Logcheck syntax

This is a discussion on Logcheck syntax within the Linux Security forums, part of the System Security and Security Related category; Hello, I have been testing to filter out some messages in logcheck. I have added a local.name to /etc/...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-10-2004
Brian Olivier
 
Posts: n/a
Default Logcheck syntax

Hello,

I have been testing to filter out some messages in logcheck.
I have added a local.name to /etc/logcheck/ignore.d.server for my own
filters.

The line I want to filter is:

postfix/smtpd[8782]: reject: RCPT from unknown[211.237.92.198]: 554
Service unavailable; [211.237.92.198] blocked using bl.spamcop.net,
reason: Blocked - see http://www.spamcop.net/bl.shtml?211.237.92.198;
from=<fzcqqnewwbnm@front.ru> to=<duncan@olivier.com>

To filter it out I have the following string:

postfix/smtpd\[.*\]: reject: RCPT from .*\[.*\]: 554 Service
unavailable; \[.*\] blocked using bl.spamcop.net, reason: Blocked
- see http://www.spamcop.net/bl.shtml?.*\; from=.* to=.*

When I run grep -f local.name /var/log/mail.log I receive only similar
lines when I do grep -v -f local.name /var/log/mail.log the line is
ignored.

However when logcheck runs the line is not ignored and shows up in the
report. Any clues to why my filter does not work?

Thanks in advance for your help.

Brian
Reply With Quote
  #2 (permalink)  
Old 08-10-2004
Bill Marcum
 
Posts: n/a
Default Re: Logcheck syntax

On 10 Aug 2004 06:14:39 -0700, Brian Olivier
<brian@olivier.com> wrote:
> Hello,
>
> I have been testing to filter out some messages in logcheck.
> I have added a local.name to /etc/logcheck/ignore.d.server for my own
> filters.
>
> However when logcheck runs the line is not ignored and shows up in the
> report. Any clues to why my filter does not work?
>

You probably need to put this filter in violations.ignore.d.


--
The truth you speak has no past and no future. It is, and that's all it
needs to be.
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:56 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0