summaryrefslogtreecommitdiff
path: root/logcheck/ignore.d.workstation/local
blob: c7a60348d82b3ebfaec43f23975a638ede27567e (plain)
  1. ### ignore.d.server/amanda
  2. amandad\[[0-9]+\]: connect from
  3. ### ignore.d.server/amavis
  4. amavis\[[0-9]+\]: infected \([^[:space:]]+\), from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine virus-[0-9-]+
  5. amavis\[[0-9]+\]: local delivery: <[^[:space:]]+> -> <(spam|virus)-quarantine>, mbx=/var/lib/amavis/virusmails/(spam|virus)-[[:alnum:]-]+(\.gz)?
  6. amavis\[[0-9]+\]: mail checking ended: (DISCARD|REJECT)
  7. amavis\[[0-9]+\]: spam from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine spam-[^[:space:]]+
  8. amavis\[[0-9]+\]: spam_scan: Yes, hits=[\.0-9]+ tests=[^[:space:]]+ <[^[:space:]]+>
  9. ### ignore.d.server/anacron
  10. anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' terminated( \(exit status: 1\))?( \(mailing output\))?
  11. anacron\[[0-9]+\]: Normal exit
  12. anacron\[[0-9]+\]: Anacron 2.3 started on [0-9-]+
  13. anacron\[[0-9]+\]: Will run job `cron.(daily|weekly|monthly)' in (5|10|15) min\.
  14. anacron\[[0-9]+\]: Jobs will be executed sequentially
  15. anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' started
  16. anacron\[[0-9]+\]: Updated timestamp for job `cron.(daily|weekly|monthly)' to [0-9-]+
  17. ### ignore.d.server/bind
  18. named\[[0-9]+\]: .*: query\(.*\) NS points to CNAME \(.*\)
  19. named\[[0-9]+\]: NSTATS [0-9]+ [0-9]+
  20. named\[[0-9]+\]: .* All possible .* lame
  21. named\[[0-9]+\]: sysquery: query\(.*\) No possible A RRs
  22. named\[[0-9]+\]: client .*: transfer of '.*': AXFR started
  23. named\[[0-9]+\]: zone .*/IN: transfered serial [0-9]+
  24. named\[[0-9]+\]: transfer of '.*/IN' from .*: end of transfer
  25. named\[[0-9]+\]: zone .*/IN: sending notifies \(serial [0-9]+\)
  26. named\[[0-9]+\]: rcvd NOTIFY\(.*, IN, SOA\) from \[.*\]\.[0-9]+
  27. named\[[0-9]+\]: late CNAME in answer section for .*
  28. ### ignore.d.server/bind.tmp
  29. named\[[0-9]+\]: zone .*: refresh: failure trying master .*: timed out
  30. named\[[0-9]+\]: client [\.0-9]+#[0-9]+: update forwarding denied
  31. ### ignore.d.server/courier
  32. courierpop3login: Connection, ip=\[::ffff:.*\]
  33. courierpop3login: LOGIN, user=.*, ip=\[::ffff:.*\]
  34. courierpop3login: LOGOUT, user=.*, ip=\[::ffff:.*\], top=.* retr=.*
  35. courierpop3login: Disconnected, ip=\[::ffff:.*\]
  36. courierpop3login: TIMEOUT, user=.*, ip=\[::ffff:.*\], top=0, retr=0
  37. pop3d-ssl: Connection, ip=\[::ffff:.*\]
  38. pop3d-ssl: LOGIN, user=.*, ip=\[::ffff:.*\]
  39. pop3d-ssl: LOGOUT, user=.*, ip=\[::ffff:.*\], top=.*, retr=.*
  40. pop3d-ssl: TIMEOUT, user=.*, ip=\[::ffff:.*\],top=.*, retr=.*
  41. imaplogin: Connection, ip=\[::ffff:.*\]
  42. imaplogin: LOGIN, user=.*, ip=\[::ffff:.*\]
  43. imaplogin: LOGOUT, user=.*, ip=\[::ffff:.*\], headers=.* body=.*
  44. imaplogin: DISCONNECTED, user=.*, ip=\[::ffff:.*\].*
  45. imapd-ssl: LOGOUT, user=.*, ip=\[::ffff:.*\], headers=.* body=.*
  46. imapd-ssl: Connection, ip=\[::ffff:.*\]
  47. imapd-ssl: LOGIN, user=.*, ip=\[::ffff:.*\]
  48. imapd-ssl: DISCONNECTED, user=.*, ip=\[::ffff:.*\]
  49. ### ignore.d.server/dancer-ircd
  50. ircd\[[0-9]+\]: ircd exiting: autodie
  51. ircd\[[0-9]+\]: Server Ready
  52. (ircd\[[0-9]+\]: )?binding stream socket [\.[:alnum:]]+\[\*\.666[789]\]: Address already in use
  53. ### ignore.d.server/dhcp-client
  54. # NB: dhcp 2-x entries are in dhcp
  55. dhclient(-2.2.x)?: DHCP(REQUEST|DISCOVER) on .* to .* port 67( interval [0-9]+)?
  56. dhclient(-2.2.x)?: DHCP(ACK|OFFER) from [\.0-9]+
  57. dhclient(-2.2.x)?: bound to .* -- renewal in [0-9]+ seconds\.
  58. dhclient(-2.2.x)?: irda0: unknown hardware address type 783
  59. ### ignore.d.server/dhcp.changes
  60. # NB: dhcp3 entries are in dhcp3-common
  61. dhcpd-2.2.x: Abandoning IP address [\.0-9]+: pinged before offer
  62. dhcpd-2.2.x: BOOTREQUEST from [:0-9a-f]+
  63. dhcpd-2.2.x: DHCP(ACK|NACK|OFFER) on [\.0-9]+ to [:0-9a-f]+ via eth[0-9]+
  64. dhcpd-2.2.x: DHCPDISCOVER from .* via eth[0-9]+
  65. dhcpd-2.2.x: DHCPRELEASE of [\.0-9]+ from [:0-9a-f]+ via eth[0-9]+ \((not )?found\)
  66. dhcpd-2.2.x: DHCPREQUEST for .* from .* via eth[0-9]+
  67. ### ignore.d.server/dhcp3-common
  68. dhcpd: Abandoning IP address [\.0-9]+: pinged before offer
  69. dhcpd: BOOTREQUEST from
  70. dhcpd: DHCP(ACK|NACN|OFFER) on [\.0-9]+ to [:0-9a-f]+( \([^[:space:]]+\))? via eth[0-9]+
  71. dhcpd: DHCPACK to [\.0-9]+
  72. dhcpd: DHCPDISCOVER from [:0-9a-f]+ via eth[0-9]+
  73. dhcpd: DHCPINFORM from
  74. dhcpd: DHCPRELEASE of [\.0-9]+
  75. dhcpd: DHCPREQUEST for [\.0-9]+ from [:0-9a-f]+( \([^[:space:]]+\))? via eth[0-9]+
  76. dhcpd: ICMP Echo reply while lease [\.0-9]+ valid.
  77. dhcpd: Wrote [0-9]+ (leases|deleted host decls|new dynamic host decls) to leases file\.
  78. dhcpd: accepting packet with data after udp payload.
  79. dhcpd: ip length 576 disagrees with bytes received 590.
  80. ### ignore.d.server/gdm
  81. gdm\[[0-9]+\]: run_pictures: .*/.gnome/gdm .*\.
  82. ### ignore.d.server/gdm.da_DK
  83. gdm\[[0-9]+\]: Pingning af.* mislykkedes, deaktiver terminal!
  84. gdm\[[0-9]+\]: gdm_slave_xioerror_handler: Fatal X-fejl - genstarter.*
  85. ### ignore.d.server/hotplug
  86. /etc/hotplug/net.agent: invoke if(up|down) ppp[0-9]
  87. /etc/hotplug/net.agent: assuming ppp[0-9] is already up
  88. ### ignore.d.server/hylafax-server
  89. Fax(Getty|Send)\[[0-9]+\]: STATE CHANGE:( ->| BASE| LOCKWAIT| LISTENING| RUNNING| ANSWERING| RECEIVING| MODEMWAIT)+
  90. Fax(Getty|Send)\[[0-9]+\]: MODEM (ROCKWELL|ZYXEL) .*
  91. FaxGetty\[[0-9]+\]: RECV FAX \([0-9]+\): from .*, page .* in [0-9]+:[0-9]+, INF, .* line/mm, (1|2)-D MR(, [0-9]+ bit/s)?
  92. FaxGetty\[[0-9]+\]: RECV FAX \([0-9]+\): recvq/fax[0-9]+\.tif from .*, route to .*, [0-9]+ pages in [0-9]+:[0-9]+
  93. FaxGetty\[[0-9]+\]: RECV FAX: bin/faxrcvd "recvq/fax[0-9]+\.tif" "ttyS[012]" "[0-9]+" ""
  94. FaxGetty\[[0-9]+\]: ANSWER: Ring detected without successful handshake
  95. FaxGetty\[[0-9]+\]: ANSWER: FAX CONNECTION
  96. FaxQueuer\[[0-9]+\]: SUBMIT JOB [0-9]+
  97. FaxSend\[[0-9]+\]: SEND FAX: JOB [0-9]+ DEST [0-9]+ COMMID [0-9]+
  98. HylaFAX\[[0-9]+\]: Filesystem has SysV-style file creation semantics.
  99. ### ignore.d.server/imp
  100. IMP\[[0-9]+\]: Login .* to .*:143 as .*
  101. ### ignore.d.server/libgpmg1
  102. [[:alnum:]]: /dev/gpmctl: No such file or directory
  103. ### ignore.d.server/libpam-modules
  104. pam_limits\[[0-9]+\]: default limits skipped for 'root'
  105. ### ignore.d.server/mailutils-imap4d
  106. gnu-imap4d\[[0-9]+\]: Incoming connection opened
  107. gnu-imap4d\[[0-9]+\]: connect from [\.0-9]+
  108. gnu-imap4d\[[0-9]+\]: User '[[:alnum:]]+' logged in
  109. gnu-imap4d\[[0-9]+\]: Session timed out for user: [[:alnum:]]+
  110. gnu-imap4d\[[0-9]+\]: got signal Alarm clock
  111. ### ignore.d.server/misc
  112. # Figure out if these belong to dhcp or dhcp3-common (or dhclient?)
  113. dhcpd.*: Reclaiming( REQUESTed) abandoned IP address [\.0-9]+
  114. dhcpd.*: already acking lease
  115. dhcpd.*: send_packet: Connection refused
  116. dhcpd.*: fallback_discard: Connection refused
  117. # These show up when isdnutils is installed, but isn't strictly related to those packages
  118. kernel: isdn_net: call from [,0-9]+ -> [0-9]+
  119. kernel: isdn_net: Service-Indicator not [0-9], ignored
  120. # This one shows up with firewalls blocking SMB ports non-silently
  121. kernel: Packet log: input DENY eth[0-9]+ PROTO=17 .*:(137|138) .*:(137|138) L=[0-9]+ S=0x00 I=[0-9]+ F=0x0000 T=[0-9]+ \(#[0-9]+\)
  122. ### ignore.d.server/murasaki
  123. murasaki\.usb\[[0-9]+\]: found depended module="[[:alnum:]]+"
  124. murasaki\.(usb|net)\[[0-9]+\]: try expanding "\[net\]"
  125. murasaki\.(usb|net)\[[0-9]+\]: dependent\(net\) is found
  126. murasaki\.(usb|net)\[[0-9]+\]: net device is (added|removed|(un)?register(e)?d)
  127. murasaki\.(usb|net)\[[0-9]+\]: Execuing "net" "(stop|start)"
  128. murasaki\.(usb|net)\[[0-9]+\]: execute if(up|down) (eth|(i)?ppp|irda)[0-9]
  129. murasaki\.usb\[[0-9]+\]: (MATCH\(audio\) -> match_flags:[[:alnum:]]+ )?vendor:[[:alnum:]]+ product:[[:alnum:]]+ Dclass:[[:alnum:]]+ Dsubclass:[[:alnum:]]+ Dprotocol:[[:alnum:]]+ Iclass:[[:alnum:]]+ Isubclass:[[:alnum:]]+ Iprotocol:[[:alnum:]]+
  130. ### ignore.d.server/netatalk.changes
  131. afpd\[[0-9]+\]: CNID DB initialized using Sleepycat Software: Berkeley DB
  132. afpd\[[0-9]+\]: removed [^[:space:]]+/net[\.0-9]+node[0-9]+
  133. afpd\[[0-9]\]: ((dhx|cleartext|randnum/rand2num) )?login: [[:alnum:]]+
  134. afpd\[[0-9]\]: (server_child\[[0-9]+\] [0-9]+ )?(done|exited 1)
  135. afpd\[[0-9]\]: ASIP session:[0-9]+\([0-9]+\) from [\.:0-9]+\([0-9]+\)
  136. afpd\[[0-9]\]: Connection terminated
  137. afpd\[[0-9]\]: [\.[:alnum:]]+ read, [\.[:alnum:]]+ written
  138. afpd\[[0-9]\]: [^[:space:]]+: Broken pipe
  139. afpd\[[0-9]\]: [^[:space:]]+: Connection reset by peer
  140. afpd\[[0-9]\]: [^[:space:]]+: (C|c)onnection timed out
  141. afpd\[[0-9]\]: [^[:space:]]+: No route to host
  142. afpd\[[0-9]\]: [^[:space:]]+: No such file or directory
  143. afpd\[[0-9]\]: [^[:space:]]+: Permission denied
  144. afpd\[[0-9]\]: [^[:space:]]+: child timed out
  145. afpd\[[0-9]\]: afp_openfork: ad_open: File Exists
  146. afpd\[[0-9]\]: asp_alrm: [0-9]+ timed out
  147. afpd\[[0-9]\]: login [[:alnum:]]+ \(uid [0-9]+, gid [0-9]+\)
  148. afpd\[[0-9]\]: login noauth
  149. afpd\[[0-9]\]: logout [[:alnum:]]+
  150. afpd\[[0-9]\]: registering [[:alnum:]]+ \(uid [0-9]+\) on [\.0-9]+ as /.+/net[\.0-9]+node[0-9]+
  151. afpd\[[0-9]\]: session from [\.:0-9]+ on [\.:0-9]+
  152. afpd\[[0-9]\]: uams_dhx_pam.c :PAM: PAM (Auth OK!|Success -- Success)
  153. afpd\[[0-9]\]: using codepage directory: /etc/netatalk/nls/maccode\.[\.[:alnum:]-]+
  154. atalkd\[[0-9]+\]: [^[:space:]]+: zip gnireply from [\.0-9]+ \([^[:space:]]+\)
  155. atalkd\[[0-9]+\]: [^[:space:]]+: zip ignoring gnireply
  156. atalkd\[[0-9]\]: [^[:space:]]+: Network is unreachable
  157. atalkd\[[0-9]\]: zip gnireply from [\.0-9]+ \([^[:space:]]+\)
  158. atalkd\[[0-9]\]: zip ignoring gnireply
  159. papd\[[0-9]\]: child [0-9]+ done
  160. papd\[[0-9]\]: child [0-9]+ for "[^[:space:]]+" from [\.0-9]+
  161. ### ignore.d.server/netsaint
  162. netsaint: SERVICE (ALERT|NOTIFICATION|FLAPPING ALERT): .*
  163. netsaint: Auto-save of retention data completed successfully\.
  164. netsaint: HOST ALERT:.*;DOWN;SOFT;.*;CRITICAL - Plugin timed out after 10 seconds
  165. netsaint: HOST ALERT:*;UP;SOFT;.*;PING OK - Packet loss = 0%, RTA =.*ms
  166. netsaint: SERVICE ALERT:.*;HTTP;CRITICAL;HARD;.*;Connection refused or timed out
  167. ### ignore.d.server/non-debian
  168. # These entries are for syslogd open for remote hosts
  169. # (and advertised through DHCP)
  170. #
  171. # HP printers
  172. printer: peripheral low-power state
  173. printer: paper out
  174. printer: error cleared
  175. printer: powered up
  176. printer: ready to print
  177. ### ignore.d.server/ntp-simple.changes
  178. ntpd\[[0-9]+\]: kern_enable is 1
  179. ntpd\[[0-9]+\]: precision = [0-9]+ usec
  180. ntpd\[[0-9]+\]: signal_no_reset: signal 13 had flags [0-9]+
  181. ntpd\[[0-9]+\]: using kernel phase-lock loop [0-9]+
  182. ### ignore.d.server/pop-before-smtp
  183. pop-before-smtp\[[0-9]+\]: (opening|closing) relay for [\.0-9]+( --- not in mynetworks)?
  184. ### ignore.d.server/postfix
  185. postfix/[[:alnum:]]+\[[0-9]+\]: table has changed -- exiting
  186. postfix/cleanup\[[0-9]+\]: warning: premature end-of-input from cleanup socket while reading input attribute name
  187. postfix/local\[[0-9]+\]: warning: unable to create lock file /var/mail/[[:alnum:]]+\.lock: Permission denied
  188. postfix/master\[[0-9]+\]: reload configuration
  189. postfix/postfix-script: refreshing the Postfix mail system
  190. postfix/qmgr\[[0-9]+\]: [A-Z0-9]+: skipped, still being delivered
  191. postfix/smtp\[[0-9]+\]: [A-Z0-9]+: enabling PIX <CRLF>\.<CRLF> workaround for [\.[:alnum:]-]+\[[\.0-9]+\]
  192. postfix/smtp\[[0-9]+\]: [^[:space:]]+ status=deferred \(connect to [^[:space:]]+: (Connection refused|server refused mail service)\)
  193. postfix/smtp\[[0-9]+\]: connect to [^[:space:]]+: (Connection (refused|reset by peer|timed out)|read timeout|server (refused mail service|dropped connection)|No route to host) \(port 25\)
  194. postfix/smtp\[[0-9]+\]: warning: bad size limit "truncates" in EHLO reply from [^[:space:]]+
  195. postfix/smtp\[[0-9]+\]: warning: host [\.[:alnum:]-]+\[[\.0-9]+\] (greeted me|replied to HELO/EHLO) with my own hostname [\.[:alnum:]-]+
  196. postfix/smtp\[[0-9]+\]: warning: mailer loop: best MX host for [^[:space:]]+ is local
  197. postfix/smtp\[[0-9]+\]: warning: no MX host for [\.[:alnum:]-]+ has a valid A record
  198. postfix/smtp\[[0-9]+\]: warning: numeric domain name in resource data of MX record for [^[:space:]]+: [\.0-9]+
  199. postfix/smtpd\[[0-9]+\]: (lost connection|timeout) after [^ ]+ from [\.[:alnum:]-]+\[[\.0-9]+\]
  200. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+ sent (message header|mail content) instead of SMTP command:
  201. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+: address not listed for hostname [^[:space:]]+
  202. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+: hostname [\.[:alnum:]-]+ verification failed: Host (name has no address|not found)
  203. ### ignore.d.server/postgresql
  204. postgres\[[0-9]+\]: \[[0-9-]+\] \^ICPU .* sec elapsed .* sec\.
  205. postgres\[[0-9]+\]: \[[0-9-]+\] \^ITotal CPU .* sec elapsed .* sec\.
  206. ### ignore.d.server/ppp
  207. chat\[[0-9]+\]: abort on \(.*\)
  208. chat\[[0-9]+\]: expect \(.*\)
  209. chat\[[0-9]+\]: send \(AT.*\^M\)
  210. chat\[[0-9]+\]: -- got it
  211. chat\[[0-9]+\]: AT.*\^M\^M
  212. chat\[[0-9]+\]: \^M
  213. chat\[[0-9]+\]: CONNECT
  214. chat\[[0-9]+\]: OK
  215. chat\[[0-9]+\]: send \(\\d\)
  216. ### ignore.d.server/proftpd
  217. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]]+\[[\.0-9]+\]\) - FTP session opened\.
  218. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]]+\[[\.0-9]+\]\) - FTP login timed out, disconnected\.
  219. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]]+\[[\.0-9]+\]\) - USER (anonymous|ftp)(@[\.[:alnum:]]+)? \(Login failed\): Can't find user\.
  220. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]]+\[[\.0-9]+\]\) - USER (anonymous|ftp)(@[\.[:alnum:]]+)?: no such user found from .*\[[\.0-9]+\] to [\.0-9]+
  221. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]]+\[[\.0-9]+\]\) - no such user '(anonymous|ftp)(@[\.[:alnum:]]+)?'
  222. proftpd\[[0-9]+\]: connect from [\.0-9]+
  223. proftpd\[[0-9]+\]: No certificate files found!
  224. proftpd\[[0-9]+\]: [^[:space:]]+ ([^[:space:]]+\[[\.0-9]\]) - Refused PORT.* (address mismatch)\.
  225. ### ignore.d.server/samba
  226. smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4\. Error = (No route to host|Connection reset by peer)
  227. smbd\[[0-9]+\]: \[[/0-9]+ [:0-9]+, [0-9]+\] lib/util_sock.c:read(_socket)?_data\([0-9]+\)
  228. ### ignore.d.server/spamassassin
  229. spamd\[[0-9]+\]: Creating default_prefs
  230. spamd\[[0-9]+\]: connection from .* at port
  231. spamd\[[0-9]+\]: clean message for
  232. spamd\[[0-9]+\]: identified spam for
  233. spamd\[[0-9]+\]: skipped large message in
  234. ### ignore.d.server/squid
  235. squid\[[0-9]+\]: Finished. Wrote [0-9]+ entries\.
  236. squid\[[0-9]+\]: Took [\.0-9]+ seconds \(.* entries/sec\)\.
  237. squid\[[0-9]+\]: (access|store)LogRotate: Rotating(\.)?
  238. squid\[[0-9]+\]: logfileRotate: /var/log/squid/(access|store).log
  239. squid\[[0-9]+\]: (Closing Pinger socket|Pinger socket opened) on FD [0-9]+
  240. squid\[[0-9]+\]: NETDB state saved;
  241. squid\[[0-9]+\]: storeDirWriteCleanLogs: Starting\.\.\.
  242. squid\[[0-9]+\]: helperOpenServers: Starting [0-9]+ '.*' processes
  243. ### ignore.d.server/ssh
  244. sshd\[[0-9]+\]: syslogin_perform_logout: logout\(\) returned an error
  245. sshd\[[0-9]+\]: Could not reverse map address .*\.
  246. sshd\[[0-9]+\]: Connection closed by .*
  247. sshd\[[0-9]+\]: Did not receive ident(ification)? string from [\.0-9]+
  248. sshd\[[0-9]+\]: scanned from [\.0-9]+ with SSH-1\.0-SSH_Version_Mapper\. Don't panic\.
  249. sshd\[[0-9]+\]: Disconnecting: Your ssh version is too old and is no longer supported\. Please install a newer version\.
  250. sshd\[[0-9]+\]: Accepted (keyboard-interactive|publickey) for [[:alnum:]]+ from [\.0-9]+ port [0-9]+ ssh2
  251. sshd\[[0-9]+\]: warning: /etc/hosts.deny, line 15: can't verify hostname: gethostbyname(.*) failed
  252. sshd\[[0-9]+\]: refused connect from .*
  253. sshd\[[0-9]+\]: Received disconnect from [\.0-9]+: 11: Disconnect requested by Windows SSH Client.
  254. sshd\[[0-9]+\]: subsystem request for sftp
  255. ### ignore.d.server/ssmtp
  256. sSMTP mail\[[0-9]+\]: .* sent mail for root
  257. ### ignore.d.server/tftpd
  258. in.tftpd\[[0-9]+\]: RRQ from.*filename.*
  259. in.tftpd\[[0-9]+\]: tftp: client does not accept options
  260. ### ignore.d.server/tmp
  261. ## imp
  262. IMP\[[0-9]+\]: FAILED .* to .*:143 as .*
  263. ## libpam-modules
  264. PAM_unix\[[0-9]+\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service
  265. # old-style pam entries (no longer provided by logcheck but needed on woody
  266. PAM_.*: .* session (opened|closed) for user .*
  267. ## netatalk
  268. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM (Auth OK!|Success -- .*|User entered a null value -- .*)
  269. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument)
  270. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM: User entered a null value -- No such file or directory
  271. afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied
  272. afpd\[[0-9]+\]: bad function 7A
  273. atalkd\[[0-9]+\]: as_timer sendto: Netvaerket er ikke tilgaengeligt
  274. ## hylafax-server
  275. FaxGetty\[[0-9]+\]: ANSWER: Can not lock modem device
  276. gnome-name-server\[[0-9]+\]: server_is_alive: .*
  277. ## uw-imap
  278. i(map|pop3)d\[[0-9]+\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\]
  279. ## ppp
  280. ipppd\[[0-9]+\]: Connect\[0\]: /dev/ippp[0-9], fd: 12
  281. ## misc
  282. kernel: Disorder[0-9] [0-9] [0-9] f[0-9] s[0-9] rr[0-9]
  283. kernel: IP_MASQ:reverse ICMP: failed checksum from .*!
  284. kernel: OPEN: [\.0-9]* -> [\.0-9]* UDP, port: [0-9]* -> [0-9]*
  285. kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\)
  286. kernel: lp[0-9]: compatibility mode
  287. kernel: Undo( partial)? (Hoe|loss|retrans)
  288. printer: offline or intervention needed
  289. ## ntp-simple
  290. ntpd\[[0-9]+\]: synchronisation lost
  291. ntpd\[[0-9]+\]: synchronisation lost
  292. ntpd\[[0-9]+\]: time reset [\.0-9-]* .
  293. ntpd\[[0-9]+\]: time reset [\.0-9-]+ s
  294. ## portsentry
  295. portsentry\[[0-9]+\]: attackalert: .*
  296. ## pump
  297. pumpd\[[0-9]+\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument
  298. ## samba
  299. smbd\[[0-9]+\]: read_socket_data: recv failure for 4. Error = No route to host
  300. smbd\[[0-9]+\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ !
  301. smbd\[[0-9]+\]: \[[/[0-9]]+ [:[0-9]]+, 0\] smbd/service.c:find_service\([0-9]+\)
  302. smbd\[[0-9]+\]: yield_connection: tdb_delete for name failed with error Record does not exist\.
  303. smbd\[[0-9]+\]: \[.*\] smbd/connection.c:yield_connection\([0-9]+\)
  304. smbd\[[0-9]+\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([0-9]+\)
  305. sshd\[[0-9]+\]: Failed password for .*
  306. sshd\[[0-9]+\]: packet_set_maxsize: setting to 4096
  307. ## postfix
  308. postfix.*\[[0-9]+\]: .* from=<groove@mailomat.grooveattack.com>
  309. postfix/smtpd\[[0-9]+\]: warning: Illegal address syntax from [\.[:alnum:]-]+\[[\.0-9]+\] in MAIL command: <C:\\Email\\Headers\\fresh froms 5-1\.txt>
  310. rpc.mountd: authenticated mount request from .* for .*
  311. ## snort
  312. snort: .*FrontPage
  313. snort: IDS015 - RPC - portmap-request-status:
  314. snort: IDS029 - SCAN-Possible Queso Fingerprint attempt:
  315. snort: IDS115 - MISC-Traceroute-UDP:
  316. snort: IDS212 - MISC - DNS Zone Transfer:
  317. snort: IDS226 - CVE-1999-0172 - CGI-formmail:
  318. snort: IDS246 - MISC - Large ICMP Packet:
  319. snort: IIS-
  320. snort: MISC-Attempted Sun RPC high port access:
  321. snort: NETBIOS-SMB-C:
  322. snort: NETBIOS-SMB-CD...:
  323. snort: NMAP TCP ping!:
  324. snort: RPC Info Query:
  325. snort: SCAN-SYN FIN:
  326. snort: spp_http_decode: IIS Unicode attack detected:
  327. snort: spp_portscan: End of portscan
  328. snort: spp_portscan: PORTSCAN DETECTED
  329. snort: spp_portscan: portscan status from
  330. snort: WEB-../..:
  331. snort: WEB-CGI-upload.pl:
  332. ## postgres
  333. postgres\[[0-9]+\]: \[.*\] DEBUG:
  334. postgres\[[0-9]+\]: \[[0-9-]*\] Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.
  335. postgres\[[0-9]+\]: \[[0-9-]*\] [0-9]*; Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.
  336. ## amavis
  337. amavis\[[0-9]+\]: warning - MIME::Parser error: .*
  338. ### ignore.d.server/ucd-snmp
  339. ucd-snmp\[[0-9]+\]: Connection from .*
  340. ### ignore.d.server/uw-imap.changes
  341. i(map|pop(2|3))d\[[0-9]+\]: (Broken pipe|Command stream end of file|Connection (reset by peer|timed out))(,)? while (reading (authentication|line|literal|char)|writing text) (user=.* )?host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  342. i(map|pop3)d\[[0-9]+\]: (Login|Auth|Authenticated|Logout|Autologout) user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  343. i(map|pop3)d\[[0-9]+\]: Killed \(lost mailbox lock\) user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  344. i(map|pop3)d\[[0-9]+\]: Moved [0-9]+ bytes of new mail to [^[:space:]]+ from [^[:space:]]+ host= (([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  345. imapd\[[0-9]+\]: (port 143|imap|imaps SSL) service init from
  346. imapd\[[0-9]+\]: No route to host, while reading line user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  347. ipop3d\[[0-9]+\]: Error opening or locking INBOX user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)
  348. ipop3d\[[0-9]+\]: Expunge ignored on readonly mailbox
  349. ipop3d\[[0-9]+\]: Mailbox is open by another process, access is readonly
  350. ipop3d\[[0-9]+\]: Trying to get mailbox lock from process [0-9]+
  351. ipop[2|3]d\[[0-9]+\]: (connect|pop3(s SSL)? service init) from [\.0-9]+
  352. ### ignore.d.workstation/bind
  353. named\[[0-9]+\]: ns_forw: sendto.*: Network is unreachable
  354. ### ignore.d.workstation/devfsd
  355. devfsd\[[0-9]+\]: Caught SIGHUP
  356. devfsd\[[0-9]+\]: read config file: "/etc/devfsd.conf"
  357. ### ignore.d.workstation/dhcp-client
  358. dhclient(-2.2.x)?: No working leases in persistent database( - sleeping)?\.
  359. dhclient(-2.2.x)?: Sleeping\.
  360. dhclient(-2.2.x)?: No DHCPOFFERS received\.
  361. dhclient(-2.2.x)?: receive_packet failed on eth[0-9]: Network is down
  362. ### ignore.d.workstation/gconf.changes
  363. gconfd \(.*\): starting \(version [\.0-9]+\), pid [0-9]+ user '.*'
  364. gconfd \(.*\): Resolved address "xml:readonly:.*" to a read-only config source at position [0-9]+
  365. gconfd \(.*\): Resolved address "xml:readwrite:.*" to a writable config source at position [0-9]+
  366. gconfd \(.*\): CORBA_ORB_destroy: ORB still has [0-9]+ refs\.
  367. gconfd \(.*\): GConf server is not in use, shutting down\.
  368. gconfd \(.*\): Exiting
  369. ### ignore.d.workstation/gconf.da_DK
  370. gconfd \(.*\): Modtog signal 15, lukker pænt ned
  371. gconfd \(.*\): starter \(version [\.0-9]+\), pid [0-9]+ bruger '.*'
  372. gconfd \(.*\): Bestemte adressen "xml:readonly:.*" til en skrivebeskyttet konfigureringskilde ved position [0-9]+
  373. gconfd \(.*\): Bestemte adressen "xml:readwrite:.*" til en skrivbar konfigureringskilde ved position [0-9]+
  374. gconfd \(.*\): GConf-server er ikke i brug, lukker ned\.
  375. gconfd \(.*\): Afslutter
  376. ### ignore.d.workstation/gdm
  377. gdm\[[0-9]+\]: run_pictures: Directory [^[:space:]] does not exist\.
  378. ### ignore.d.workstation/gdm.da_DK
  379. gdm\[[0-9]+\]: run_pictures: Mappen [^[:space:]] eksisterer ikke\.
  380. gdm\[[0-9]+\]: run_pictures: /usr/share/pixmaps er ikke ejet af uid [^[:space:]]\.
  381. gdm\[[0-9]+\]: \(child [0-9]+\) gdm_slave_xioerror_handler: Fatal X-fejl - genstarter [0-9:\.]*
  382. ### ignore.d.workstation/libgnorba
  383. gnome-name-server\[[0-9]+\]: starting
  384. gnome-name-server\[[0-9]+\]: name server starting
  385. gnome-name-server\[[0-9]+\]: server_is_alive: .*
  386. ### ignore.d.workstation/misc
  387. # Linux Thin clients
  388. syslogd started: BusyBox v[\.0-9]+ \([:space:]]2\)
  389. init: Entering runlevel: 2
  390. rpc.mountd: authenticated mount request from 192\.168\..* for /home/opt/ltsp/i386 \(/home/opt/ltsp/i386\)
  391. ### ignore.d.workstation/ntpdate
  392. ntpdate\[[0-9]+\]: can't find host
  393. ntpdate\[[0-9]+\]: no servers can be used, exiting
  394. ntpdate\[[0-9]+\]: step time server [\.0-9]+ offset [\.0-9]+ sec
  395. ### ignore.d.workstation/oaf
  396. oafd: server_is_alive: cnx\[IDL:Bonobo/ConfigDatabase:1\.0\] = \(nil\)
  397. ### ignore.d.workstation/pmud
  398. pmud\[[0-9]+\]: running /etc/power/pwrctl (maximum|minimum|sleep|wakeup|lid-(closed|opened)) (ac|battery)
  399. pmud\[[0-9]+\]: lid closed: request sleep
  400. pmud\[[0-9]+\]: going to sleep
  401. pmud\[[0-9]+\]: initiating user requested sleep
  402. pmud\[[0-9]+\]: system awake again