↑ ↓ select, Enter open, Esc close

Count IP addresses blocked by ufw

Adjust the values, the command updates live
root@server
journalctl -k --since "today" --no-pager | grep 'UFW BLOCK' | grep -o 'SRC=[^ ]*' | sort | uniq -c | sort -rn | head -20

Reads the kernel messages from the journal, filters the packets blocked by ufw and counts the source addresses. Also works on Debian 12 without rsyslog, where there is no /var/log/ufw.log. Time ranges such as today, 1 hour ago or 2026-10-09 08:00 are accepted.

Note: Requires ufw logging to be enabled (ufw logging low).

Also searched as

  • ufw show blocked ips
  • count ufw block entries
  • ufw.log missing debian 12

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.