Displaying 20 results from an estimated 9000 matches similar to: "Processed: logcheck ignore rules for rsyslogd"
2011 Apr 16
0
Bug#623058: logcheck: tweak 'rsyslogd was HUPed' filter
Package: logcheck
Version: 1.3.13
Severity: minor
Tags: patch
Hi,
Logcheck reports messages of the form:
Mar 15 06:25:26 foohost rsyslogd: [origin software="rsyslogd" swVersion="5.7.6" x-pid="3301" x-info="http://www.rsyslog.com"] rsyslogd was HUPed
I suggest the following tweak to /etc/logcheck/ignore.d.server/rsyslog:
diff -u
2010 Jul 28
2
Bug#590684: [logcheck-database] rules for rsyslog
Package: logcheck-database
Severity: wishlist
Tags: patch
Hi,
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ kernel: imklog 3\.18\.6, log
source = /proc/kmsg started\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rsyslogd: \[origin
software="rsyslogd" swVersion="3.18.6" x-pid="[[:digit:]]+"
x-info="http://www.rsyslog.com"\] restart$
Hendrik
--
Hendrik Jaeger
2006 Feb 09
1
Processed: Re: Bug#352043: dovecot-imapd: logcheck rules miss some lines
Processing commands for control at bugs.debian.org:
> reassign 352043 logcheck
Bug#352043: please integrate dovecot logcheck rule in the dovecot-common package
Bug reassigned from package `dovecot-common' to `logcheck'.
> retitle 352043 Please provide a backport of logcheck
Bug#352043: please integrate dovecot logcheck rule in the dovecot-common package
Changed Bug title.
>
2008 Feb 03
3
Bug#463793: rsyslogd restarts are not ignored
Package: logcheck-database
Version: 1.2.63
Severity: normal
--- Please enter the report below this line. ---
In fact, there does not appear to be any consideration
of rsyslogd's behavior. Attached is a rule to ignore
restarts.
--- System information. ---
Architecture: i386
Kernel: Linux 2.6.22-3-686
Debian Release: lenny/sid
990 testing ftp.debian.org
600 unstable
2011 Nov 09
0
Processed: Re: Bug#648146: ignore.d.server/ssh is too aggressive
Processing commands for control at bugs.debian.org:
> reassign 648146 logcheck-database 1.3.13
Bug #648146 [logcheck-database-1.3.13] ignore.d.server/ssh is too aggressive
Warning: Unknown package 'logcheck-database-1.3.13'
Bug reassigned from package 'logcheck-database-1.3.13' to 'logcheck-database'.
Bug No longer marked as found in versions squeeze.
Bug #648146
2010 Oct 29
0
Processed: reassign 583155 to logcheck
Processing commands for control at bugs.debian.org:
> reassign 583155 logcheck
Bug #583155 {Done: Hannes von Haugwitz <hannes at vonhaugwitz.com>} [amavisd-new] logcheck-database: Please create rules for amavis(d-new)
Bug #590965 {Done: Hannes von Haugwitz <hannes at vonhaugwitz.com>} [amavisd-new] amavisd-new: Please reprovide logcheck rules
Bug reassigned from package
2009 Feb 23
1
Bug#463793: rsyslogd restarts are not ignored
On Mon, 4 Feb 2008 08:15:24 +1300, martin f krafft wrote:
> logcheck has the policy not to ignore restart messages. Thanks for
> the patch, please understand that I won't be including it.
Quote from README.logcheck-database:
"Unfortunately, we don't have the time to add and update rules for
everything, therefore the following exceptions apply:
* Debug messages
* Messages
2011 Mar 07
0
Bug#617232: logcheck: ignore regexes match ipv4 addresses only, causing false positives with ipv6 addresses.
Package: logcheck
Version: 1.3.13
Severity: normal
Various files under ignore.d.* use "[0-9.]{7,15}" to match an IPv4
address, e.g., a connection to rsyncd. However, this does not match
IPv6 addresses, causing spurious reports.
A better regexp might be something like: ([0-9.]{7,15}|[0-9a-f:]{2,39})
-- System Information:
Debian Release: 6.0
APT prefers stable
APT policy: (990,
2005 Apr 10
0
Processed: Re: Bug#295352: logcheck doesn't ignore rsync's log "rsync on modulename-with-hyphen from host (ip)"
Processing commands for control at bugs.debian.org:
> reassign 295352 logcheck-database
Bug#295352: logcheck doesn't ignore rsync's log "rsync on modulename-with-hyphen from host (ip)"
Bug reassigned from package `rsync' to `logcheck-database'.
> thanks
Stopping processing here.
Please contact me if you need assistance.
Debian bug tracking system administrator
2005 Aug 31
1
Processed: Re: [Pkg-nagios-devel] Bug#325874: nagios-common: logcheck regexp issue
Processing commands for control at bugs.debian.org:
> reassign 325874 logcheck-database
Bug#325874: nagios-common: logcheck regexp issue
Bug reassigned from package `nagios-common' to `logcheck-database'.
> tags 325874 + patch
Bug#325874: nagios-common: logcheck regexp issue
Tags were: patch
Tags added: patch
> thanks
Stopping processing here.
Please contact me if you need
2011 Aug 23
1
Bug#475553: Patch for logcheck-rules
Hi,
after we switched to rsyslog with high precision timestamps logcheck did
not match the timestamps any more. A patch adding the high precision
timestamp format is attached. The rules now match both the traditional
timestamp format and the high precision timestamp format (with or without
microseconds).
Yours sincerely,
Ralf D?blitz
--
Ralf D?blitz
r.doeblitz at asco.de
Tel 0531/3906-116
2007 Jul 04
1
Bug#425035: hylafax-server: missing logcheck rule
package hylafax-server
reassign 425035 logcheck-database 1.2.56
thanks
I am reassigning this bug report since the hylafax logcheck rule is
distributed in package logcheck-database.
Bye,
Giuseppe
2012 Mar 02
1
Bug#661912: logcheck: files with period in ignore rule dirs ignored
Package: logcheck
Version: 1.3.14
Severity: normal
I added a local.rules file to ignore.d.server and then ran logcheck. The file was not used during the run.
Renaming it to local-rules got the file used during the next run.
Fix: periods should be allowed in filenames, or the fact that they are forbidden expressly documented inteh logcheck README.
Thanks
Nils
-- System Information:
Debian
2010 Feb 17
1
Bug#570207: logcheck wu-ftpd rules do'nt match
Package: logcheck
Version: 1.2.69
Severity: normal
In the file /etc/logcheck/ignore.d.server/wu-ftpd
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ wu-ftpd: PAM-listfile: Refused user [._[:alnum:]-]+ for service wu-ftpd$
should be
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ wu-ftpd\[[0-9]{4}\]: PAM-listfile: Refused user [._[:alnum:]-]+ for service wu-ftpd$
There is a number after "wu-ftpd"
-- System
2005 Jan 29
0
Processed: webmin bugs
Processing commands for control at bugs.debian.org:
> reassign 286307 logcheck
Bug#286307: logcheck rules file
Bug reassigned from package `webmin' to `logcheck'.
> tag 290516 woody wontfix
Bug#290516: webmin-cluster-useradmin: RPC error trying to add a new server
There were no tags set.
Tags added: woody, wontfix
> tag 280728 woody wontfix
Bug#280728: webmin postgresql module
2009 May 04
1
Bug#526911: logcheck: Please set rsyslog as default system log daemon
Package: logcheck
Version: 1.2.69
Severity: wishlist
User: biebl at debian.org
Usertags: goal-rsyslog
Hi,
since lenny, the default syslog daemon is rsyslog. Please update
logcheck to depend on
rsyslog | system-log-daemon
so the correct default syslog daemon is installed.
(btw, the optional | syslog-ng dependency is not required, as syslog-ng
does provide system-log-daemon)
Cheers,
Michael
--
2005 Mar 05
0
Processed: reassign syslog file handling
Processing commands for control at bugs.debian.org:
> clone 296096 -1
Bug#296096: logcheck shows the same month old logs again and again
Bug 296096 cloned as bug 298206.
> reassign -1 syslog-ng
Bug#298206: logcheck shows the same month old logs again and again
Bug reassigned from package `logcheck' to `syslog-ng'.
> severity -1 minor
Bug#298206: logcheck shows the same month
2005 Jun 03
2
[ttroxell@debian.org: Re: Logcheck rules from other packages]
I'm not sure if this message ever made it to you, Jamie. I had a reverse DNS
problem shortly after it was sent.
----- Forwarded message from Todd Troxell <ttroxell at debian.org> -----
Date: Wed, 1 Jun 2005 01:22:18 -0400
From: Todd Troxell <ttroxell at debian.org>
To: "Jamie L. Penman-Smithson" <jamie at silverdream.org>
Subject: Re: Logcheck rules from other
2011 Mar 09
1
Bug#617527: logcheck-database: incomplete rules for scponly-full
Package: logcheck-database
Version: 1.3.13
Severity: wishlist
Hi,
scponly-full (using 4.8-4.1) in Debian is compiled with additional support for rsync, unison and SVN.
However, the logcheck rule is based on the original version and doesn't include those commands in
the regexp.
Please add those three commands to the regexp.
Best regards,
Markus
-- System Information:
Debian Release:
2012 Jan 27
1
Bug#657641: /usr/sbin/logcheck: line 100: kill: (31667) - No such process
Package: logcheck
Version: 1.3.14
Severity: normal
Tags: patch
I keep getting these messages logged, when under high load.
This patch should clean that up.
commit 72661acccafa519fcb48a6a756e5c35d96e7511d
Author: Cristian Ionescu-Idbohrn <cristian.ionescu-idbohrn at axis.com>
Date: Fri Jan 27 16:08:33 2012 +0100
Workaround for error:
/usr/sbin/logcheck: line 100: kill: (31667)