From 4fc6db3247b0f8278fbfe5a735f2afa801509714 Mon Sep 17 00:00:00 2001 From: Jonas Smedegaard Date: Sun, 18 May 2003 16:24:24 +0000 Subject: Misc. additional ignores related to remote syslog reception. --- logcheck/ignore.d.workstation/local | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) (limited to 'logcheck/ignore.d.workstation') diff --git a/logcheck/ignore.d.workstation/local b/logcheck/ignore.d.workstation/local index 460c255..c9938ad 100644 --- a/logcheck/ignore.d.workstation/local +++ b/logcheck/ignore.d.workstation/local @@ -9,13 +9,14 @@ amavis\[[0-9]+\]: spam from=(<[^>]+>|\(\?\)), to=(<[^>]+>,)+ quarantine spam-[0- amavis\[[0-9]+\]: spam_scan: (No|Yes), hits=[\.0-9-]+ tests=[,_A-Z0-9]+ <[^>]*>$ amavis\[[0-9]+\]: spam_scan: whitelisted sender <[^[:space:]]+>, spam check skipped$ ### ignore.d.server/anacron -anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' terminated( \(exit status: 1\))?( \(mailing output\))?$ -anacron\[[0-9]+\]: Normal exit \([0-9]+ jobs run\)$ +/USR/SBIN/CRON\[[0-9]+\]: \(root\) CMD \(test -e /usr/sbin/anacron || run-parts --report /etc/cron.(daily|weekly|monthly)\) $ anacron\[[0-9]+\]: Anacron 2.3 started on [0-9-]+$ -anacron\[[0-9]+\]: Will run job `cron.(daily|weekly|monthly)' in (5|10|15) min\.$ -anacron\[[0-9]+\]: Jobs will be executed sequentially$ anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' started$ +anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' terminated( \(exit status: 1\))?( \(mailing output\))?$ +anacron\[[0-9]+\]: Jobs will be executed sequentially$ +anacron\[[0-9]+\]: Normal exit \([0-9]+ jobs run\)$ anacron\[[0-9]+\]: Updated timestamp for job `cron.(daily|weekly|monthly)' to [0-9-]+$ +anacron\[[0-9]+\]: Will run job `cron.(daily|weekly|monthly)' in (5|10|15) min\.$ ### ignore.d.server/bind.changes named\[[0-9]+\]: Lame delegation named\[[0-9]+\]: Lame server on '[^[:space:]]+' \(in '[^[:space:]]+'\?\): \[[\.0-9]+\]\.[0-9]+ '[^[:space:]]+'$ @@ -167,6 +168,7 @@ afpd\[[0-9]+\]: ([^[:space:]]+: I:Default: )?(server_child\[[0-9]+\] [0-9]+ )?(d afpd\[[0-9]+\]: ([^[:space:]]+: I:Default: )?ASIP session:[0-9]+\([0-9]+\) from [\.:0-9]+\([0-9]+\)$ afpd\[[0-9]+\]: ([^[:space:]]+: I:Default: )?CNID DB initialized using Sleepycat Software: Berkeley DB( [\.0-9]+: \([^\(]+\))?$ afpd\[[0-9]+\]: ([^[:space:]]+: I:UAMSDaemon: )?((dhx|cleartext|randnum/rand2num) )?login: [[:alnum:]]+$ +afpd\[[0-9]+\]: ([^[:space:]]+: I:UAMSDaemon: )?login noauth$ afpd\[[0-9]+\]: ([^[:space:]]+: I:UAMSDaemon: )?uams_dhx_pam.c :PAM: PAM (Auth OK!|Success -- Success)$ afpd\[[0-9]+\]: (afp_flushfork|afp_read|getforkparms): (ad_refresh|of_find): (No such file or directory|No such process|Permission denied)$ afpd\[[0-9]+\]: (atp_rresp|afp_die: asp_shutdown): Connection timed out$ @@ -179,7 +181,6 @@ afpd\[[0-9]+\]: dsi_stream_(read\(-1\)|write): Connection reset by peer$ afpd\[[0-9]+\]: dsi_stream_read\(0\): (No such file or directory|No such process|Permission denied)$ afpd\[[0-9]+\]: dsi_stream_read\(0\): Success$ afpd\[[0-9]+\]: error stat'ing /[^[:space:]]+/net[\.0-9]+node[0-9]+: No such file or directory$ -afpd\[[0-9]+\]: login noauth$ atalkd\[[0-9]+\]: (as_timer|nbp brrq) sendto [\.0-9]+( \([0-9]+\))?: Network is unreachable $ atalkd\[[0-9]+\]: zip (ignoring gnireply|gnireply from [\.0-9]+ \([[:alnum:]]+ [[:alnum:]]+\)) $ papd\[[0-9]+\]: ([^[:space:]]+: I:PAPDaemon: )?child [0-9]+ done$ @@ -212,6 +213,7 @@ ntpd\[[0-9]+\]: kernel time discipline status [0-9]+$ ntpd\[[0-9]+\]: precision = [0-9]+ usec$ ntpd\[[0-9]+\]: signal_no_reset: signal 13 had flags [0-9]+$ ntpd\[[0-9]+\]: using kernel phase-lock loop [0-9]+$ +ntpd\[[0-9]+\]: ntpd [\.0-9]+ [a-zA-Z]+ [a-zA-Z]+ [0-9]+ [0-9:]+ UTC 200[2-9]+ \(2\)$ ### ignore.d.server/pop-before-smtp pop-before-smtp\[[0-9]+\]: (opening|closing) relay for [\.0-9]+( --- not in mynetworks)?$ ### ignore.d.server/postfix @@ -319,6 +321,8 @@ sshd\[[0-9]+\]: Received disconnect from [\.0-9]+: 11: Disconnect requested by W sshd\[[0-9]+\]: subsystem request for sftp$ ### ignore.d.server/ssmtp sSMTP mail\[[0-9]+\]: .* sent mail for root +### ignore.d.server/sysklogd +syslogd [\.#0-9]+: restart \(remote reception\). ### ignore.d.server/tftpd in\.tftpd\[[0-9]+\]: RRQ from [\.0-9]+ filename [^[:space:]]+ $ in\.tftpd\[[0-9]+\]: tftp: client does not accept options @@ -331,11 +335,11 @@ PAM_unix\[[0-9]+\]: check pass; user unknown$ # old-style pam entries (no longer provided by logcheck but needed on woody) PAM_.*: .* session (opened|closed) for user .* ## netatalk +afpd\[[0-9]+\]: ([^[:space:]]+: I:AFPDaemon: )?bad function 7A +afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: (PAM Auth OK!|Success -- .*|User entered a null value -- .*) afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument) afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: User entered a null value -- No such file or directory -afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied -afpd\[[0-9]+\]: ([^[:space:]]+: I:AFPDaemon: )?bad function 7A atalkd\[[0-9]+\]: as_timer sendto: Netvaerket er ikke tilgaengeligt ## hylafax-server FaxGetty\[[0-9]+\]: ANSWER: Can not lock modem device -- cgit v1.2.3