summaryrefslogtreecommitdiff
path: root/logcheck/ignore.d.server/tmp
blob: c72783af7f78c52a30b7e607a4091cd75b4ab1b0 (plain)
  1. ## imp
  2. IMP\[[0-9]+\]: FAILED .* to .*:143 as .*
  3. ## libpam-modules
  4. PAM_unix\[[0-9]+\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service
  5. # old-style pam entries (no longer provided by logcheck but needed on woody
  6. PAM_.*: .* session (opened|closed) for user .*
  7. ## netatalk
  8. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM (Auth OK!|Success -- .*|User entered a null value -- .*)
  9. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument)
  10. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM: User entered a null value -- No such file or directory
  11. afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied
  12. afpd\[[0-9]+\]: bad function 7A
  13. atalkd\[[0-9]+\]: as_timer sendto: Netvaerket er ikke tilgaengeligt
  14. ## hylafax-server
  15. FaxGetty\[[0-9]+\]: ANSWER: Can not lock modem device
  16. gnome-name-server\[[0-9]+\]: server_is_alive: .*
  17. ## uw-imap
  18. i(map|pop3)d\[[0-9]+\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\]
  19. ## ppp
  20. ipppd\[[0-9]+\]: Connect\[0\]: /dev/ippp[0-9], fd: 12
  21. ## misc
  22. kernel: Disorder[0-9] [0-9] [0-9] f[0-9] s[0-9] rr[0-9]
  23. kernel: IP_MASQ:reverse ICMP: failed checksum from .*!
  24. kernel: OPEN: [\.0-9]* -> [\.0-9]* UDP, port: [0-9]* -> [0-9]*
  25. kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\)
  26. kernel: lp[0-9]: compatibility mode
  27. kernel: Undo( partial)? (Hoe|loss|retrans)
  28. printer: offline or intervention needed
  29. ## ntp-simple
  30. ntpd\[[0-9]+\]: synchronisation lost
  31. ntpd\[[0-9]+\]: synchronisation lost
  32. ntpd\[[0-9]+\]: time reset [\.0-9-]* .
  33. ntpd\[[0-9]+\]: time reset [\.0-9-]+ s
  34. ## portsentry
  35. portsentry\[[0-9]+\]: attackalert: .*
  36. ## pump
  37. pumpd\[[0-9]+\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument
  38. ## samba
  39. smbd\[[0-9]+\]: read_socket_data: recv failure for 4. Error = No route to host
  40. smbd\[[0-9]+\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ !
  41. smbd\[[0-9]+\]: \[[/[0-9]]+ [:[0-9]]+, 0\] smbd/service.c:find_service\([0-9]+\)
  42. smbd\[[0-9]+\]: yield_connection: tdb_delete for name failed with error Record does not exist\.
  43. smbd\[[0-9]+\]: \[.*\] smbd/connection.c:yield_connection\([0-9]+\)
  44. smbd\[[0-9]+\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([0-9]+\)
  45. sshd\[[0-9]+\]: Failed password for .*
  46. sshd\[[0-9]+\]: packet_set_maxsize: setting to 4096
  47. ## postfix
  48. postfix.*\[[0-9]+\]: .* from=<groove@mailomat.grooveattack.com>
  49. postfix/smtpd\[[0-9]+\]: warning: Illegal address syntax from [\.[:alnum:]-]+\[[\.0-9]+\] in MAIL command: <C:\\Email\\Headers\\fresh froms 5-1\.txt>
  50. rpc.mountd: authenticated mount request from .* for .*
  51. ## snort
  52. snort: .*FrontPage
  53. snort: IDS015 - RPC - portmap-request-status:
  54. snort: IDS029 - SCAN-Possible Queso Fingerprint attempt:
  55. snort: IDS115 - MISC-Traceroute-UDP:
  56. snort: IDS212 - MISC - DNS Zone Transfer:
  57. snort: IDS226 - CVE-1999-0172 - CGI-formmail:
  58. snort: IDS246 - MISC - Large ICMP Packet:
  59. snort: IIS-
  60. snort: MISC-Attempted Sun RPC high port access:
  61. snort: NETBIOS-SMB-C:
  62. snort: NETBIOS-SMB-CD...:
  63. snort: NMAP TCP ping!:
  64. snort: RPC Info Query:
  65. snort: SCAN-SYN FIN:
  66. snort: spp_http_decode: IIS Unicode attack detected:
  67. snort: spp_portscan: End of portscan
  68. snort: spp_portscan: PORTSCAN DETECTED
  69. snort: spp_portscan: portscan status from
  70. snort: WEB-../..:
  71. snort: WEB-CGI-upload.pl:
  72. ## postgres
  73. postgres\[[0-9]+\]: \[.*\] DEBUG:
  74. postgres\[[0-9]+\]: \[[0-9-]*\] Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.
  75. postgres\[[0-9]+\]: \[[0-9-]*\] [0-9]*; Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.