From:
[email protected]
--aFi3jz1oiPowsTUB
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
tags 265176 pending
thanks
On Thu, 12 Aug 2004, Jamie L. Penman-Smithson wrote:
Package: logcheck
Version: 1.2.24
Severity: minor
If you run the gps policy server with postfix, you end up with a lot of unneeded messages:
Aug 12 01:15:18 lorien gps[27125]: disconnecting from DB
Aug 12 01:31:47 lorien gps[27264]: started (ver.: 0.7b built: Jul 14
2004 14:39:53)
Aug 12 01:31:47 lorien gps[27264]: ok: 'bounce-debian-user=devnull=[email protected]' -> '[email protected]', '146.82.138.6' (1350, 1695 secs)
Aug 12 01:37:35 lorien gps[27332]: new: '[email protected]' -> '[email protected]', '82.217.137.112'
Aug 12 01:46:44 lorien gps[27483]: wl nw: 'spamassassin-users-return-14314-devnull=[email protected]' -> '[email protected]', '209.237.227.': apache.org mailing lists
The following regexps match the above messages:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: disconnecting from DB$ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: started \(ver.:
[a-z0-9\.]+ built: [A-Za-z]+ [0-9[:space:]]+
[0-9]{2}:[0-9]{2}:[0-9]{2}\)$
For the other three rules, this is the closest I could get. Really these
will probably need to be separate rules:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: (ok|new|wl nw): '[[:alnum:][:punct:]]+@[[:alnum:][:punct:]]+'.*$
Thanks,
nice bug report,
i've added the attached rules for next release, please test them?
1 rule unmodified,
2 rule uses [[:alpha:]] instead of [a-zA-Z] explanations at ("Writing
rules"): /usr/share/doc/logcheck-database/README.logcheck-database.gz
3 rule uses [^[:space:]] to match emails, but fails on above 3 log message
the ip inside there seems very strange '209.237.227.'
thanks for a review + test
--
maks
--aFi3jz1oiPowsTUB
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment; filename=local-gps
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: disconnecting from DB$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: started \(ver.: [.[:alnum:]]+ built: \w{3} [0-9]{2} [0-9]{4} [0-9:]{8}\)$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ gps\[[0-9]+\]: (new|ok): '[^[:space:]]+' -> '[^[:space:]]+', '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'.*$
--aFi3jz1oiPowsTUB--
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBHOCt6//kSTNjoX0RAtkFAJ9QW5TfzbGAiQkDxCpmYJXZ1fcGxgCfW00A hQULsgqc2GcdIEmmeE9cQP4=
=rXgT
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: you cannot sedate... all the things you hate (1:229/2)