Re: stunnel filter
"Stefan Jakobs" <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
Jonas Marczona wrote: > Hello, Hello Jonas, I reworked your patch and checked it in as revision 98. Please check if it still works as intended. Thanks Stefan > we use stunnel 4.15 on CentOs 5.7. > Yes its old, but this is what we get from the CentOs repos. This traffic is > behind a firewall - so medium security acceptable for us. > > *Format mismatch* > Sadly the output from stunnel is not matched from the logwatch filter. > > Example output (hostname and ips anonymized): > Dec 29 12:35:09 hostname stunnel: LOG3[2411:3086588816]: SSL_read: > Connection reset by peer (104) > Dec 30 20:22:37 hostname stunnel: LOG5[2411:3084352400]: Connection closed: > 829 bytes sent to SSL, 403 bytes sent to socket > Dec 31 08:31:52 hostname stunnel: LOG5[2411:3084143504]: Connection reset: > 7571653 bytes sent to SSL, 80209 bytes sent to socket > Dec 31 11:43:27 hostname stunnel: LOG5[2411:3084143504]: uals connected > from xx.xx.xx.111:49254 > Dec 31 11:44:00 hostname stunnel: LOG5[2411:3084352400]: uals connected > from xx.xx.xx.111:49261 > Dec 31 11:45:08 hostname stunnel: LOG5[2411:3084352400]: Connection closed: > 829 bytes sent to SSL, 403 bytes sent to socket > Dec 31 11:56:59 hostname stunnel: LOG5[2411:3084143504]: Connection closed: > 7199827 bytes sent to SSL, 136049 bytes sent to socket > > The part "LOG5[2411:3084143504]:" is not expected by the current filter. > I have extended some if-conditions with an "or"-block to match this format. > The matching of "connected from" is reduced to services without spaces in > their name. I do not know if stunnel support this at all. > > *Reduced output for "allowed services"* > In addition to this we are not interested to see each ip of each service. > So i did extend the filter script to be sensitive to an environment > variable "stunnelallowedservices" - all services listed there (comma > separated) will be summarized to "how often was this service used". > independent of the ip. Obviously stunnelallowedservices could be set within > "stunnel.conf" > > Hopefully i does not changed anything if the other input-format is produced > and stunnelallowedservices is not set. > > Please find attached the diff and my complete version of the stunnel filter. > > Regards, > Jonas Marczona ------------------------------------------------------------------------------ For Developers, A Lot Can Happen In A Second. Boundary is the first to Know...and Tell You. Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! http://p.sf.net/sfu/Boundary-d2dvs2