Re: stunnel filter

"Stefan Jakobs" <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
Jonas Marczona wrote:
> Hello,

Hello Jonas,

I reworked your patch and checked it in as revision 98. Please check if it 
still works as intended.

Thanks
Stefan

> we use stunnel 4.15 on CentOs 5.7.
> Yes its old, but this is what we get from the CentOs repos. This traffic is
> behind a firewall - so medium security acceptable for us.
> 
> *Format mismatch*
> Sadly the output from stunnel is not matched from the logwatch filter.
> 
> Example output (hostname and ips anonymized):
> Dec 29 12:35:09 hostname stunnel: LOG3[2411:3086588816]: SSL_read:
> Connection reset by peer (104)
> Dec 30 20:22:37 hostname stunnel: LOG5[2411:3084352400]: Connection closed:
> 829 bytes sent to SSL, 403 bytes sent to socket
> Dec 31 08:31:52 hostname stunnel: LOG5[2411:3084143504]: Connection reset:
> 7571653 bytes sent to SSL, 80209 bytes sent to socket
> Dec 31 11:43:27 hostname stunnel: LOG5[2411:3084143504]: uals connected
> from xx.xx.xx.111:49254
> Dec 31 11:44:00 hostname stunnel: LOG5[2411:3084352400]: uals connected
> from xx.xx.xx.111:49261
> Dec 31 11:45:08 hostname stunnel: LOG5[2411:3084352400]: Connection closed:
> 829 bytes sent to SSL, 403 bytes sent to socket
> Dec 31 11:56:59 hostname stunnel: LOG5[2411:3084143504]: Connection closed:
> 7199827 bytes sent to SSL, 136049 bytes sent to socket
> 
> The part "LOG5[2411:3084143504]:" is not expected by the current filter.
> I have extended some if-conditions with an "or"-block to match this format.
> The matching of "connected from" is reduced to services without spaces in
> their name. I do not know if stunnel support this at all.
> 
> *Reduced output for "allowed services"*
> In addition to this we are not interested to see each ip of each service.
> So i did extend the filter script to be sensitive to an environment
> variable "stunnelallowedservices"  - all services listed there (comma
> separated) will be summarized to "how often was this service used".
> independent of the ip. Obviously stunnelallowedservices could be set within
> "stunnel.conf"
> 
> Hopefully i does not changed anything if the other input-format is produced
> and stunnelallowedservices is not set.
> 
> Please find attached the diff and my complete version of the stunnel filter.
> 
> Regards,
> Jonas Marczona

------------------------------------------------------------------------------
For Developers, A Lot Can Happen In A Second.
Boundary is the first to Know...and Tell You.
Monitor Your Applications in Ultra-Fine Resolution. Try it FREE!
http://p.sf.net/sfu/Boundary-d2dvs2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.