Return-Path: Delivered-To: apmail-httpd-users-archive@www.apache.org Received: (qmail 34600 invoked from network); 5 Apr 2011 18:12:17 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.3) by minotaur.apache.org with SMTP; 5 Apr 2011 18:12:17 -0000 Received: (qmail 50774 invoked by uid 500); 5 Apr 2011 18:12:13 -0000 Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 50714 invoked by uid 500); 5 Apr 2011 18:12:13 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 50706 invoked by uid 99); 5 Apr 2011 18:12:13 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 05 Apr 2011 18:12:13 +0000 X-ASF-Spam-Status: No, hits=1.5 required=5.0 tests=HTML_MESSAGE,RCVD_IN_DNSWL_LOW,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of yehuda@ymkatz.net designates 209.85.214.45 as permitted sender) Received: from [209.85.214.45] (HELO mail-bw0-f45.google.com) (209.85.214.45) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 05 Apr 2011 18:12:05 +0000 Received: by bwz16 with SMTP id 16so723823bwz.18 for ; Tue, 05 Apr 2011 11:11:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ymkatz.net; s=g; h=domainkey-signature:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=XZacAMBhMN2ZNpKDYlI2T5ACrWh3okGbP1aAVCr27U8=; b=bPSvgSnl8oR8Rs1DnGwgAv+n9NbHTDS3y2qgcH2YwkHqp/HfxGUqL6kYnN9R4lOx/g lxnce9qqX7fU/NoyoH84pITweyHJMb4x9/G0n0dTyJE1uRBK5dKadI9WAp+PLvLFod6Z D3YKB0LhXdaFCDb2cmP2Al/ErIEAMXgLjUOrY= DomainKey-Signature: a=rsa-sha1; c=nofws; d=ymkatz.net; s=g; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; b=JDAMmDzgS+MQQI6Kj2bItbxuRWh3mjl6BQxYbz14hF3UTqX+cg3Xr5DItTIAUk1/E+ svFTvKfliFJIPbXFjDOGGIzFEe+8jDk08oHyuXBAGnOrk6b3UAJdB6iVGInDM27HpjbJ TgK8aJlZPBWnIzGhP6mWeeKyxZKB8ZCpiGtTI= Received: by 10.204.74.85 with SMTP id t21mr7480376bkj.128.1302027104457; Tue, 05 Apr 2011 11:11:44 -0700 (PDT) Received: from mail-fx0-f45.google.com (mail-fx0-f45.google.com [209.85.161.45]) by mx.google.com with ESMTPS id z18sm3904929bkf.8.2011.04.05.11.11.43 (version=SSLv3 cipher=OTHER); Tue, 05 Apr 2011 11:11:44 -0700 (PDT) Received: by fxm2 with SMTP id 2so597328fxm.18 for ; Tue, 05 Apr 2011 11:11:42 -0700 (PDT) Received: by 10.223.5.212 with SMTP id 20mr709105faw.40.1302027102626; Tue, 05 Apr 2011 11:11:42 -0700 (PDT) MIME-Version: 1.0 Received: by 10.223.97.73 with HTTP; Tue, 5 Apr 2011 11:11:22 -0700 (PDT) In-Reply-To: References: From: Yehuda Katz Date: Tue, 5 Apr 2011 14:11:22 -0400 Message-ID: To: users@httpd.apache.org Cc: Chad Morland Content-Type: multipart/alternative; boundary=0015174737aaf0a64804a02fce47 X-Virus-Checked: Checked by ClamAV on apache.org Subject: Re: [users@httpd] Full Request URI in access_log --0015174737aaf0a64804a02fce47 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On Tue, Apr 5, 2011 at 1:00 PM, Chad Morland wrote: > I've got a domain hosted on one of our servers that seems to be getting a > ton of junk traffic from Bit Torrent clients. > > The request that is showing up in my access_log is: > > > /announce...cedc031275%20430?info_hash=3D%CE%0Az%19%3C%3B~%84%2F.%8Cc%8A%= DDyZ%C7%18%18%26&peer_id=3D-BC0109-%5E%02%B2%FDw%AB%19%DD%D9%BDxB&port=3D24= 668&natmapped=3D1&localip=3D192.168.1.11&port_type=3Dwan&uploaded=3D0&downl= oaded=3D0&left=3D31457280&numwant=3D100&compact=3D1&no_peer_id=3D1&key=3D48= 054&event=3Dstarted > > As you can see the full URI is not displayed after "announce". What is > causing this to be clipped? I've tried different LogFormat options but > nothing seems to display the full URI. > You might be able to use "%U" for the URL without the query string and separately "%q" for the query string only. - Y --0015174737aaf0a64804a02fce47 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
On Tue, Apr 5, 2011 at 1:00 PM,= Chad Morland <c= morland@gmail.com> wrote:
I've got a domain hosted on one of our servers that seems to be getting= a ton of junk traffic from Bit Torrent clients.

The request that i= s showing up in my access_log is:

/announce...cedc031275%20430?info_= hash=3D%CE%0Az%19%3C%3B~%84%2F.%8Cc%8A%DDyZ%C7%18%18%26&peer_id=3D-BC01= 09-%5E%02%B2%FDw%AB%19%DD%D9%BDxB&port=3D24668&natmapped=3D1&lo= calip=3D192.168.1.11&port_type=3Dwan&uploaded=3D0&downloaded=3D= 0&left=3D31457280&numwant=3D100&compact=3D1&no_peer_id=3D1&= amp;key=3D48054&event=3Dstarted

As you can see the full URI is not displayed after "announce"= . What is causing this to be clipped? I've tried different LogFormat op= tions but nothing seems to display the full URI.

You might be able to use "%U" for the URL without = the query string and separately "%q" for the query string only.

- Y
--0015174737aaf0a64804a02fce47--