summaryrefslogtreecommitdiff
path: root/logcheck/violations.ignore.d/local
diff options
context:
space:
mode:
authorJonas Smedegaard <dr@jones.dk>2002-12-06 18:05:09 +0000
committerJonas Smedegaard <dr@jones.dk>2002-12-06 18:05:09 +0000
commitf500da26477d433e0bf59a1714d32e9e0ee92896 (patch)
tree33f6780db8b1c6d0c731f8017662426d1c66e237 /logcheck/violations.ignore.d/local
parent4df46411735f3924d3f06201d7daa863e0e81661 (diff)
Add $ to all non-loose entries. Misc. cleanup.
Diffstat (limited to 'logcheck/violations.ignore.d/local')
-rw-r--r--logcheck/violations.ignore.d/local74
1 files changed, 37 insertions, 37 deletions
diff --git a/logcheck/violations.ignore.d/local b/logcheck/violations.ignore.d/local
index 18408ea..fac54e1 100644
--- a/logcheck/violations.ignore.d/local
+++ b/logcheck/violations.ignore.d/local
@@ -1,25 +1,26 @@
### violations.ignore.d/amavis
-amavis\[[0-9]+\]: Checking: <[^[:space:]]*> -> (<[^[:space:]]*>(,)?)+
-amavis\[[0-9]+\]: SMTP-in \[[\.0-9]+\] /var/lib/amavis/amavis[0-9-]+: <[^[:space:]]*> -> (<[^[:space:]]*>(,)?)+
-amavis\[[0-9]+\]: cached [a-f0-9]+ from <[^[:space:]]*>
-amavis\[[0-9]+\]: infected \([^[:space:]]+\), from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine virus-[0-9-]+
-amavis\[[0-9]+\]: local delivery: <[^[:space:]]+> -> <(spam|virus)-quarantine>, mbx=/var/lib/amavis/virusmails/(spam|virus)-[[:alnum:]-]+(\.gz)?
-amavis\[[0-9]+\]: spam from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine spam-[^[:space:]]+
-amavis\[[0-9]+\]: spam_scan: (No|Yes), hits=[\.0-9-]+ tests=[,_A-Z0-9]+ <[^[:space:]]*>
+amavis\[[0-9]+\]: Checking: <[^[:space:]]*> -> (<[^[:space:]]*>(,)?)+$
+amavis\[[0-9]+\]: SMTP-in \[[\.0-9]+\] /var/lib/amavis/amavis[0-9-]+: <[^[:space:]]*> -> (<[^[:space:]]*>(,)?)+$
+amavis\[[0-9]+\]: cached [a-f0-9]+ from <[^[:space:]]*>$
+amavis\[[0-9]+\]: infected \([^[:space:]]+\), from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine virus-[0-9-]+$
+amavis\[[0-9]+\]: local delivery: <[^[:space:]]+> -> <(spam|virus)-quarantine>, mbx=/var/lib/amavis/virusmails/(spam|virus)-[[:alnum:]-]+(\.gz)?$
+amavis\[[0-9]+\]: spam from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine spam-[^[:space:]]+$
+amavis\[[0-9]+\]: spam_scan: (No|Yes), hits=[\.0-9-]+ tests=[,_A-Z0-9]+ <[^[:space:]]*>$
### violations.ignore.d/bind
+named\[[0-9]+\]: client [\.0-9]+#[0-9]+: update forwarding denied$
+### violations.ignore.d/bind.tmp
named\[[0-9]+\]: zone .*: refresh: failure trying master .*: timed out
-named\[[0-9]+\]: client [\.0-9]+#[0-9]+: update forwarding denied
### violations.ignore.d/dhcp-client
-dhcpd(-2.2.x)?: (send_packet|fallback_discard): Connection refused
-dhclient(-2.2.x)?: receive_packet failed on eth[0-9]: Network is down
+dhcpd(-2.2.x)?: (send_packet|fallback_discard): Connection refused$
+dhclient(-2.2.x)?: receive_packet failed on eth[0-9]: Network is down$
### violations.ignore.d/misc
# This one shows up with firewalls blocking SMB ports non-silently
kernel: Packet log: input DENY eth[0-9]+ PROTO=17 .*:137 .*:137 L=78 S=0x00 I=[0-9]+ F=0x0000 T=[0-9]+ \(#[0-9]+\)
### violations.ignore.d/netatalk.changes
-afpd\[[0-9]+\]: afp_die: asp_shutdown: Connection timed out
-afpd\[[0-9]+\]: afp_getsrvrparms: stat /.+/: Permission denied
-afpd\[[0-9]+\]: dsi_stream_read\([[:digit:]]+\): Permission denied
-afpd\[[0-9]+\]: getforkparms: (ad_refresh|of_find): Permission denied
+afpd\[[0-9]+\]: afp_die: asp_shutdown: Connection timed out$
+afpd\[[0-9]+\]: afp_getsrvrparms: stat /[^/]+/: Permission denied$
+afpd\[[0-9]+\]: dsi_stream_read\([[:digit:]]+\): Permission denied$
+afpd\[[0-9]+\]: getforkparms: (ad_refresh|of_find): Permission denied$
### violations.ignore.d/netsaint
netsaint: SERVICE ALERT:.*;PING;CRITICAL;.*;PING CRITICAL - Packet loss =.*%, RTA =.*ms
netsaint: SERVICE ALERT:.*;ROUTER;CRITICAL;.*;CRITICAL - Plugin timed out after 10 seconds
@@ -32,34 +33,33 @@ netsaint: SERVICE ALERT: mail;SMTP;OK;.* OK - 0 second response time
netsaint: HOST ALERT:.*;DOWN;SOFT;.*;CRITICAL.*
netsaint: HOST ALERT:.*;UP;SOFT;.*;PING OK.*
### violations.ignore.d/pmud
-pmud\[[0-9]+\]: Sleep for this PMU unsupported: will shutdown the machine on sleep request
+pmud\[[0-9]+\]: Sleep for this PMU unsupported: will shutdown the machine on sleep request$
### violations.ignore.d/postfix
-postfix/(qmgr|smtp)\[[0-9]+\]: .* status=deferred \(connect to [^[:space:]]+\[[\.0-9]+\]: (Connection refused|server refused mail service)\)
-postfix/cleanup\[[0-9]+\]: [A-Z0-9]+: message-id=<[^[:space:]]+>
-postfix/local\[[0-9]+\]: warning: unable to create lock file /var/mail/[[:alnum:]]+\.lock: Permission denied
-postfix/nqmgr\[[0-9]+\]: [A-Z0-9]+: from=<[^[:space:]]+>, size=[0-9]+, nrcpt=[0-9]+ \(queue active\)
+postfix/(qmgr|smtp)\[[0-9]+\]: .* status=deferred \(connect to [^[:space:]\[]+\[[\.0-9]+\]: (Connection refused|server refused mail service)\)
+postfix/cleanup\[[0-9]+\]: [A-Z0-9]+: message-id=<[^[:space:]>]+>$
+postfix/local\[[0-9]+\]: warning: unable to create lock file /var/mail/[[:alnum:]]+\.lock: Permission denied$
+postfix/nqmgr\[[0-9]+\]: [A-Z0-9]+: from=<[^[:space:]>]+>, size=[0-9]+, nrcpt=[0-9]+ \(queue active\)$
postfix/smtp\[[0-9]+\]: .* status=bounced \(Name service error for .*: Host not found\)
-postfix/smtp\[[0-9]+\]: .* status=bounced \(bad host/domain syntax: "[^[:space:]]+"\)
-postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]]+\[[\.0-9]+\] said: 550 .* (User unknown; rejecting|Relaying denied|Access denied\.|unknown or illegal alias: [^[:space:]]+|Recipient address rejected: This user does not have an account here \(MTA:imta15\))\)
-postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]]+\[[\.0-9]+\] said: 552 header content rejected: see .*\)
-postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]]+\[[\.0-9]+\] said: 554 <[^[:space:]]+>:( Recipient address rejected:)? Relay access denied\)
-postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]]+\[[\.0-9]+\] said: 571 <>... denied\)
-postfix/smtp\[[0-9]+\]: .* status=deferred \(host [^[:space:]]+\[[\.0-9]+\] said: 450 <[^[:space:]]+>: Recipient address rejected: Recipient mailbox is full\)
-postfix/smtp\[[0-9]+\]: .* status=deferred \(host [^[:space:]]+\[[\.0-9]+\] said: 450 <[^[:space:]]+>: Sender address rejected: Domain not found\)
-postfix/smtp\[[0-9]+\]: .* status=deferred \(host [^[:space:]]+\[[\.0-9]+\] said: 451 Transaction failed.\)
-postfix/smtp\[[0-9]+\]: [A-Z0-9]+: to=<[^[:space:]]+>, relay=127\.0\.0\.1\[127\.0\.0\.1\], delay=[0-9]+, status=bounced \(host 127\.0\.0\.1\[127\.0\.0\.1\] said: 550 Message content rejected, id=[^[:space:]]+\)
-postfix/smtp\[[0-9]+\]: connect to [^[:space:]]+\[[\.0-9]+\]: (Connection refused|server refused mail service) \(port 25\)
-postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 504 <[^[:space:]]+>: Recipient address rejected: need fully-qualified address; from=<[^[:space:]]+> to=<[^[:space:]]+>
-postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 550 <[^[:space:]]+>: User unknown; from=<[^[:space:]]+> to=<[^[:space:]]+>
-postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 554 <[^[:space:]]+>: (Recipient address rejected: )?(Relay a|A)ccess denied; from=<[^[:space:]]*> to=<[^[:space:]]+>
-postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 554 Service unavailable; .* blocked using .*; from=<[^[:space:]]+> to=<[^[:space:]]+>
-postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+: hostname [\.[:alnum:]-]+ verification failed: Host (name has no address|not found)
+postfix/smtp\[[0-9]+\]: .* status=bounced \(bad host/domain syntax: "[^"]+"\)
+postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]\[]+\[[\.0-9]+\] said: 550 .* (User unknown; rejecting|Relaying denied|Access denied\.|unknown or illegal alias: [^[:space:]]+|Recipient address rejected: This user does not have an account here \(MTA:imta15\))\)
+postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]\[]+\[[\.0-9]+\] said: 552 header content rejected: see .*\)
+postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]\[]+\[[\.0-9]+\] said: 554 <[^[:space:]>]+>:( Recipient address rejected:)? Relay access denied\)
+postfix/smtp\[[0-9]+\]: .* status=bounced \(host [^[:space:]\[]+\[[\.0-9]+\] said: 571 <>\.\.\. denied\)
+postfix/smtp\[[0-9]+\]: .* status=deferred \(host [^[:space:]\[]+\[[\.0-9]+\] said: 450 <[^[:space:]>]+>: (Recipient address rejected: Recipient mailbox is full|Sender address rejected: Domain not found\)
+postfix/smtp\[[0-9]+\]: .* status=deferred \(host [^[:space:]\[]+\[[\.0-9]+\] said: 451 Transaction failed.\)
+postfix/smtp\[[0-9]+\]: [A-Z0-9]+: to=<[^[:space:]>]+>, relay=127\.0\.0\.1\[127\.0\.0\.1\], delay=[0-9]+, status=bounced \(host 127\.0\.0\.1\[127\.0\.0\.1\] said: 550 Message content rejected, id=[^\)]+\)$
+postfix/smtp\[[0-9]+\]: connect to [^[:space:]\[]+\[[\.0-9]+\]: (Connection refused|server refused mail service) \(port 25\)$
+postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]\[]+\[[\.0-9]+\]: 504 <[^[:space:]>]+>: Recipient address rejected: need fully-qualified address; from=<[^[:space:]>]+> to=<[^[:space:]>]+>$
+postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]\[]+\[[\.0-9]+\]: 550 <[^[:space:]>]+>: User unknown; from=<[^[:space:]>]+> to=<[^[:space:]>]+>$
+postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]\[]+\[[\.0-9]+\]: 554 <[^[:space:]>]+>: (Recipient address rejected: )?(Relay a|A)ccess denied; from=<[^[:space:]>]*> to=<[^[:space:]>]+>$
+postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]\[]+\[[\.0-9]+\]: 554 Service unavailable; .* blocked using .*; from=<[^[:space:]>]+> to=<[^[:space:]>]+>
+postfix/smtpd\[[0-9]+\]: warning: [^[:space:]:]+: hostname [\.[:alnum:]-]+ verification failed: Host (name has no address|not found)$
### violations.ignore.d/proftpd
-proftpd\[[0-9]+\]: .* \(.*\) - USER anonymous \(Login failed\): Can't find user\.
+proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]\[]+\[[\.0-9]+\]\) - USER anonymous \(Login failed\): Can't find user\.$
### violations.ignore.d/samba
-smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4\. Error = (No route to host|Connection reset by peer)
+smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4\. Error = (No route to host|Connection reset by peer)$
### violations.ignore.d/ssh
-sshd\[[0-9]+\]: Failed keyboard-interactive for [[:alnum:]]+ from [\.0-9]+ port [0-9]+ ssh2
+sshd\[[0-9]+\]: Failed keyboard-interactive for [^[:space:]]+ from [\.0-9]+ port [0-9]+ ssh2$
### violations.ignore.d/temp
afpd\[[0-9]+\]: afp_flushfork: of_find: Permission denied
afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied