diff options
-rw-r--r-- | logcheck/ignore.d.server/local | 7 | ||||
-rw-r--r-- | logcheck/ignore.d.server/tmp | 23 |
2 files changed, 17 insertions, 13 deletions
diff --git a/logcheck/ignore.d.server/local b/logcheck/ignore.d.server/local index 6badec6..383a518 100644 --- a/logcheck/ignore.d.server/local +++ b/logcheck/ignore.d.server/local @@ -29,19 +29,22 @@ dhclient-2.2.x: No DHCPOFFERS received\. dhclient-2.2.x: DHCPOFFER from [\.[:digit:]]+ dhclient-2.2.x: DHCPACK from .* dhclient-2.2.x: bound to .* -- renewal in [[:digit:]]+ seconds\. -FaxGetty\[.*\]: STATE CHANGE:( ->| LISTENING| ANSWERING| RUNNING| RECEIVING)+ -FaxGetty\[.*\]: MODEM ROCKWELL .* +Fax(Getty|Send)\[.*\]: STATE CHANGE:( ->| BASE| LOCKWAIT| LISTENING| RUNNING| ANSWERING| RECEIVING)+ +FaxGetty\[.*\]: MODEM (ROCKWELL|ZYXEL) .* FaxGetty\[.*\]: RECV FAX \([[:digit:]]+\): from .*, page .* in [[:digit:]]+:[[:digit:]]+, INF, .* line/mm, 1-D MR, [[:digit:]]+ bit/s FaxGetty\[.*\]: RECV FAX \([[:digit:]]+\): recvq/fax[[:digit:]]+\.tif from .*, route to .*, [[:digit:]]+ pages in [[:digit:]]+:[[:digit:]]+ FaxGetty\[.*\]: RECV FAX: bin/faxrcvd "recvq/fax[[:digit:]]+.tif" "ttyS[012]" "[[:digit:]]+" "" FaxGetty\[.*\]: ANSWER: Ring detected without successful handshake FaxGetty\[.*\]: ANSWER: FAX CONNECTION +FaxQueuer\[.*\]: SUBMIT JOB [[:digit:]]+ +FaxSend[2786]: SEND FAX: JOB [[:digit:]]+ DEST [[:digit:]]+ COMMID [[:digit:]]+ gdm\[.*\]: run_pictures: Directory .* does not exist\. gnu-imap4d\[.*\]: Incoming connection opened gnu-imap4d\[.*\]: connect from [\.[:digit:]]+ gnu-imap4d\[.*\]: User '[[:alnum:]]+' logged in gnu-imap4d\[.*\]: Session timed out for user: [[:alnum:]]+ gnu-imap4d\[.*\]: got signal Alarm clock +HylaFAX\[.*\]: Filesystem has SysV-style file creation semantics. imapd\[.*\]: (port 143|imap|imaps SSL) service init from imapd\[.*\]: No route to host, while reading line user=.* host=.* i(map|pop3)d\[.*\]: Killed \(lost mailbox lock\) user=.* host=.* diff --git a/logcheck/ignore.d.server/tmp b/logcheck/ignore.d.server/tmp index 303c4f6..e3f3e52 100644 --- a/logcheck/ignore.d.server/tmp +++ b/logcheck/ignore.d.server/tmp @@ -1,26 +1,27 @@ +IMP\[.*\]: FAILED .* to .*:143 as .* +PAM_unix\[.*\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service afpd\[.*\]: uams_dhx_pam\.c :PAM: PAM (Auth OK!|Success -- .*|User entered a null value -- .*) afpd\[.*\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- Invalid argument atalkd\[.*\]: as_timer sendto: Netvaerket er ikke tilgaengeligt -named\[.*\]: sysquery: findns error \(NXDOMAIN\) on dns\.homebase\.dk\? -IMP\[.*\]: FAILED .* to .*:143 as .* +FaxGetty\[.*\]: ANSWER: Can not lock modem device +gnome-name-server\[.*\]: server_is_alive: .* i(map|pop3)d\[.*\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\] ipppd\[.*\]: Connect\[0\]: /dev/ippp[[:digit:]], fd: 12 +kernel: Disorder[[:digit:]] [[:digit:]] [[:digit:]] f[[:digit:]] s[[:digit:]] rr[[:digit:]] kernel: IP_MASQ:reverse ICMP: failed checksum from .*! kernel: OPEN: [\.[:digit:]]* -> [\.[:digit:]]* UDP, port: [[:digit:]]* -> [[:digit:]]* -kernel: Undo( partial)? (Hoe|loss|retrans) -kernel: Disorder[[:digit:]] [[:digit:]] [[:digit:]] f[[:digit:]] s[[:digit:]] rr[[:digit:]] kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\) +kernel: Undo( partial)? (Hoe|loss|retrans) +named\[.*\]: sysquery: findns error \(NXDOMAIN\) on dns\.homebase\.dk\? +ntpd\[.*\]: synchronisation lost ntpd\[.*\]: synchronisation lost +ntpd\[.*\]: time reset [\.[:digit:]-]* . ntpd\[.*\]: time reset [\.[:digit:]-]+ s -PAM_unix\[.*\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service portsentry\[.*\]: attackalert: .* proftpd\[.*\]: .* \(.*\) - USER anonymous@ftp.microsoft.com: no such user found from .* proftpd\[.*\]: .* \(.*\) - no such user 'anonymous@ftp.microsoft.com' -smbd\[.*\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([[:digit:]]+\) -smbd\[.*\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ ! +pumpd\[.*\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument smbd[14793]: read_socket_data: recv failure for 4. Error = No route to host +smbd\[.*\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ ! +smbd\[.*\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([[:digit:]]+\) sshd\[.*]: Failed password for .* -pumpd\[.*\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument -gnome-name-server\[.*\]: server_is_alive: .* -ntpd\[.*\]: synchronisation lost -ntpd\[.*\]: time reset [\.[:digit:]-]* . |