Re: Logwatch Dovecot Deliver Summary
Orion Poplawski <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On 05/10/2014 08:12 AM, Klaipedaville on Google wrote:
> Hey Orion,
>
> Are there any more updates? Was my latest original dovecot-info.log file
> now 'feed-able' to Logwatch for parsing?
>
> Is there anything else you may need in order to advise on my further
> actions in search for solutions?
Bringing this back to the list.
So, I see you are using a very custom configuration which logwatch does
not handle (as you well know), but should be able to. You were quite
close, but the dovecot script needed some changes too.
See the attached files. Replace
/usr/share/logwatch/scripts/services/dovecot with the new dovecot
script. Install dovecot.conf into /etc/logwatch/conf/logfiles/dovecot.conf.
Then edit your /usr/share/logwatch/default.conf/services/dovecot.conf to
have:
# Which logfile group...
LogFile = dovecot
#*OnlyService = (imap-login|pop3-login|dovecot)
*RemoveHeaders = "^\w{3} .\d \d\d:\d\d:\d\d (?:[^\s:]* )?"
and see how that works for you.
I'm curious as to what the difference between the /var/log/dovecot.log
and /var/log/dovecot-info.log files is.
I tried putting the new services/dovecot.conf into
/etc/logwatch/conf/serivces, but then I ended up with a mish-mash of
both configs. Not sure what is going on there.
- Orion
>
> -----Original Message----- From: Klaipedaville on Google
> Sent: Saturday, May 10, 2014 00:22
> To: Orion Poplawski
> Subject: Re: [Logwatch-devel] Logwatch Dovecot Deliver Summary
>
> Well, I have just changed the logrotate as it had one duplicate entry for
> dovecot-info.log and restarted dovecot and postfix.
>
> Now the logs look a bit different but the entries "as if" from the
> output of
> Logwatch are still present. I have been there before as I had tried so many
> things for the past three days that it slipped my mind.
>
> Here's how the output from Logwatch log looks now:
>
> May 09 22:57:08 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22308, TLS,
> session=<GC2xAP346ABWZGD7>: 1 Time(s)
> May 09 22:57:26 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22310, TLS,
> session=<SRi/Af348ABWZGD7>: 1 Time(s)
> May 09 23:02:07 lda([email protected]): Info:
> msgid=<20140509200203.339255F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
> May 09 23:04:42 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=23346, TLS,
> session=<gwm4G/34/gBWZGD7>: 1 Time(s)
> May 09 23:04:47 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=23348, TLS,
> session=<GHwEHP34AgBWZGD7>: 1 Time(s)
> May 09 15:39:39 lda([email protected]): Info:
> msgid=<5EF8D9A41E6940B5A4245960892EEF20@Computer>: saved mail to INBOX: 1
> Time(s)
> May 09 16:11:24 lda([email protected]): Info:
> msgid=<20140509131124.796355F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
> May 09 17:02:02 lda([email protected]): Info:
> msgid=<20140509140202.4D6D25F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
> May 09 23:02:07 lda([email protected]): Info:
> msgid=<20140509200203.339255F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
>
> Here is how the "exact" output from my dovecot-info.log looks now:
>
> May 09 22:57:02 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22306, TLS,
> session=<LaRPAP345ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 22:57:08 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22308, TLS,
> session=<GC2xAP346ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 22:57:26 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22310, TLS,
> session=<SRi/Af348ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 22:57:29 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22306, TLS,
> session=<LaRPAP345ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 22:57:38 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22308, TLS,
> session=<GC2xAP346ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 22:57:56 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22310, TLS,
> session=<SRi/Af348ABWZGD7>: 1 Time(s)
> May 09 23:02:07 lda([email protected]): Info:
> msgid=<20140509200203.339255F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 23:27:02 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22306, TLS,
> session=<LaRPAP345ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 23:45:08 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22308, TLS,
> session=<GC2xAP346ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 23:57:26 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22310, TLS,
> session=<SRi/Af348ABWZGD7>: 1 Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
> May 09 23:58:29 pop3-login: Info: Login: user=<[email protected]>,
> method=PLAIN, rip=68.101.69.152, lip=99.157.35.122, mpid=22306, TLS,
> session=<LaRPAP345ABWZGD7>: 1 Time(s)
> May 09 23:58:07 lda([email protected]): Info:
> msgid=<20140509200203.339255F492@[email protected]>: saved mail to
> INBOX: 1
> Time(s)
> May 10 00:07:52 pop3([email protected]): Info: Disconnected: Logged out
> top=0/0, retr=0/0, del=0/1, size=2386
>
> Please, note that after checking / connecting / disconnecting it pops up
> this lda(... line anyway because it means which is pretty much obvious that
> the email safely arrived and was saved to my spool directory...
>
> I am beginning to think to start looking at my Dovecot configuration and
> re-check it thoroughly one more time. It's working OK though but chances
> are
> that there is something missing in there somewhere. I can't really think of
> anything else at the moment.. Do you have any more ideas? Many thanks,
> really appreciate your assistance!
>
> Regards,
> Dennis.
>
>
> -----Original Message----- From: Orion Poplawski
> Sent: Friday, May 9, 2014 22:36
> To: Klaipedaville on Google
> Subject: Re: [Logwatch-devel] Logwatch Dovecot Deliver Summary
>
> On 05/09/2014 12:43 PM, Klaipedaville on Google wrote:
>> Thank you so much for responding and for giving it a try to help.
>>
>> I think I have to break it into steps as I have been experimenting with
>> it for three days and gradually starting to get lost and go crazy..
>
> Thanks for the details, now we are getting somewhere. But:
>
>> 4. The custom logfile dovecot-info.log is absolutely the same as the
>> output from Logwatch.
>>
>> here is dovecot-info.log:
>>
>> **Unmatched Entries**
>> lda(mail <mailto:mail-3Q2Tfjf0mexWk0Htik3J/[email protected]>@mydomain.
>> <mailto:mail@mydomain.>com): Info:
>> msgid=20140508183811.B746C622D3-i4yH9JU3wRtWVPTZF4YnfwC/[email protected]
>> <mailto:20140508183811.B746C622D3-i4yH9JU3wRtWVPTZF4YnfwC/[email protected]>: saved mail to
>> INBOX: 1 Time(s)
>
> I'm sure this isn't dovecot-info.log, but the logwatch output. Give me
> some lda lines *exactly* from dovecot-info.log.
>
--
Orion Poplawski
Technical Manager 303-415-9701 x222
NWRA/CoRA Division FAX: 303-415-9702
3380 Mitchell Lane [email protected]
Boulder, CO 80301 http://www.cora.nwra.com
------------------------------------------------------------------------------
"Accelerate Dev Cycles with Automated Cross-Browser Testing - For FREE
Instantly run your Selenium tests across 300+ browser/OS combos.
Get unparalleled scalability from the best Selenium testing platform available
Simple to use. Nothing to install. Get started now for free."
http://p.sf.net/sfu/SauceLabs
_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel
dovecot
(text/plain, 22.1 KB)
######################################################## # $Id: dovecot 159 2013-08-19 09:35:30Z stefjakobs $ ######################################################## # $Log: dovecot,v $ # Revision 1.18 2010/09/18 17:41:00 stefan # ignore: ssl-build-param # # Revision 1.17 2009/06/02 14:48:06 mike # Removed some periods that were in the Fedora patch and broke the file -mgt # # Revision 1.16 2009/06/02 14:45:48 mike # Patch from Fedora (Ivana Hutarova Varekova) -mgt # # Revision 1.15 2008/11/18 06:02:49 mike # Rolled back..that was wrong. -mgt # # Revision 1.14 2008/11/18 06:00:34 mike # Removed a space should be better -mgt # # Revision 1.13 2008/11/18 04:32:49 mike # Added bytes detected to IMAP disconnect match expect more issues -mgt # # Revision 1.12 2008/08/11 15:38:02 mike # Connection closed patch from Niels Baggesen -mgt # # Revision 1.11 2008/06/30 23:07:51 kirk # fixed copyright holders for files where I know who they should be # # Revision 1.10 2008/03/24 23:31:26 kirk # added copyright/license notice to each script # # Revision 1.9 2008/02/14 18:19:51 mike # Patch from Gilles Detillieux summarize pop3/imap -mgt # # Revision 1.8 2008/01/16 20:11:04 bjorn # Filtering dovecot start-up message, by Gilles Detillieux. # # Revision 1.7 2007/06/18 03:54:45 bjorn # Better printing of IPv6 addresses, by Patrick Vande Walle. # # Revision 1.6 2007/03/17 19:13:13 bjorn # Now handling dovecot starts/kills. # # Revision 1.5 2006/12/20 15:25:09 bjorn # Additional filtering, by Ivana Varekova. # # Revision 1.4 2006/08/13 22:02:31 bjorn # IPv4 addresses displayed in native format, and don't display user totals # if user connects from only one IP address; changes by Patrick Vande Walle. # # Revision 1.3 2006/08/13 21:06:33 bjorn # Added support for Dovecot 1.0 based on patches from Mark Nienberg, and # IP addresses displayed without brackets for consistency across versions; # modifications by Patrick Vande Walle. # # Revision 1.2 2005/12/07 04:31:44 bjorn # Added $dovecot_ignore_host. # # Revision 1.1 2005/09/18 17:01:05 bjorn # Dovecot filters written by Patrick Vande Walle. # ######################################################## # Please send all comments, suggestions, bug reports, # etc, to [email protected] ######################################################## # The Dovecot script was written by: # Patrick Vande Walle <[email protected]> # Based on previous work by # Pawel Golaszewski <[email protected]> # # TODO: # - use printf features to align text in table # ######################################################## ######################################################## ## Copyright (c) 2008 Patrick Vande Walle ## Covered under the included MIT/X-Consortium License: ## http://www.opensource.org/licenses/mit-license.php ## All modifications and contributions by other persons to ## this script are assumed to have been donated to the ## Logwatch project and thus assume the above copyright ## and licensing terms. If you want to make contributions ## under your own copyright or a different license this ## must be explicitly stated in the contribution an the ## Logwatch project reserves the right to not accept such ## contributions. If you have made significant ## contributions to this script and want to claim ## copyright please contact [email protected] ######################################################### my $Debug = $ENV{'LOGWATCH_DEBUG'} || 0; my $Detail = $ENV{'dovecot_detail'} || $ENV{'LOGWATCH_DETAIL_LEVEL'} || 0; my $IgnoreHost = $ENV{'dovecot_ignore_host'} || ""; my $Restarts = 0; my $End = 0; if ( $Debug >= 5 ) { print STDERR "\n\nDEBUG \n\n"; } use Socket; my $rdns = {}; sub hostName { (my $ipaddr) = @_; if ($ENV{'LOGWATCH_NUMERIC'} || $ENV{'dovecot_numeric'}) { return $ipaddr; } if (exists $rdns{ $ipaddr }) { return $rdns{ $ipaddr }; } $rdns{ $ipaddr } = $ipaddr; my $iaddr = inet_aton($ipaddr); if (defined $iaddr) { my $host = gethostbyaddr($iaddr, AF_INET); if (defined $host) { my $iaddrcheck = gethostbyname($host); if (defined $iaddrcheck) { if ($iaddr == $iaddrcheck) { $rdns{ $ipaddr } = $host; } } } } return $rdns{ $ipaddr }; } # Handle "dovecot: <svc>" and "dovecot: [ID yyyyy mail.info] <svc" my $dovecottag = qr/dovecot:(?:\s*\[[^]]+\])?/; while (defined($ThisLine = <STDIN>)) { # remove timestamp. We can't use *RemoveHeaders because we need the # service name #$ThisLine =~ s/^\w{3} .\d \d\d:\d\d:\d\d (?:[^\s:]* |)//; if ( ($ThisLine =~ /(?:ssl-build-param|ssl-params): SSL parameters regeneration completed/) or ($ThisLine =~ /ssl-params: Generating SSL parameters/) or ($ThisLine =~ /auth-worker/) or ($ThisLine =~ /auth:.*: Connected to/) or ($ThisLine =~ /Connection closed/) or ($ThisLine =~ /IMAP.*: Connection closed bytes/) or ($ThisLine =~ /IMAP.* failed with mbox file/) or ($ThisLine =~ /discarded duplicate forward to/) or ($ThisLine =~ /discarding vacation response/) ) { # We don't care about these } elsif ( $ThisLine =~ /Killed with signal /) { $End++; } elsif ( $ThisLine =~ /Dovecot (v\d[^ ]* |)starting up( \(core dumps disabled\))?$/) { $Restarts++; $End = 0; } elsif ( ( ($User, $Host) = ( $ThisLine =~ /^pop3-login: Login: (.*?) \[(.*)\]/ ) ) or ( ($User, $Host) = ( $ThisLine =~ /^pop3-login: Info: Login: user=\<(.*?)\>.*rip=(.*)\, lip=/ ) ) ) { if ($Host !~ /$IgnoreHost/) { $Host = hostName($Host); $Login{$User}{$Host}++; $LoginPOP3{$User}++; $ConnectionPOP3{$Host}++; $Connection{$Host}++; } } elsif ( ( ($User, $Host) = ( $ThisLine =~ /^imap-login: Login: (.*?) \[(.*)\]/ ) ) or ( ($User, $Host) = ( $ThisLine =~ /^imap-login: Info: Login: user=\<(.*?)\>.*rip=(.*)\, lip=/ ) ) ) { if ($Host !~ /$IgnoreHost/) { $Host = hostName($Host); $Login{$User}{$Host}++; $LoginIMAP{$User}++; $ConnectionIMAP{$Host}++; $Connection{$Host}++; } } elsif ( ($User, $Host) = ( $ThisLine =~ /managesieve-login: Login: user=\<(.*?)\>.*rip=(.*)\, lip=/ ) ) { if ($Host !~ /$IgnoreHost/) { $Host = hostName($Host); $SieveLogin{$User}{$Host}++; $LoginSieve{$User}++; $ConnectionSieve{$Host}++; $Connection{$Host}++; } # 'lda' for dovecot 2.0, 'deliver' for earlier versions } elsif ( ($User, $Mailbox) = ( $ThisLine =~ /^(?:$dovecottag )?(?:lda|deliver)\((.*)\):(?: Info:)? msgid=.*: saved mail to (\S+)/ ) ) { $Deliver{$User}{$Mailbox}++; # For Sieve-based delivery } elsif ( ($User, $Mailbox) = ( $ThisLine =~ /^(?:$dovecottag )?(?:lda\(|deliver\(|lmtp\(\d+, )(.*)\): (?:[^:]+: )?sieve: msgid=.*: stored mail into mailbox '([^']*)'/ ) ) { $Deliver{$User}{$Mailbox}++; # LMTP-based delivery } elsif ( ($User, $Mailbox) = ( $ThisLine =~ /^(?:$dovecottag )?lmtp\(\d+, (.*)\): [^:]+: msgid=.*: saved mail to (\S+)/ ) ) { # dovecot: [ID 583609 mail.info] lmtp(12782, [email protected]): jBt1EfjCMk3uMQAAm9eMBA: msgid=<[email protected]>: saved mail to INBOX $Deliver{$User}{$Mailbox}++; # sieve forward } elsif (($User, $Recip) = ($ThisLine =~ /^(?:$dovecottag )?(?:lda|deliver)\((.*)\): sieve: msgid=.* forwarded to \<(.*)\>/)) { $Forwarded{$User}{$Recip}++; # sieve vacation } elsif (($User, $Recip) = ($ThisLine =~ /^(?:$dovecottag )?(?:lda|deliver)\((.*)\): sieve: msgid=.* sent vacation response to \<(.*)\>/)) { $VacationResponse{$User}{$Recip}++; } elsif (($User, $Recip) = ($ThisLine =~ /^(?:$dovecottag )?(?:lda|deliver)\((.*)\): sieve: msgid=.* discarded duplicate vacation response to \<(.*)\>/ )) { $VacationDup{$User}{$Recip}++; } elsif ( $ThisLine =~ /^(?:$dovecottag )?(?:lda|deliver)\(.*\): sieve: msgid=.* marked message to be discarded if not explicitly delivered/ ) { # dovecot: lda(joe): sieve: msgid=<m$01$@com>: marked message to be discarded if not explicitly delivered (discard action) # IGNORE } elsif ( $ThisLine =~ /^(?:$dovecottag )?lmtp\(.*\): Connect from/ ) { # dovecot: [ID 583609 mail.info] lmtp(12782): Connect from local: 1 Time(s) # IGNORE } elsif ( $ThisLine =~ /^(?:$dovecottag )?lmtp\(.*\): Disconnect from/ ) { # dovecot: [ID 583609 mail.info] lmtp(12782): Disconnect from local: Client quit: 1 Time(s) # IGNORE # This is for Dovecot 1.0 series } elsif ( ($User, $Host) = ( $ThisLine =~ /^(?:$dovecottag )?pop3-login: Login: user=\<(.*?)\>.*rip=(.*)\, lip=/ ) ) { if ($Host !~ /$IgnoreHost/) { $Host = hostName($Host); $Login{$User}{$Host}++; $LoginPOP3{$User}++; $ConnectionPOP3{$Host}++; $Connection{$Host}++; } } elsif ( ($User, $Host) = ( $ThisLine =~ /^(?:$dovecottag )?imap-login: Login: user=\<(.*?)\>.*rip=(.*)\, lip=/) ) { if ($Host !~ /$IgnoreHost/) { $Host = hostName($Host); $Login{$User}{$Host}++; $LoginIMAP{$User}++; $ConnectionIMAP{$Host}++; $Connection{$Host}++; } # Dovecot 2.0 proxy } elsif ( ($User, $Host) = ( $ThisLine =~ /^(?:$dovecottag )?pop3-login: proxy\((.*)\): started proxying to .*: user=<.*>, method=.*, rip=(.*), lip=/ ) ) { if ($Host !~ /$IgnoreHost/) { $ProxyLogin{$User}{$Host}++; $ProxyLoginPOP3{$User}++; $ProxyConnectionPOP3{$Host}++; $ProxyConnection{$Host}++; } } elsif ( ($User, $Host) = ( $ThisLine =~ /^(?:$dovecottag )?imap-login: proxy\((.*)\): started proxying to .*: user=<.*>, method=.*, rip=(.*), lip=/ ) ) { if ($Host !~ /$IgnoreHost/) { $ProxyLogin{$User}{$Host}++; $ProxyLoginIMAP{$User}++; $ProxyConnectionIMAP{$Host}++; $ProxyConnection{$Host}++; } } elsif ( ($Reason) = ( $ThisLine =~ /proxy\(.*\): disconnecting .* \(Disconnected (.*)\)/ ) ) { $ProxyDisconnected{$Reason}++; } elsif ($ThisLine =~ /Disconnected (\[|top)/) { $Disconnected{"no reason"}++; } elsif (($Reason) = ($ThisLine =~ /Disconnected: (.*) \[/) ) { $Disconnected{$Reason}++; } elsif (($Reason) = ($ThisLine =~ /Disconnected: (.*) (bytes|top)=.*/) ) { $Disconnected{$Reason}++; } elsif (($Reason) = ($ThisLine =~ /Disconnected \((.*)\):/) ) { $Disconnected{$Reason}++; } elsif ($ThisLine =~ /Disconnected (bytes|top)=.*/) { $Disconnected{"No reason"}++; } elsif (($Reason, $Host) = ($ThisLine =~ /TLS initialization failed/) ) { $TLSInitFail++; } elsif (($Host) = ($ThisLine =~ /Aborted login:.* rip=(.*),/) ) { $Host = hostName($Host); $Aborted{$Host}++; } elsif (($Host) = ($ThisLine =~ /Aborted login \[(.*)\]/) ) { $Host = hostName($Host); $Aborted{$Host}++; } elsif (($Reason) = ($ThisLine =~ /Aborted login \((.*)\):/)) { $Aborted{$Reason}++; } elsif (($user, $rip, $lip) = ($ThisLine =~ /Maximum number of connections.* exceeded.* user=<([^>]+)>.*rip=([^,]+), lip=([^,]+)/)) { # dovecot: [ID 583609 mail.info] imap-login: Maximum number of connections from user+IP exceeded (mail_max_userip_connections=10): user=<[email protected]>, method=CRAM-MD5, rip=102.225.17.52, lip=14.105.322.67, TLS $LimitExceeded{"max_userip_connections: $user from $rip to $lip"}++; # This is for Dovecot 1.0 series # Overly general matches in this section -mgt } elsif ($ThisLine =~ /Disconnected for inactivity/) { $Disconnected{"Inactivity"}++; } elsif ($ThisLine =~ /Disconnected in IDLE/) { $Disconnected{"in IDLE"}++; } elsif ($ThisLine =~ /Disconnected in APPEND/) { $Disconnected{"in APPEND"}++; } elsif (($ThisLine =~ /Disconnected$/) or ($ThisLine =~ /(IMAP|POP3)\(.+\): Disconnected (bytes|top|rip|user|method)=/) or ($ThisLine =~ /(imap\-login|pop3\-login): Disconnected: (bytes|top|rip|user|method)=/) ) { $Disconnected{"no reason"}++; } elsif ( (($Reason) = ($ThisLine =~ /(?:IMAP|POP3).+: Disconnected: (.+) (bytes|top)=/i)) or (($Reason) = ($ThisLine =~ /(?:imap\-login|pop3\-login): Disconnected: \(?(.+)\)?: /)) or #This one should go away also -mgt (($Reason) = ($ThisLine =~ /IMAP.+: Disconnected: (.+)/i)) ) { $Disconnected{$Reason}++; } elsif ($ThisLine =~ /(IMAP|POP3).+: Connection closed (top|bytes)=/i) { $ConnectionCl{"no reason"}++; } elsif ( ($Reason) = ($ThisLine =~ /(?:IMAP|POP3).+: Connection closed: (.*) (?:bytes|method|top|rip|user)=/i) ) { $ConnectionCl{$Reason}++; } elsif ($ThisLine =~ /(IMAP|POP3).+: (Connection closed.*)/) { $Disconnected{$2}++; } elsif (($Host) = ($ThisLine =~ /(?:imap\-login|pop3\-login): Aborted login: .*rip=(?:::ffff:)?(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})/) ) { $Aborted{$Host}++; } elsif (($Error) = ($ThisLine =~ /child \d* (?:\(login\) )?returned error (.*)/)) { # dovecot: child 23747 (login) returned error 89 # dovecot: log: Error: service(auth): child 19654 returned error 89 (Fatal failure) $ChildErr{$Error}++; } elsif (($Name) = ($ThisLine =~ /(?:$dovecottag )?IMAP\((.*)\): .*(.*) failed: Disk quota exceeded/i)) { # dovecot: IMAP(podracka): mkdir(/home/LF/KLINIKY/podracka/mail/.imap/saved-messages) failed: Disk quota exceeded $DiskQuotaExceed{$Name}++; } else { # Report any unmatched entries... chomp($ThisLine); $OtherList{$ThisLine}++; } } ################################################ if ( $End ) { print "\nDovecot was killed, and not restarted afterwards.\n"; } if ( ( $Detail >=5 ) and $Restarts ) { print "\nDovecot restarted $Restarts time(s).\n"; } if ( ( $Detail >= 5 ) and (keys %Connection)) { print "\n[Dovecot IMAP and POP3] Connections:". "\n====================================". "\nPOP3 IMAP Total Host". "\n" . "-" x 72; $TLSInitFail = 0; foreach $Host (sort { $Connection{$b} <=> $Connection{$a} } keys %Connection) { $Total = $Connection{$Host}; if (defined ($ConnectionPOP3{$Host})) { $Conns = $ConnectionPOP3{$Host}; } else { $Conns = 0; } if (defined ($ConnectionIMAP{$Host})) { $IMAP = $ConnectionIMAP{$Host}; } else { $IMAP = 0; } # Cleanly display IPv4 addresses $Host=~ s/::ffff://; printf "\n%4s %4s %5s %s", $Conns, $IMAP, $Total, $Host; $POP3Count += $Conns; $IMAPCount += $IMAP; $TotalCount += $Total; } print "\n" . "-" x 72; printf "\n%4s %4s %5s %s", $POP3Count, $IMAPCount, $TotalCount, "Total"; } if (keys %Deliver) { my $DeliverCount = 0; my $DeliverUserCount = {}; foreach my $User (keys %Deliver) { foreach my $Mailbox (keys %{$Deliver{$User}}) { $DeliverUserCount{$User} += $Deliver{$User}{$Mailbox}; } $DeliverCount += $DeliverUserCount{$User}; } printf "\n" if ($Detail >= 5); printf "\nDovecot Deliveries: %s", $DeliverCount; if ($Detail >= 5) { foreach my $User (sort { $DeliverUserCount{$b} <=> $DeliverUserCount{$a} } keys %DeliverUserCount) { printf "\n %4s %s", $DeliverUserCount{$User}, $User; if ($Detail >= 10) { foreach my $Mailbox (sort { $Deliver{$User}{$b} <=> $Deliver{$User}{$a} } keys %{$Deliver{$User}}) { printf "\n %4s %s", $Deliver{$User}{$Mailbox}, $Mailbox; } } } } } if (($Detail >= 10) and (keys %Forwarded)) { $TotalForwarded = 0; print "\n\nDovecot LDA sieve forwards:"; foreach $User (sort keys %Forwarded) { print "\n\n User $User"; foreach my $Recip (sort keys %{$Forwarded{$User}}) { print "\n To $Recip: $Forwarded{$User}{$Recip} time(s)"; $TotalForwarded += $Forwarded{$User}{$Recip}; } } print "\n\n Total: $TotalForwarded Time(s)"; } if (($Detail >= 10) and (keys %VacationResponse)) { $TotalVacResp = 0; print "\n\nDovecot LDA sieve vacation responses:"; foreach my $User (sort keys %VacationResponse) { print "\n\n User $User"; foreach my $Recip (sort keys %{$VacationResponse{$User}}) { print "\n To $Recip: $VacationResponse{$User}{$Recip} time(s)"; $TotalVacResp += $VacationResponse{$User}{$Recip}; } } print "\n\n Total: $TotalVacResp Time(s)"; } if (($Detail >= 10) and (keys %VacationDup)) { $TotalVacDup = 0; print "\n\nDovecot LDA sieve duplicate vacation responses not sent:"; foreach my $User (sort keys %VacationDup) { print "\n User $User"; foreach my $Recip (sort keys %{$VacationDup{$User}}) { print "\n To $Recip: $VacationDup{$User}{$Recip} time(s)"; $TotalVacDup += $VacationDup{$User}{$Recip}; } } print "\n\n Total: $TotalVacDup Time(s)"; } if (keys %Login) { my $LoginCount = 0; my $LoginUserCount = {}; foreach my $User (keys %Login) { foreach my $Host (keys %{$Login{$User}}) { $LoginUserCount{$User} += $Login{$User}{$Host}; } $LoginCount += $LoginUserCount{$User}; $LoginPOP3{$User} = 0 if $LoginPOP3{$User} <= 0; $LoginIMAP{$User} = 0 if $LoginIMAP{$User} <= 0; } printf "\n" if ($Detail >= 5); printf "\nDovecot IMAP and POP3 Successful Logins: %s", $LoginCount; if ($Detail >= 5) { foreach my $User (sort { $LoginUserCount{$b} <=> $LoginUserCount{$a} } keys %LoginUserCount) { printf("\n %4s %s", $LoginUserCount{$User}, $User); if ($Detail >= 10) { printf(" (%s POP3, %s IMAP)", $LoginPOP3{$User}, $LoginIMAP{$User}); foreach my $Host (sort { $Login{$User}{$b} <=> $Login{$User}{$a} } keys %{$Login{$User}}) { $HostCount = $Login{$User}{$Host}; # Cleanly display IPv4 addresses $Host=~ s/::ffff://; printf "\n %4s %s", $Login{$User}{$Host}, $Host; } } } } } if ( ( $Detail >= 10 ) and (keys %SieveLogin)) { print "\n\nDovecot ManageSieve Successful Logins:"; $LoginCount = 0; foreach my $User (sort keys %SieveLogin) { print "\n\n User $User:"; $UserCount = 0; $NumHosts = 0; foreach $Host (sort keys %{$SieveLogin{$User}}) { $NumHosts++; $HostCount = $SieveLogin{$User}{$Host}; # Cleanly display IPv4 addresses $Host=~ s/::ffff://; print "\n From $Host: $HostCount Time(s)"; $UserCount += $HostCount; } $LoginCount += $UserCount; if ($NumHosts > 1) { print "\n Total: $UserCount Time(s)"; } } print "\n\nTotal: $LoginCount successful ManageSieve logins"; } if (keys %LimitExceeded) { print "\n\nDovecot limits exceeded:"; foreach my $Reason (sort keys %LimitExceeded) { print "\n $Reason: $LimitExceeded{$Reason} Time(s)"; } } if (keys %Disconnected) { my $Disconnects = 0; foreach my $Reason (%Disconnected) { $Disconnects += $Disconnected{$Reason}; } printf "\n" if ($Detail >= 5); printf "\nDovecot disconnects: %s", $Disconnects; if ($Detail >= 5) { foreach my $Reason (sort { $Disconnected{$b} <=> $Disconnected{$a} } keys %Disconnected) { printf "\n %4s %s", $Disconnected{$Reason}, $Reason; } } } if (keys %ConnectionCl) { print "\n\nDovecot connections closed:"; foreach my $Reason (sort keys %ConnectionCl) { print "\n $Reason: $ConnectionCl{$Reason} Time(s)"; } } if (keys %ChildErr) { print "\n\nDovecot child error:"; foreach my $Error (sort keys %ChildErr) { print "\n error number ". $Error . ": ". $ChildErr{$Error} ." Time(s)"; } } if ((keys %Aborted) && ($Detail >= 10)) { print "\n\nLogout/aborts:"; foreach my $Host (sort keys %Aborted) { print "\n $Host: $Aborted{$Host} Time(s)"; } } if ($TLSInitFail > 0) { print "\n\nTLS Initialization failed $TLSInitFail Time(s)"; } if (keys %DiskQuotaExceed) { print "\n\nDisk quota exceeded:"; foreach my $Name (sort keys %DiskQuotaExceed) { print "\n disk quota for user '". $Name . "' exceeded: ". $DiskQuotaExceed{$Name} ." Time(s)"; } } if ( ( $Detail >= 5 ) and (keys %ProxyLogin)) { print "\n\nDovecot Proxy IMAP and POP3 Successful Logins:"; $LoginCount = 0; foreach my $User (sort keys %ProxyLogin) { print "\n User $User:"; if ( ($Detail >= 10) and ($ProxyLoginPOP3{$User} > 0 || $ProxyLoginIMAP{$User} > 0) ) { print " ("; if ($ProxyLoginPOP3{$User} > 0) { print "$ProxyLoginPOP3{$User} POP3"; }; if ($ProxyLoginPOP3{$User} > 0 && $ProxyLoginIMAP{$User} > 0) { print "/"; }; if ($ProxyLoginIMAP{$User} > 0) { print "$ProxyLoginIMAP{$User} IMAP"; }; print ")"; } $UserCount = 0; $NumHosts = 0; foreach $Host (sort keys %{$ProxyLogin{$User}}) { $NumHosts++; $HostCount = $ProxyLogin{$User}{$Host}; # Cleanly display IPv4 addresses $Host=~ s/::ffff://; print "\n From $Host: $HostCount Time(s)" if ($Detail >= 10); $UserCount += $HostCount; } $LoginCount += $UserCount; if ($Detail >= 10) { if ($NumHosts > 1) { print "\n Total: $UserCount Time(s)\n"; } else { print "\n"; } } elsif ($Detail >= 5) { print " $UserCount Time(s)"; } } print "\nTotal: $LoginCount successful logins"; } if (keys %ProxyDisconnected) { print "\n\nDovecot Proxy disconnects:\n"; foreach my $Reason (sort keys %ProxyDisconnected) { print " $Reason: $ProxyDisconnected{$Reason} Time(s)\n"; } } if (keys %OtherList) { print "\n\n**Unmatched Entries**\n"; foreach $line (sort {$a cmp $b} keys %OtherList) { print " $line: $OtherList{$line} Time(s)\n"; } } exit(0); # vi: shiftwidth=3 tabstop=3 syntax=perl et # Local Variables: # mode: perl # perl-indent-level: 3 # indent-tabs-mode: nil # End:
dovecot.conf
(text/plain, 462 B)
# What actual file? Defaults to LogPath if not absolute path.... LogFile = dovecot-info.log # If the archives are searched, here is one or more line # (optionally containing wildcards) that tell where they are... #If you use a "-" in naming add that as well -mgt Archive = dovecot-info.log.* # Expand the repeats (actually just removes them now) *ExpandRepeats # Keep only the lines in the proper date range... *ApplyStdDate # vi: shiftwidth=3 tabstop=3 et