SF.net SVN: logwatch:[215] scripts/services/pam_unix

[email protected] Mon, 8 Sep 2014 20:45:36 +0000
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
Revision: 215
          http://sourceforge.net/p/logwatch/code/215
Author:   stefjakobs
Date:     2014-09-08 20:45:36 +0000 (Mon, 08 Sep 2014)
Log Message:
-----------
pam_unix: Fix two unknown entries (Thanks: Willi Mann)

Modified Paths:
--------------
    scripts/services/pam_unix

Modified: scripts/services/pam_unix
===================================================================
--- scripts/services/pam_unix	2014-09-08 20:44:17 UTC (rev 214)
+++ scripts/services/pam_unix	2014-09-08 20:45:36 UTC (rev 215)
@@ -171,7 +171,8 @@
       } elsif ($line =~ s/^session opened for user (.+) by LOGIN\(uid=\d+\)/$1/) {
 	 $data{$service}{'Sessions Opened'}{$line}++;
       } elsif ($line =~ /session closed for user/) {
-	# ignore this line
+      } elsif ($line =~ /^service\(sshd\) ignoring max retries/) {
+	# ignore these lines
       } elsif ($line =~ s/^authentication failure; .*rhost=(\S*)\s+user=(\S*)$/$2 ($1)/) {
  	 $data{$service}{'Authentication Failures'}{$line}++;
       } elsif ($line =~ s/^authentication failure; .*rhost=(\S*)\s*$/unknown ($1)/) {
@@ -182,7 +183,7 @@
          $data{$service}{'Authentication Failures'}{$line}++;
       } elsif ($line =~ s/^(\d+) more authentication failures?; .*rhost=(\S*)\s+user=(\S*)$/$3 ($2)/) {
          $data{$service}{'Authentication Failures'}{$line} += $1;
-      } elsif ($line =~ s/^(\d+) more authentication failures?; .*rhost=(\S*)$/unknown ($2)/) {
+      } elsif ($line =~ s/^(\d+) more authentication failures?; .*rhost=(\S*)\s*$/unknown ($2)/) {
          $data{$service}{'Authentication Failures'}{$line} += $1;
       } elsif ($line =~ /check pass; user unknown/) {
          $data{$service}{'Invalid Users'}{'Unknown Account'}++;

This was sent by the SourceForge.net collaborative development platform, the world's largest Open Source development site.


------------------------------------------------------------------------------
Want excitement?
Manually upgrade your production database.
When you want reliability, choose Perforce
Perforce version control. Predictably reliable.
http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk