Re: Logwatch Dovecot Deliver Summary

"Klaipedaville on Google" <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <71EF4BD521EC49DF9849262DD5603882@Computer>
OK. I understand. The log directory is the same almost in every Linux 
distro. It's in /var/log/maillog in Debian as well. I have custom logfiles 
for my Dovecot. They are also located in /var/log and called dovecot.log and 
dovecot-info.log. What I've have sent was parsed by Logwatch from my custom 
dovecot logs. The original maillog file looks like this:

May  9 13:39:16 klaipedaville postfix/qmgr[13650]: 67A6E5F492: removed
May  9 15:38:34 klaipedaville postfix/master[13631]: terminating on signal 
15
May  9 15:39:37 klaipedaville postfix/smtpd[20321]: connect from 
www554.hostpc.com[208.85.3.226]
May  9 15:39:37 klaipedaville postfix/smtpd[20321]: ACE2F5E044: 
client=www554.hostpc.com[208.85.3.226]
May  9 15:39:37 klaipedaville postfix/cleanup[20326]: ACE2F5E044: 
message-id=<5EF8D9A41E6940B5A4245960892EEF20@Computer>
May  9 15:39:37 klaipedaville postfix/qmgr[20305]: ACE2F5E044: 
from=<info-jd1zGDH2eM+tTU+SVyu7EgC/[email protected]>, size=2097, nrcpt=1 (queue active)
May  9 15:39:37 klaipedaville spamd[26593]: spamd: connection from 
localhost.localdomain [127.0.0.1] at port 52780
May  9 15:39:37 klaipedaville spamd[26593]: spamd: processing message 
<5EF8D9A41E6940B5A4245960892EEF20@Computer> for [email protected]:7001
May  9 15:39:37 klaipedaville postfix/smtpd[20321]: disconnect from 
www554.hostpc.com[208.85.3.226]
May  9 15:39:39 klaipedaville spamd[26593]: spamd: clean message (0.0/5.0) 
for [email protected]:7001 in 1.3 seconds, 2125 bytes.
May  9 15:39:39 klaipedaville spamd[26593]: spamd: result: . 0 - 
HTML_MESSAGE,SPF_PASS,T_DKIM_INVALID 
scantime=1.3,size=2125,[email protected],uid=7001,required_score=5.0,rhost=localhost.localdomain,raddr=127.0.0.1,rport=52780,mid=<5EF8D9A41E6940B5A4245960892EEF20@Computer>,autolearn=ham
May  9 15:39:39 klaipedaville spamd[26592]: prefork: child states: II
May  9 15:39:39 klaipedaville postfix/pipe[20327]: ACE2F5E044: 
to=<[email protected]>, relay=dovecot-spamass, delay=1.7, 
delays=0.28/0/0/1.5, dsn=2.0.0, status=sent (delivered via dovecot-spamass 
service)
May  9 15:39:39 klaipedaville postfix/qmgr[20305]: ACE2F5E044: removed
May  9 15:42:57 klaipedaville postfix/anvil[20324]: statistics: max 
connection rate 1/60s for (smtp:208.85.3.226) at May  9 15:39:37
May  9 15:42:57 klaipedaville postfix/anvil[20324]: statistics: max 
connection count 1 for (smtp:208.85.3.226) at May  9 15:39:37
May  9 15:42:57 klaipedaville postfix/anvil[20324]: statistics: max cache 
size 1 at May  9 15:39:37
May  9 16:01:34 klaipedaville postfix/pickup[20304]: B3FE9622DC: uid=115 
from=<logcheck>
May  9 16:01:34 klaipedaville postfix/cleanup[23153]: B3FE9622DC: 
message-id=<20140509130134.B3FE9622DC-koArGuWC/1Fl4O6Odmo/[email protected]>
May  9 16:01:34 klaipedaville postfix/qmgr[20305]: B3FE9622DC: 
from=<[email protected]>, size=26794, nrcpt=1 (queue active)
May  9 16:01:34 klaipedaville spamd[26593]: spamd: connection from 
localhost.localdomain [127.0.0.1] at port 52782
May  9 16:01:38 klaipedaville spamd[26593]: spamd: clean message (-0.0/5.0) 
for [email protected]:7001 in 3.7 seconds, 26594 bytes.
May  9 16:01:38 klaipedaville spamd[26593]: spamd: result: . 0 - NO_RELAYS

Regards,
Dennis.



-----Original Message----- 
From: Orion Poplawski
Sent: Friday, May 9, 2014 19:16
To: Klaipedaville on Google ; logwatch-devel
Subject: Re: [Logwatch-devel] Logwatch Dovecot Deliver Summary

On 05/09/2014 10:13 AM, Klaipedaville on Google wrote:
> Hello Orion,
>
> Thank you so much for replying.
>
> What do you mean by original logfile? This is my original logfile. I just
> changed [email protected] Do you want my real domain name? Please, 
> specify.
> Thanks.
>
> Regards,
> Dennis.
>

You've sent the output from logwatch.  But logwatch parses *logfiles*.  I 
need
a few corresponding lines from the logfile.  Not sure what it is on Debian.
On redhat it's /var/log/maillog.

- Orion

> -----Original Message----- From: Orion Poplawski
> Sent: Friday, May 9, 2014 18:45
> To: Klaipedaville on Google ; logwatch-devel
> Subject: Re: [Logwatch-devel] Logwatch Dovecot Deliver Summary
>
> On 05/08/2014 10:36 PM, Klaipedaville on Google wrote:
>> Hello there,
>> I was wondering and would be really grateful if you could please, advise 
>> on
>> the following.
>> Logwatch 7.4.0 (released 11/08/13) in combination with Dovecot 2.1.7 
>> installed
>> on Debian Wheezy.
>> I have Logwatch reporting dovecot service with each connection / saved 
>> mail
>> per line as shown below. Now each line represents a separate connection 
>> as far
>> as I understand and if I have for example 50 000 connections per day I 
>> get 50
>> 000 lines in my daily Dovecot report. This is all that I receive for 
>> Dovecot,
>> no summaries, never.
>> --------------------- Dovecot Begin ------------------------
>>
>> **Unmatched Entries**
>> lda(mail <mailto:mail-3Q2Tfjf0mexWk0Htik3J/[email protected]>@mydomain. 
>> <mailto:mail@mydomain.>com):
>> Info: msgid=20140508183811.B746C622D3-i4yH9JU3wRtWVPTZF4YnfwC/[email protected]
>> <mailto:20140508183811.B746C622D3-i4yH9JU3wRtWVPTZF4YnfwC/[email protected]>: saved mail to 
>> INBOX: 1
>> Time(s)
>
> Can you post an example line from the original logfile?
>


-- 
Orion Poplawski
Technical Manager                     303-415-9701 x222
NWRA, Boulder/CoRA Office             FAX: 303-415-9702
3380 Mitchell Lane                       [email protected]
Boulder, CO 80301                   http://www.nwra.com 


------------------------------------------------------------------------------
Is your legacy SCM system holding you back? Join Perforce May 7 to find out:
&#149; 3 signs your SCM is hindering your productivity
&#149; Requirements for releasing software faster
&#149; Expert tips and advice for migrating your SCM now
http://p.sf.net/sfu/perforce
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.