Avatar of Jason Yu
Jason YuFlag for United States of America asked on

how to extract lines with specific key word from a 30 G firewall log file.

I got a ftp drop error frequently on my gentran edi server. the error is as below:

Sent: Sunday, March 09, 2014 6:08 PM
To: EDI Group
Subject: Error in BaseEDI_Get_SCNCentre PID=4976630

System of Origin: IBM Sterling B2B Integrator 5.2 .
An ERROR has occurred in process BaseEDI_Get_SCNCentre.
Process ID: 4976630
Error Description: FTPGetError_Get
.
The errored file has been written to /u1/gis5.2/install/_BaseEDI/inboundErrors with filename 4976630.FTPGetError_Get.20140309180589_089.txt.
.
More details can be found in the GIS process Monitor.


My EDI coworker doubts if the firewall blocked the ftp traffic from time to time. My firewall is an old Cisco PIX 507 firewall with PIX Version 7.2(4). I am using Cisco ASDM 5.2 for PIX to check the firewall status. I saved the firewall log file to a linux box.

When I was checking the log file, it has a size of 30 G per day, I would like to know if there is a way I can customize the log file so that I capture only the records relates to that server?

Also, if I want to process that big log file, what linux command can I use to extract the lines with specific word.

thank you.
firewall-log-file-analysis.png
LinuxCisco

Avatar of undefined
Last Comment
Gerwin Jansen

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Gerwin Jansen

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Your help has saved me hundreds of hours of internet surfing.
fblack61