Show all requests from one IP address in the access log
what is this ip doing on my server | show requests from one ip | filter access log by ip address | investigate suspicious ip | awk | access-log | ip | securityawk -v ip="203.0.113.10" '$1 == ip' /var/www/vhosts/system/example.com/logs/access_ssl_log | tail -50Prints only lines whose first column exactly matches the given IP and shows the last 50 of them. Unlike a plain grep, the exact comparison does not accidentally match similar addresses such as 1203.0.113.10. Useful after an IP has stood out in the top list and you want to know what it requests before blocking it.
Also searched as
- what is this ip doing on my server
- show requests from one ip
- filter access log by ip address
- investigate suspicious ip