Package: sogo
Version: 1.3.15a-1
Severity: grave
Tags: patch
Justification: renders package unusable
Dear Maintainer,
the packages cronjob at /etc/cron.daily/sogo implements a really
bad find statement to clean up empty directory beneath /var/spool/sogo.
find /var/spool/sogo -mindepth 1 -type d
Hi,
here is the complete mail body attached. It is reported as "Security
Events":
-
This email is sent by logcheck. If you wish to no-longer receive it,
you can either deinstall the logcheck package or modify its
configuration file (/etc/logcheck/logcheck.conf).
Security Events
=-=-=-=-=-=-=
Package: logcheck-database
Version: 1.2.44
Severity: normal
the following rule in /etc/logcheck/ignore.d.server/bind does not match
the linei(s) in our log and get reported:
rule:
---
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ named\[[0-
Package: logcheck
Version: 1.2.42
Severity: normal
logcheck reports lots (and I mean lots) of messages from snmpd in the
following format:
Dec 13 16:05:07 example snmpd[571]: Connection from UDP:
[xxx.xxx.xxx.xxx]:33164
inside ignore.d.server I found a rule that should in my opinion match
those
dia/plugin/net.php.smarty/libs/plugins/modifier.debug_print_var.php uploadedĀ (1863 bytes, 9.41KB/sec)
can't figuere out why the lines are not ignored.
thanks in advice!
On Sun, 2005-02-20 at 16:55 +, Jamie L. Penman-Smithson wrote:
On Sun, 2005-02-20 at 12:10 +0100, Ingo Theiss wrote:
&
> I couldn't find this rule anywhere, however I've added the following
> rule to CVS which matches the log message you gave:
>
> ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ courierpop3login: (TIMEOUT|
> DISCONNECTED), [EMAIL PROTECTED]:alnum:]]+, ip=\[[.:[:alnum:]]+\],
> top=[[:digit:]]+, retr=[[:digit:
Package: logcheck
Version: 1.2.34
Severity: normal
the pattern in ignore.d.server pure-ftpd for '[NOTICE] ... uploaded' is
not matching the following message:
Feb 18 23:06:18 example pure-ftpd: ([EMAIL PROTECTED]) [NOTICE]
/docroot/example.com//htdocs/guradia/plugin/net.php.smarty/libs/plugins/fu
Package: logcheck
Version: 1.2.34
Severity: normal
please include a rule for the following message from pure-ftpd:
Feb 19 04:04:58 web1 pure-ftpd: ([EMAIL PROTECTED]) [NOTICE]
Restarting at 331138
this message is not relevant for a server administrator and should be
ignored.
thanks a lot.
-- S
Package: logcheck
Version: 1.2.34
Severity: normal
the patterns for pure-ftpd in ignore.d.server are not matching a user
with a trailing whitespace. here a some examples:
Feb 18 13:02:33 web1 pure-ftpd: (stupid-pure-ftpd @84.56.131.73) [NOTICE]
/example/example.txt downloaded (5908 bytes, 152196
Package: logcheck
Version: 1.2.34
Severity: normal
the courier-pop pattern for 'DISCONNECTED' does not match the following
message:
Feb 17 18:25:58 backup courierpop3login: DISCONNECTED,
[EMAIL PROTECTED], ip=[:::111.111.111.111], top=0, retr=0,
time=5
seems like a typo prevents a match! her
Package: logcheck
Version: 1.2.34
Severity: normal
there is no pattern matching a simply 'Logout' with ip address. please
supply a pattern for the following message too:
Feb 15 18:13:38 backup courierpop3login: LOGOUT,
ip=[:::111.111.111.111]
thank you for the good work!
-- System Informati
Package: logcheck
Version: 1.2.34
Severity: normal
the 'Logout' pattern does not match a message without a ftp user name
given. here is the message from syslog:
Feb 14 16:31:51 web1 pure-ftpd: ([EMAIL PROTECTED]) [INFO] Logout.
although the missing user name from pure-ftpd is not correct the mes
Package: logcheck
Version: 1.2.34
Severity: normal
there is no pattern for 'Timeout' message without additional
information. the following message should be ignored to:
Feb 14 17:23:15 web1 pure-ftpd: ([EMAIL PROTECTED]) [INFO]
Timeout
the two lines regarding 'Timeout' do not match:
^\w{3} [ :0
Package: logcheck
Version: 1.2.34
Severity: normal
the ignore.d.server pattern for courier 'imaplogin: DISCONNECTED' does
not match the following line:
Feb 12 16:19:47 backup imaplogin: DISCONNECTED,
[EMAIL PROTECTED], ip=[:::111.111.111.111],
headers=14013, body=0, time=1
This line should b
Package: logcheck
Version: 1.2.34
Severity: normal
logcheck is reporting all 'Logout' messages from pure-ftpd. the pattern
in ignore.d.server for pure-ftpd is not matching. the 'Logout' messages
in syslog are in the following format:
Feb 10 08:42:28 web1 pure-ftpd: ([EMAIL PROTECTED]) [INFO]
Logo
15 matches
Mail list logo