On Fri, 28 May 2010 19:04:17 +0200 Holger Levsen <[email protected]> wrote:
> I often add logcheck ignore rules for security related events (like ssh login > attemps. etc), cause they are too many and login is protected reasonably > anyway. > > But then I would like to get summaries for some ignored patterns, probably one > mail per host day. > > Do you think thats a reasonable feature request? This is already possible, maybe that's why no-one replied for 15 years. Simply create a command called syslog-summary and tell logcheck to use it (via the setting in logcheck.conf) Think we should close this bug on that basis it would be better to develop such a summarising programme outside logcheck as it's a whole other project to work out what to summarise, and how to present the results - you'd need a lot of flexibility to please everyone, i suspect. There was packaged version called syslog-summary some releases ago, but no-one maintained it and it was removed from Debian. but the code to use it remains in logcheck.

