/var/log/vsftpd.log 或 /var/log/xferlog,可通过配置文件 /etc/vsftpd/vsftpd.conf 确认路径。cat /var/log/vsftpd.log:查看完整日志。less /var/log/vsftpd.log:分页查看,支持上下翻页。tail -f /var/log/vsftpd.log:实时监控最新日志。grep "user1" /var/log/vsftpd.log。awk '$1 == "$(date +%Y-%m-%d)"' /var/log/vsftpd.log。grep "RETR" /var/log/vsftpd.log | wc -l。awk '/user1/ {count++} END {print count}' /var/log/vsftpd.log。awk '{print $5}' /var/log/vsftpd.log | sort | uniq -c | sort -nr。grep "Failed password" /var/log/auth.log(需结合系统认证日志)。Logwatch:每日生成日志报告,需安装配置。ELK Stack:可视化分析大规模日志,适合复杂场景。cron 定时任务删除超过7天的日志。sudo 访问日志文件,避免权限不足。参考来源: