Made condition to detect bots

I have a short log, where several columns – date, time, ip, name of user and operations, what user did

Friday, 10 October 2012 13:15:39 +0300|192.168.110.5|rock| - |user has made auth in| -
Friday, 10 October 2012 13:15:39 +0300|192.168.110.5|rock| - |user has changed password| -
Friday, 10 October 2012 13:15:39 +0300|192.168.110.5|rock| - |user has made auth off| -

From this part of log, I know, that “rock” it is a bot.
I have two conditions:
– user has made auth in, user changed password, user has made auth of within same second;
– actions (has made auth in, change, has made auth off) happend one after another

But i don’t understand how to do this ? What the instrument, i should use to solve this task ?

Related:


Leave a Reply