Re: Bind Service & Script
"Klaipedaville on Google" <[email protected]> Thu, 19 Apr 2018 21:19:30 +0300
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <DA3893E83CED4249A5F9DCE4547F4F89@Computer> |
This is a multi-part message in MIME format.
--===============0410599137163527717==
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_001B_01D3D824.1AF01400"
This is a multi-part message in MIME format.
------=_NextPart_000_001B_01D3D824.1AF01400
Content-Type: text/plain;
charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hi Frank,
Thank you for replying.
Well, the "named module" that is the name script and service of Logwatch =
do not really parse the Bind9=E2=80=99s log files as I=E2=80=99ve =
mentioned in my first message before. Bind recommends custom logging =
because when you leave it "dropping" right into your syslog it does not =
really reflect the real picture so to speak. Now when you set it up as =
per Bind=E2=80=99s recommendations then there is nothing reported by =
Logwatch because there is nothing "dumped" into your syslog any more =
where Logwatch picks up "named module logging" from. That=E2=80=99s why =
I was asking if there were any work arounds to make Logwatch report on =
Bind9's?.. I thought that Bind=E2=80=99s script and service in Logwatch =
were required.. was I wrong? Thanks.
Regards,
Dennis
P.S. I provided log examples in my first email to try to parse it / feed =
it through "named module"... it did not work my side...
From: Frank Crawford=20
Sent: Thursday, April 19, 2018 15:05
To: Klaipedaville on Google ; logwatch-devel ; Orion Poplawski=20
Subject: Re: [Logwatch-devel] Bind Service & Script
Dennis,
Isn't the "named" module what you need? It does look through =
/var/log/messages for the output, not a dedicated bind file, but still =
it is what I see for my DNS server output.
Frank
On Wed, 2018-04-18 at 17:28 +0300, Klaipedaville on Google wrote:
Hello everybody, =20
I can=E2=80=99t believe it that the latest Logwatch 7.4.3 still does =
not have any Bind services and scripts. Am I wrong? I tried to "feed" =
bind9=E2=80=99s regular log files to named but it won=E2=80=99t parse =
them. Could anybody advise, please on how to make Logwatch "report" =
Bind? The standard / regular log files in Bind9 are setup like this:
logging {
channel bind_log {
file "/var/log/bind/bind.log" versions 3 size 5m;
severity info;
print-category yes;
print-severity yes;
print-time yes;
};
};
and what the logging produces as the outcome looks like this:
18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: query: =
ns2.barcap.com IN A + (1.2.3.4)
18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: query: =
a10-66.akam.net IN A + (1.2.3.4)
18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#52132: query: =
a9-66.akam.net IN A + (1.2.3.4)
18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#132: query: =
ns7.barcap.com IN A + (1.2.3.4)
18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: query: =
ns3.barcap.com IN A + (1.2.3.4)
18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: query: =
a1-71.akam.net IN A + (1.2.3.4)
18-Apr-2018 11:36:14.964 queries: info: client 1.12.3.4#52132: query: =
a12-64.akam.net IN A + (1.2.3.4)
I would be really grateful for any pointers, suggestions, =
recommendations, assistance.
Many thanks in advance!
Regards,
Dennis
=20
-------------------------------------------------------------------------=
-----
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! =
http://sdm.link/slashdot_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel
------=_NextPart_000_001B_01D3D824.1AF01400
Content-Type: text/html;
charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<HTML><HEAD></HEAD>
<BODY dir=3Dltr>
<DIV dir=3Dltr>
<DIV style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Calibri'; COLOR: #000000">
<DIV>Hi Frank,</DIV>
<DIV> </DIV>
<DIV>Thank you for replying.</DIV>
<DIV> </DIV>
<DIV>Well, the "named module" that is the name script and service of =
Logwatch do=20
not really parse the Bind9=E2=80=99s log files as I=E2=80=99ve mentioned =
in my first message=20
before. Bind recommends custom logging because when you leave it =
"dropping"=20
right into your syslog it does not really reflect the real picture so to =
speak.=20
Now when you set it up as per Bind=E2=80=99s recommendations then there =
is nothing=20
reported by Logwatch because there is nothing "dumped" into your syslog =
any more=20
where Logwatch picks up "named module logging" from. That=E2=80=99s why =
I was asking if=20
there were any work arounds to make Logwatch report on Bind9's?.. I =
thought that=20
Bind=E2=80=99s script and service in Logwatch were required.. was I =
wrong? Thanks.</DIV>
<DIV> </DIV>
<DIV>Regards,</DIV>
<DIV>Dennis</DIV>
<DIV> </DIV>
<DIV>P.S. I provided log examples in my first email to try to parse it / =
feed it=20
through "named module"... it did not work my side...</DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV=20
style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: normal; =
COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; DISPLAY: =
inline">
<DIV style=3D"FONT: 10pt tahoma">
<DIV><FONT size=3D3 face=3DCalibri></FONT> </DIV>
<DIV style=3D"BACKGROUND: #f5f5f5">
<DIV style=3D"font-color: black"><B>From:</B> <A =
[email protected]=20
href=3D"mailto:[email protected]">Frank Crawford</A> </DIV>
<DIV><B>Sent:</B> Thursday, April 19, 2018 15:05</DIV>
<DIV><B>To:</B> <A [email protected]=20
href=3D"mailto:[email protected]">Klaipedaville on Google</A> ; <A =
title=3Dlogwatch-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org=20
href=3D"mailto:[email protected]">logwatch-devel</A> =
; <A=20
[email protected] href=3D"mailto:[email protected]">Orion =
Poplawski</A> </DIV>
<DIV><B>Subject:</B> Re: [Logwatch-devel] Bind Service &=20
Script</DIV></DIV></DIV>
<DIV> </DIV></DIV>
<DIV=20
style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: normal; =
COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; DISPLAY: =
inline">
<DIV>Dennis,</DIV>
<DIV> </DIV>
<DIV>Isn't the "named" module what you need? It does look through=20
/var/log/messages for the output, not a dedicated bind file, but still =
it is=20
what I see for my DNS server output.</DIV>
<DIV> </DIV>
<DIV>Frank</DIV>
<DIV> </DIV>
<DIV>On Wed, 2018-04-18 at 17:28 +0300, Klaipedaville on Google =
wrote:</DIV>
<BLOCKQUOTE=20
style=3D"PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: =
#729fcf 2px solid"=20
type=3D"cite">
<DIV dir=3Dltr>
<DIV style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Calibri'; COLOR: =
#000000">
<DIV>Hello everybody, </DIV>
<DIV> </DIV>
<DIV>I can=E2=80=99t believe it that the latest Logwatch 7.4.3 still =
does not have any=20
Bind services and scripts. Am I wrong? I tried to "feed" =
bind9=E2=80=99s regular log=20
files to named but it won=E2=80=99t parse them. Could anybody advise, =
please on how to=20
make Logwatch "report" Bind? The standard / regular log files in Bind9 =
are=20
setup like this:</DIV>
<DIV> </DIV>
<DIV>logging {</DIV>
<DIV>channel bind_log {</DIV>
<DIV>file "/var/log/bind/bind.log" versions 3 size 5m;</DIV>
<DIV>severity info;</DIV>
<DIV>print-category yes;</DIV>
<DIV>print-severity yes;</DIV>
<DIV>print-time yes;</DIV>
<DIV> };</DIV>
<DIV>};</DIV>
<DIV> </DIV>
<DIV>and what the logging produces as the outcome looks like =
this:</DIV>
<DIV> </DIV>
<DIV>18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: =
query:=20
ns2.barcap.com IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: =
query:=20
a10-66.akam.net IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#52132: =
query:=20
a9-66.akam.net IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#132: =
query:=20
ns7.barcap.com IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: =
query:=20
ns3.barcap.com IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: =
query:=20
a1-71.akam.net IN A + (1.2.3.4)</DIV>
<DIV>18-Apr-2018 11:36:14.964 queries: info: client 1.12.3.4#52132: =
query:=20
a12-64.akam.net IN A + (1.2.3.4)</DIV>
<DIV> </DIV>
<DIV>I would be really grateful for any pointers, suggestions,=20
recommendations, assistance.</DIV>
<DIV> </DIV>
<DIV>Many thanks in advance!</DIV>
<DIV> </DIV>
<DIV>Regards,</DIV>
<DIV>Dennis</DIV>
<DIV>
<DIV=20
style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: =
normal; COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; =
DISPLAY: =
inline"></DIV> </DIV></DIV></DIV><PRE>------------------------------=
------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! <A =
href=3D"http://sdm.link/slashdot">http://sdm.link/slashdot</A></PRE><PRE>=
_______________________________________________
Logwatch-devel mailing list
<A =
href=3D"mailto:[email protected]">Logwatch-devel@lists=
.sourceforge.net</A>
<A =
href=3D"https://lists.sourceforge.net/lists/listinfo/logwatch-devel">http=
s://lists.sourceforge.net/lists/listinfo/logwatch-devel</A>
</PRE></BLOCKQUOTE></DIV></DIV></DIV></BODY></HTML>
------=_NextPart_000_001B_01D3D824.1AF01400--
--===============0410599137163527717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
--===============0410599137163527717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel
--===============0410599137163527717==--