Re: Bind Service & Script

"Klaipedaville on Google" <[email protected]> Thu, 19 Apr 2018 21:19:30 +0300
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <DA3893E83CED4249A5F9DCE4547F4F89@Computer>
This is a multi-part message in MIME format.

--===============0410599137163527717==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_001B_01D3D824.1AF01400"

This is a multi-part message in MIME format.

------=_NextPart_000_001B_01D3D824.1AF01400
Content-Type: text/plain;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Frank,

Thank you for replying.

Well, the "named module" that is the name script and service of Logwatch =
do not really parse the Bind9=E2=80=99s log files as I=E2=80=99ve =
mentioned in my first message before. Bind recommends custom logging =
because when you leave it "dropping" right into your syslog it does not =
really reflect the real picture so to speak. Now when you set it up as =
per Bind=E2=80=99s recommendations then there is nothing reported by =
Logwatch because there is nothing "dumped" into your syslog any more =
where Logwatch picks up "named module logging" from. That=E2=80=99s why =
I was asking if there were any work arounds to make Logwatch report on =
Bind9's?.. I thought that Bind=E2=80=99s script and service in Logwatch =
were required.. was I wrong? Thanks.

Regards,
Dennis

P.S. I provided log examples in my first email to try to parse it / feed =
it through "named module"... it did not work my side...



From: Frank Crawford=20
Sent: Thursday, April 19, 2018 15:05
To: Klaipedaville on Google ; logwatch-devel ; Orion Poplawski=20
Subject: Re: [Logwatch-devel] Bind Service & Script

Dennis,

Isn't the "named" module what you need? It does look through =
/var/log/messages for the output, not a dedicated bind file, but still =
it is what I see for my DNS server output.

Frank

On Wed, 2018-04-18 at 17:28 +0300, Klaipedaville on Google wrote:
  Hello everybody, =20

  I can=E2=80=99t believe it that the latest Logwatch 7.4.3 still does =
not have any Bind services and scripts. Am I wrong? I tried to "feed" =
bind9=E2=80=99s regular log files to named but it won=E2=80=99t parse =
them. Could anybody advise, please on how to make Logwatch "report" =
Bind? The standard / regular log files in Bind9 are setup like this:

  logging {
  channel bind_log {
  file "/var/log/bind/bind.log" versions 3 size 5m;
  severity info;
  print-category yes;
  print-severity yes;
  print-time yes;
     };
  };

  and what the logging produces as the outcome looks like this:

  18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: query: =
ns2.barcap.com IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: query: =
a10-66.akam.net IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#52132: query: =
a9-66.akam.net IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#132: query: =
ns7.barcap.com IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: query: =
ns3.barcap.com IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: query: =
a1-71.akam.net IN A + (1.2.3.4)
  18-Apr-2018 11:36:14.964 queries: info: client 1.12.3.4#52132: query: =
a12-64.akam.net IN A + (1.2.3.4)

  I would be really grateful for any pointers, suggestions, =
recommendations, assistance.

  Many thanks in advance!

  Regards,
  Dennis
  =20
-------------------------------------------------------------------------=
-----
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! =
http://sdm.link/slashdot_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel

------=_NextPart_000_001B_01D3D824.1AF01400
Content-Type: text/html;
	charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD></HEAD>
<BODY dir=3Dltr>
<DIV dir=3Dltr>
<DIV style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Calibri'; COLOR: #000000">
<DIV>Hi Frank,</DIV>
<DIV>&nbsp;</DIV>
<DIV>Thank you for replying.</DIV>
<DIV>&nbsp;</DIV>
<DIV>Well, the "named module" that is the name script and service of =
Logwatch do=20
not really parse the Bind9=E2=80=99s log files as I=E2=80=99ve mentioned =
in my first message=20
before. Bind recommends custom logging because when you leave it =
"dropping"=20
right into your syslog it does not really reflect the real picture so to =
speak.=20
Now when you set it up as per Bind=E2=80=99s recommendations then there =
is nothing=20
reported by Logwatch because there is nothing "dumped" into your syslog =
any more=20
where Logwatch picks up "named module logging" from. That=E2=80=99s why =
I was asking if=20
there were any work arounds to make Logwatch report on Bind9's?.. I =
thought that=20
Bind=E2=80=99s script and service in Logwatch were required.. was I =
wrong? Thanks.</DIV>
<DIV>&nbsp;</DIV>
<DIV>Regards,</DIV>
<DIV>Dennis</DIV>
<DIV>&nbsp;</DIV>
<DIV>P.S. I provided log examples in my first email to try to parse it / =
feed it=20
through "named module"... it did not work my side...</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV=20
style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: normal; =
COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; DISPLAY: =
inline">
<DIV style=3D"FONT: 10pt tahoma">
<DIV><FONT size=3D3 face=3DCalibri></FONT>&nbsp;</DIV>
<DIV style=3D"BACKGROUND: #f5f5f5">
<DIV style=3D"font-color: black"><B>From:</B> <A =
[email protected]=20
href=3D"mailto:[email protected]">Frank Crawford</A> </DIV>
<DIV><B>Sent:</B> Thursday, April 19, 2018 15:05</DIV>
<DIV><B>To:</B> <A [email protected]=20
href=3D"mailto:[email protected]">Klaipedaville on Google</A> ; <A =

title=3Dlogwatch-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org=20
href=3D"mailto:[email protected]">logwatch-devel</A> =
; <A=20
[email protected] href=3D"mailto:[email protected]">Orion =
Poplawski</A> </DIV>
<DIV><B>Subject:</B> Re: [Logwatch-devel] Bind Service &amp;=20
Script</DIV></DIV></DIV>
<DIV>&nbsp;</DIV></DIV>
<DIV=20
style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: normal; =
COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; DISPLAY: =
inline">
<DIV>Dennis,</DIV>
<DIV>&nbsp;</DIV>
<DIV>Isn't the "named" module what you need? It does look through=20
/var/log/messages for the output, not a dedicated bind file, but still =
it is=20
what I see for my DNS server output.</DIV>
<DIV>&nbsp;</DIV>
<DIV>Frank</DIV>
<DIV>&nbsp;</DIV>
<DIV>On Wed, 2018-04-18 at 17:28 +0300, Klaipedaville on Google =
wrote:</DIV>
<BLOCKQUOTE=20
style=3D"PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: =
#729fcf 2px solid"=20
type=3D"cite">
  <DIV dir=3Dltr>
  <DIV style=3D"FONT-SIZE: 12pt; FONT-FAMILY: 'Calibri'; COLOR: =
#000000">
  <DIV>Hello everybody,&nbsp; </DIV>
  <DIV>&nbsp;</DIV>
  <DIV>I can=E2=80=99t believe it that the latest Logwatch 7.4.3 still =
does not have any=20
  Bind services and scripts. Am I wrong? I tried to "feed" =
bind9=E2=80=99s regular log=20
  files to named but it won=E2=80=99t parse them. Could anybody advise, =
please on how to=20
  make Logwatch "report" Bind? The standard / regular log files in Bind9 =
are=20
  setup like this:</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>logging {</DIV>
  <DIV>channel bind_log {</DIV>
  <DIV>file "/var/log/bind/bind.log" versions 3 size 5m;</DIV>
  <DIV>severity info;</DIV>
  <DIV>print-category yes;</DIV>
  <DIV>print-severity yes;</DIV>
  <DIV>print-time yes;</DIV>
  <DIV>&nbsp;&nbsp; };</DIV>
  <DIV>};</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>and what the logging produces as the outcome looks like =
this:</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: =
query:=20
  ns2.barcap.com IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.961 queries: info: client 1.2.3.4#52132: =
query:=20
  a10-66.akam.net IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#52132: =
query:=20
  a9-66.akam.net IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.962 queries: info: client 1.2.3.4#132: =
query:=20
  ns7.barcap.com IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: =
query:=20
  ns3.barcap.com IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.963 queries: info: client 1.2.3.4#52132: =
query:=20
  a1-71.akam.net IN A + (1.2.3.4)</DIV>
  <DIV>18-Apr-2018 11:36:14.964 queries: info: client 1.12.3.4#52132: =
query:=20
  a12-64.akam.net IN A + (1.2.3.4)</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>I would be really grateful for any pointers, suggestions,=20
  recommendations, assistance.</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>Many thanks in advance!</DIV>
  <DIV>&nbsp;</DIV>
  <DIV>Regards,</DIV>
  <DIV>Dennis</DIV>
  <DIV>
  <DIV=20
  style=3D"FONT-SIZE: small; FONT-FAMILY: 'Calibri'; FONT-WEIGHT: =
normal; COLOR: #000000; FONT-STYLE: normal; TEXT-DECORATION: none; =
DISPLAY: =
inline"></DIV>&nbsp;</DIV></DIV></DIV><PRE>------------------------------=
------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! <A =
href=3D"http://sdm.link/slashdot">http://sdm.link/slashdot</A></PRE><PRE>=
_______________________________________________
Logwatch-devel mailing list
<A =
href=3D"mailto:[email protected]">Logwatch-devel@lists=
.sourceforge.net</A>
<A =
href=3D"https://lists.sourceforge.net/lists/listinfo/logwatch-devel">http=
s://lists.sourceforge.net/lists/listinfo/logwatch-devel</A>
</PRE></BLOCKQUOTE></DIV></DIV></DIV></BODY></HTML>

------=_NextPart_000_001B_01D3D824.1AF01400--



--===============0410599137163527717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
--===============0410599137163527717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel

--===============0410599137163527717==--