Requesting Hosts Report
Top Requesting Hosts By Method Report
Top Requested Names Report
Top Requested Names By Method Report
Distribution of Request Types by Method DNS Report
Distribution of Request Types Report
Distribution of Request Types By Method Report
Requests Summary DNS Report
Requests Summary by Method DNS Report
Requests By Period DNS Report
Requests By Period By Method DNS Report
Requests By Timeslot DNS Report
Requests by Period by Method DNS Report
Requests by Timeslot by Method DNS Report
Filters' Descriptions and Configuration
Select Resolver Filter
8. Email Reports
Supported Log Format
Exim
Netscape Messaging Server
Postfix
Qmail
Sendmail
Reports' Descriptions and Configuration
Deliveries Attempts By Period By Status Email Report
Deliveries Attempts By Period Email Report
Deliveries Attempts By Delay Email Report
Deliveries Attempts By Size Email Report
Failed Deliveries By Relay Email Report
Highest Average Delay By To Relay And To Domain Email Report
Most Deliveries Between Relays Email Report
Most Deliveries From Domain Email Report
Most Deliveries From User By Domain Email Report
Most Deliveries From Relay Email Report
Largest Email Exchange Email Report
Most Deliveries To Domain Email Report
Most Deliveries To User By Domain Email Report
Most Deliveries From Relay Email Report
Largest Volume Received From Domain Email Report
Largest Volume Sent To Domain Email Report
Tracked Recipients Email Report
Tracked Senders Email Report
Volume Delivered By Period Email Report
Filters' Descriptions and Configuration
9. Firewall Reports
Supported Log Format
Cisco ACL
IPChains
IP Filter
IPTables
WebTrends Enhanced Log Format
Reports' Descriptions and Configuration
Bytes by Period Firewall Report
Traffic's Volume by Rule Firewall Report
Bytes by Timeslot Firewall Report
Top Bytes per From-IP Report
Top Bytes per From-IP per Port Report
Top Bytes per To-ip Report
Top Bytes per destination IP per Port Report
Top blocked tcp packets per source IP per destination port Report
Packets by Period Firewall Report
Packets by Rule Firewall Report
Packets by Timeslot Firewall Report
Packet Summary Firewall Report
Top Volume to Destination by Source Firewall Report
Top Volume to Destination by Source Firewall Report
Top Messages Firewall Report
Top Messages Firewall Report
Top Messages Firewall Report
Top Packets by Source IP Report
Top Packets by Destination IP Report
Top Packets Destination by Source Firewall Report
Top Packets Source by Destination Firewall Report
Volume Summary Firewall Report
Filters' Descriptions and Configuration
Select Action Filter
10. FTP Reports
Supported Log Format
Microsoft Internet Information Server
Xferlog
Reports' Descriptions and Configuration
Top Remote Host FTP Report
Bytes By Day FTP Report
Bytes by Period FTP Report
Bytes by User by Period FTP Report
Bytes by Direction by User with count by Period FTP Report
Top Files FTP Report
Top Uploaded Files FTP Report
Top Downloaded Files FTP Report
Top Users FTP Report
Top by User (Bytes Transferred) FTP Report
Tracked Users FTP Report
Tracked Files FTP Report
Number of Transfers by Direction FTP Report
Number of Transfers by Transfer Type FTP Report
Filters' Descriptions and Configuration
11. Print Reports
Supported Log Format
CUPS' page_log
LPRng Account Log File
Reports' Descriptions and Configuration
Jobs per Printer Print Report
Top Users Print Report
Jobs per Printer per Period Print Report
Filters' Descriptions and Configuration
12. Proxy Reports
Supported Log Format
Microsoft Internet Security and Acceleration Server
Squid
WebTrends Enhanced Format
Reports' Descriptions and Configuration
Bytes by Cache Result
Bytes by Object's Source
Bytes Transferred By Period Proxy Report
Bytes Transferred By Timeslot Proxy Report
Client Summary Proxy Report
Requests Summary Proxy Report
Requests by Cache Result
Requests By Period Proxy Report
Requests By Size Proxy Report
Number of Requests By Timeslot Proxy Report
Requests By Request's Time Proxy Report
Top Clients by Destinations Proxy Report
Top Destinations by Number of Requests
Top Destinations by Bytes Downloaded
Top Destinations by Clients
Top Destinations by Users Proxy Report
Top Users by Destinations Proxy Report
Top MIME types by Transferred Size
Top Users by Bytes Proxy Report
Top URLs by Users Proxy Report
User Summary Proxy Report
Filters' Descriptions and Configuration
Select Cache Result Filter
13. WWW Reports
Supported Log Format
Common Log Format
Combined Log Format
CLF With mod_gzip Extensions
Referer Log Format
Logs With Virtual Host Information
W3C Extended Log Format
Reports' Descriptions and Configuration
Bytes By Day WWW Report
Bytes By Period WWW Report
Bytes Per Directory WWW Report
Bytes By HTTP Result By Day WWW Report
Bytes By HTTP Result By Period WWW Report
Bytes By HTTP Result WWW Report
Client Hosts by Day WWW Report
Client Hosts By Period WWW Report
Requests By Browser WWW Report
Number of Requests By Day WWW Report
Number of Requests By Period WWW Report
Requests By Browser Language WWW Report
Requests By HTTP Method WWW Report
Requests By OS WWW Report
Requests By Result By Day WWW Report
Requests By Result By Period WWW Report
Requests By HTTP Result WWW Report
Requests By Gzip Result WWW Report
Requests By Robot Report
Requests By Top Level Domain Report
Requests By Attack Report
Requests By Keywords Report
Requests By User Agent WWW Report
Number of Requests By Size WWW Report
Number of Requests By Timeslot WWW Report
Requests By HTTP Protocol Version WWW Report
Requests Summary WWW Report
Average Compression By File Type WWW Report
Most Averaged Compressed Requested File WWW Report
Top Client By HTTP Result WWW Report
Top Client WWW Report
Last Pages By Session WWW Report
First Pages By Session WWW Report
Most Requested Pages By Client Host WWW Report
Most Travelled Referer -> Page Connections WWW Report
Top Referring Pages By Requested Page WWW Report
Most Requested Pages WWW Report
Most Requested Tracked Pages By Client Host WWW Report
Requested Tracked Pages By Period WWW Report
Most Requested URLs By Client Host WWW Report
User Sessions By Period WWW Report
Finished and Unfinished Session WWW Report
Visit times User Session WWW Report
Page Counts User Session WWW Report
Filters' Descriptions and Configuration
Select URL Filter
Select Client Host Filter
Exclude URL Filter
Exclude Client Host Filter
Exclude Referer Filter
III. Lire Reference
14. Installation Parameters
./configure parameters
Installation Environment Variables
15. Configuration Parameters
General Configuration Parameters
Responder Configuration Parameters
Miscellaneous Configuration Parameters
The Lire Archive and Temporary Files
16. Lire Logging and Error Messages
Logging
Log Messages
17. Lire Installation Layout