Andrew Gallagher
2015-Feb-21 14:53 UTC
[Logcheck-devel] Bug#778903: logcheck: saslauthd logging has changed
Package: logcheck Version: 1.3.15 Severity: normal Tags: patch New versions of saslauthd say "pam_unix(smtp:auth)" instead of "(pam_unix)". New rule is: ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ saslauthd\[[[:digit:]]+\]: pam_unix\(smtp:auth\) authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=( [[:space:]]*user=[-._[:alnum:]]+)?$ -- System Information: Debian Release: 7.8 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel: Linux 3.14.5-x86-linode61 (SMP w/8 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages logcheck depends on: ii adduser 3.113+nmu3 ii cron 3.0pl1-124 ii lockfile-progs 0.1.17 ii logtail 1.3.15 ii mime-construct 1.11 ii postfix [mail-transport-agent] 2.9.6-2 ii rsyslog [system-log-daemon] 5.8.11-3+deb7u2 Versions of packages logcheck recommends: ii logcheck-database 1.3.15 Versions of packages logcheck suggests: pn syslog-summary <none> -- Configuration Files: /etc/logcheck/logcheck.conf changed: REPORTLEVEL="server" SENDMAILTO="root at andrewg.com" FQDN=1 -- debconf information: logcheck/changes: * logcheck/install-note: