Proftpd-Messages Unmatched Entries
"Klaipedaville on Google" <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <BA8751C6683E4C5C9FD527C0EB271C24@Computer> |
...update: re-sending it as I am now subscribed to the list. My up front apologies if this email is going to be received twice somehow. Hello, I would be really thankful if someone could give me a few pointers on proftpd-messages script of Logwatch 7.4.0 (11/08/13) run on Debian Wheezy stable. I’ll try to be concise. 1. I receive unmatched entries in my Logwatch daily mail that do hot have anything to do with proftpd at all, for example these are copy-pasted real lines: origin software="rsyslogd" swVersion="5.8.11" x-pid="2013" x-info="http://www.rsyslog.com"] rsyslogd was HUPed postgres (24373): /proc/24373/oom_adj is deprecated, please use /proc/24373/oom_score_adj instead warning: /etc/hosts.deny, line 138: can't verify hostname: getaddrinfo(212.51.174.61.dial.wz.zj.dynamic.163data.com.cn, AF_INET) I went through my proftpd log file that is "fed" to logwatch for parsing and it does not have anything like above-mentioned lines at all. Where does the script take these lines from? The proftpd's log file looks like this: Jul 27 12:54:47 host proftpd[19032] 1.2.3.4 (46.50.183.5[46.50.183.5]): FTP session opened. Jul 27 12:54:47 host proftpd[19032] 1.2.3.4 (46.50.183.5[46.50.183.5]): USER anonymous: no such user found from 46.50.183.5 [46.50.183.5] to ::ffff:1.2.3.4:21 Jul 27 12:54:48 host proftpd[19032] 1.2.3.4 (46.50.183.5[46.50.183.5]): FTP session closed. Jul 28 00:11:30 host proftpd[30483] 1.2.3.4 (173.230.157.41[173.230.157.41]): FTP session opened. Jul 28 15:48:02 host proftpd[11715] 1.2.3.4 (173.230.157.41[173.230.157.41]): FTP session opened. Jul 28 15:53:02 host proftpd[11715] 1.2.3.4 (173.230.157.41[173.230.157.41]): Login timeout exceeded, disconnected Jul 28 15:53:02 host proftpd[11715] 1.2.3.4 (173.230.157.41[173.230.157.41]): Session timed out, disconnected Jul 28 15:53:02 host proftpd[11715] 1.2.3.4 (173.230.157.41[173.230.157.41]): FTP session closed. 2. I went through every single line very carefully and in as much detail as possible in /scripts/services/proftpd-messages script and could not seem to find any tips or hints in code that would address anything else than regular proftpd log files. 3. Could you please, also advise the place where is the data for @OtherList variable declared? If I find it I may try to re-code it myself to fix my issues. I would highly appreciate any comments, suggestions, advices or any other help or assistance at all. Many thanks in advance! I thank you for your time and look forward to hearing from you soon. Regards, Dennis. P.S. I can do it via /etc/logwatch/conf/ignore.conf which is of course an option but it’s only a temporary workaround in my opinion, not a solution. ------------------------------------------------------------------------------ Want fast and easy access to all the code in your enterprise? Index and search up to 200,000 lines of code with a free copy of Black Duck Code Sight - the same software that powers the world's largest code search on Ohloh, the Black Duck Open Hub! Try it now. http://p.sf.net/sfu/bds _______________________________________________ Logwatch-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/logwatch-devel