Re: Problem with Logfile Rotation / Inconsistency

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <1203585614.5965.92.camel@arwen>
Hi,

Le jeudi 31 janvier 2008 à 10:01 +0100, [email protected] a écrit :
> ok, since nobody seems to be able to help me with my quite severe problem maybe a few more hints:
> 
> /var/log/messages shows the following lines after each rotation:
> 
> Jan 31 06:00:01 ids-master prelude-lml: WARNING: /var/log/auth.log: Metadata available, but checksum is invalid, starting at 0.
> Jan 31 06:00:01 ids-master prelude-lml: WARNING: /var/log/messages: Metadata available, but checksum is invalid, starting at 0.

This is not an error, in recent Prelude-LML version, the message has
been renamed to: "log file was rotated, starting from head.".

However, if this happen at each rotation, without you restarting LML,
then it look like a failure to properly detect the rotation. 

If this is the case, please provide information about the way your logs
are rotated (and the software doing it), and tell us whether LML is
using the FAM backend.

Regards,

-- 
Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                  Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com

_______________________________________________
Prelude-user site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.