summaryrefslogtreecommitdiff
path: root/logcheck/ignore.d.workstation/local
blob: e25e235621b87e0a6584a1e3f186c757cb6a14c2 (plain)
  1. ### ignore.d.server/amanda
  2. amandad\[[0-9]+\]: connect from
  3. ### ignore.d.server/amavis
  4. amavis\[[0-9]+\]: cached [a-f0-9]+ from <[^[:space:]]*>$
  5. amavis\[[0-9]+\]: infected \([^[:space:]]+\), from=<[^[:space:]]+>, to=<[^[:space:]]+>, quarantine virus-[0-9-]+$
  6. amavis\[[0-9]+\]: local delivery: <[^[:space:]]*> -> <(spam|virus)-quarantine>, mbx=/var/lib/amavis/virusmails/(spam|virus)-[[:alnum:]-]+(\.gz)?$
  7. amavis\[[0-9]+\]: mail checking ended: (DISCARD|REJECT)$
  8. amavis\[[0-9]+\]: spam from=(<[^[:space:]]+>|\(\?\)), to=<[^[:space:]]+>, quarantine spam-[^[:space:]]+$
  9. amavis\[[0-9]+\]: spam_scan: (No|Yes), hits=[\.0-9-]+ tests=[,_A-Z0-9]+ <[^[:space:]]*>$
  10. amavis\[[0-9]+\]: spam_scan: whitelisted sender <[^[:space:]]+>, spam check skipped$
  11. ### ignore.d.server/anacron
  12. anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' terminated( \(exit status: 1\))?( \(mailing output\))?$
  13. anacron\[[0-9]+\]: Normal exit \([0-9]+ jobs run\)$
  14. anacron\[[0-9]+\]: Anacron 2.3 started on [0-9-]+$
  15. anacron\[[0-9]+\]: Will run job `cron.(daily|weekly|monthly)' in (5|10|15) min\.$
  16. anacron\[[0-9]+\]: Jobs will be executed sequentially$
  17. anacron\[[0-9]+\]: Job `cron.(daily|weekly|monthly)' started$
  18. anacron\[[0-9]+\]: Updated timestamp for job `cron.(daily|weekly|monthly)' to [0-9-]+$
  19. ### ignore.d.server/bind.changes
  20. named\[[0-9]+\]: Lame delegation
  21. named\[[0-9]+\]: Lame server on '[^[:space:]]+' \(in '[^[:space:]]+'\?\): \[[\.0-9]+\]\.[0-9]+ '[^[:space:]]+'$
  22. named\[[0-9]+\]: Response from
  23. named\[[0-9]+\]: reloading
  24. named\[[0-9]+\]: Cleaned cache of [0-9]+ RRsets$
  25. named\[[0-9]+\]: Sent NOTIFY for [^[:space:]]+$
  26. named\[[0-9]+\]: approved AXFR from [^[:space:]]+ for [^[:space:]]+$
  27. named\[[0-9]+\]: zone transfer \(AXFR\) of [^[:space:]]+ to [^[:space:]]+$
  28. named\[[0-9]+\]: suppressing duplicate notify$
  29. named\[[0-9]+\]: USAGE [0-9]+ [0-9]+ CPU=[\.0-9]+u/[\.0-9]+s CHILDCPU=[\.0-9]+u/[\.0-9]+s$
  30. named\[[0-9]+\]: NSTATS [0-9]+ [0-9]+( (A|CNAME|SOA|PTR|MX|TXT|AAAA|38|IXFR|AXFR|ANY)=[0-9]+)*$
  31. named\[[0-9]+\]: XSTATS [0-9]+ [0-9]+( (RR|RNXD|RFwdR|RDupR|RFail|RFErr|RErr|RAXFR|RLame|ROpts|SSysQ|SAns|SFwdQ|SDupQ|SErr|RQ|RIQ|RFwdQ|RDupQ|RTCP|SFwdR|SFail|SFErr|SNaAns|SNXD|RUQ|RURQ|RUXFR|RUUpd)=[0-9]+)*$
  32. named\[[0-9]+\]: lame server resolving '[^[:space:]]+' \(in '[^[:space:]]+'\?\): [\.0-9.]+#[0-9]+$
  33. named\[[0-9]+\]: Received NOTIFY answer
  34. named\[[0-9]+\]: (master |slave )?zone "[^[:space:]]+" \(IN\) loaded \(serial [0-9]+\)$
  35. named\[[0-9]+\]: (ns_forw|ns_resp|sysquery): query\([^[:space:]]+\) (NS points to CNAME \([^[:space:]]+\)|No possible A RRs|All possible A RR's lame|Bogus LOOPBACK A RR \([^[:space:]]+\))( learnt \([^[:space:]]+\))?$
  36. named\[[0-9]+\]: client [\.0-9.]+#[0-9]+: transfer of '[^[:space:]]+/IN': AXFR(-style IXFR)? started$
  37. named\[[0-9]+\]: zone [^[:space:]]+: transfered serial [0-9]+$
  38. named\[[0-9]+\]: transfer of '[^[:space:]]+' from [^[:space:]]+: end of transfer$
  39. named\[[0-9]+\]: zone [^[:space:]]+/IN: sending notifies \(serial [0-9]+\)$
  40. named\[[0-9]+\]: rcvd NOTIFY\([^[:space:]]+, IN, SOA\) from \[[\.0-9]+\]\.[0-9]+$
  41. named\[[0-9]+\]: late CNAME in answer section for [^[:space:]]+$
  42. named\[[0-9]+\]: unrelated additional info '[^[:space:]]+' type A from \[[\.0-9]+\]\.[0-9]+$
  43. ### ignore.d.server/bind.tmp
  44. named\[[0-9]+\]: zone .*: refresh: failure trying master .*: timed out$
  45. named\[[0-9]+\]: client [\.0-9]+#[0-9]+: update forwarding denied$
  46. ### ignore.d.server/courier
  47. courierpop3login: Connection, ip=\[::ffff:.*\]
  48. courierpop3login: LOGIN, user=.*, ip=\[::ffff:.*\]
  49. courierpop3login: LOGOUT, user=.*, ip=\[::ffff:.*\], top=.* retr=.*
  50. courierpop3login: Disconnected, ip=\[::ffff:.*\]
  51. courierpop3login: TIMEOUT, user=.*, ip=\[::ffff:.*\], top=0, retr=0
  52. pop3d-ssl: Connection, ip=\[::ffff:.*\]
  53. pop3d-ssl: LOGIN, user=.*, ip=\[::ffff:.*\]
  54. pop3d-ssl: LOGOUT, user=.*, ip=\[::ffff:.*\], top=.*, retr=.*
  55. pop3d-ssl: TIMEOUT, user=.*, ip=\[::ffff:.*\],top=.*, retr=.*
  56. imaplogin: Connection, ip=\[::ffff:.*\]
  57. imaplogin: LOGIN, user=.*, ip=\[::ffff:.*\]
  58. imaplogin: LOGOUT, user=.*, ip=\[::ffff:.*\], headers=.* body=.*
  59. imaplogin: DISCONNECTED, user=.*, ip=\[::ffff:.*\].*
  60. imapd-ssl: LOGOUT, user=.*, ip=\[::ffff:.*\], headers=.* body=.*
  61. imapd-ssl: Connection, ip=\[::ffff:.*\]
  62. imapd-ssl: LOGIN, user=.*, ip=\[::ffff:.*\]
  63. imapd-ssl: DISCONNECTED, user=.*, ip=\[::ffff:.*\]
  64. ### ignore.d.server/dancer-ircd
  65. ircd\[[0-9]+\]: ircd exiting: autodie$
  66. ircd\[[0-9]+\]: Server Ready$
  67. (ircd\[[0-9]+\]: )?binding stream socket [\.[:alnum:]]+\[\*\.666[789]\]: Address already in use$
  68. ### ignore.d.server/dhcp-client
  69. # NB: dhcp 2-x entries are in dhcp
  70. dhclient(-2.2.x)?: DHCP(REQUEST|DISCOVER) on .* to .* port 67( interval [0-9]+)?$
  71. dhclient(-2.2.x)?: DHCP(ACK|OFFER) from [\.0-9]+$
  72. dhclient(-2.2.x)?: bound to .* -- renewal in [0-9]+ seconds\.$
  73. dhclient(-2.2.x)?: irda0: unknown hardware address type 783$
  74. ### ignore.d.server/dhcp.changes
  75. # NB: dhcp3 entries are in dhcp3-common
  76. dhcpd-2.2.x: Abandoning IP address [\.0-9]+: (declined\.|pinged before offer) $
  77. dhcpd-2.2.x: BOOT(DISCOVER|REQUEST) from [0-9a-f:]+ via eth[0-9]+ $
  78. dhcpd-2.2.x: BOOTREPLY for [\.0-9]+ to [^[:space:]]+ ([0-9a-f:]+) via eth[0-9]+ $
  79. dhcpd-2.2.x: DHCP(ACK|NAK|OFFER) on [\.0-9]+ to [0-9a-f:]+ via eth[0-9]+ $
  80. dhcpd-2.2.x: DHCP(DECLINE on|RELEASE of|REQUEST for) [\.0-9]+ from [0-9a-f:]+( \([^[:space:]]+\))? via eth[0-9]+ \((not )?found\) $
  81. dhcpd-2.2.x: DHCPINFORM from [\.0-9]+ $
  82. dhcpd-2.2.x: DHCPREQUEST for [\.0-9]+ from [0-9a-f:]+( \([^[:space:]]+\))? via eth[0-9]+: wrong network\.$
  83. ### ignore.d.server/dhcp3-common
  84. dhcpd: Abandoning IP address [\.0-9]+: pinged before offer$
  85. dhcpd: BOOTREQUEST from [0-9a-f:]+$
  86. dhcpd: DHCP(ACK|NAK|OFFER) on [\.0-9]+ to [0-9a-f:]+( \([^\)]+\))? via eth[0-9]+$
  87. dhcpd: DHCPACK to [\.0-9]+$
  88. dhcpd: DHCPDISCOVER from [0-9a-f:]+( \([^\)]+\))? via eth[0-9]+$
  89. dhcpd: DHCPINFORM from [\.0-9]+$
  90. dhcpd: DHCPRELEASE of [\.0-9]+$
  91. dhcpd: DHCPREQUEST for [\.0-9]+( \([\.0-9]+\))? from [0-9a-f:]+( \([^\)]+\))? via eth[0-9]+$
  92. dhcpd: ICMP Echo reply while lease [\.0-9]+ valid.$
  93. dhcpd: Wrote [0-9]+ (leases|deleted host decls|new dynamic host decls) to leases file\.$
  94. dhcpd: accepting packet with data after udp payload.$
  95. dhcpd: ip length 576 disagrees with bytes received 590.$
  96. ### ignore.d.server/gdm
  97. gdm\[[0-9]+\]: run_pictures: Directory [^[:space:]] does not exist\.$
  98. ### ignore.d.server/gdm.da_DK
  99. gdm\[[0-9]+\]: Pingning af.* mislykkedes, deaktiver terminal!
  100. gdm\[[0-9]+\]: \(child [0-9]+\) gdm_slave_xioerror_handler: Fatal X-fejl - genstarter [0-9:\.]*$
  101. gdm\[[0-9]+\]: run_pictures: /usr/share/pixmaps er ikke ejet af uid [^[:space:]]\.$
  102. gdm\[[0-9]+\]: run_pictures: Mappen [^[:space:]] eksisterer ikke\.$
  103. ### ignore.d.server/hotplug
  104. /etc/hotplug/net.agent: invoke if(up|down) ppp[0-9]$
  105. /etc/hotplug/net.agent: assuming ppp[0-9] is already up$
  106. ### ignore.d.server/hylafax-server
  107. Fax(Getty|Send)\[[0-9]+\]: STATE CHANGE:( ->| BASE| LOCKWAIT| LISTENING| RUNNING| ANSWERING| RECEIVING| MODEMWAIT)+$
  108. Fax(Getty|Send)\[[0-9]+\]: MODEM (ROCKWELL|ZYXEL) .*$
  109. FaxGetty\[[0-9]+\]: RECV FAX \([0-9]+\): from .*, page .* in [0-9]+:[0-9]+, INF, .* line/mm, (1|2)-D MR(, [0-9]+ bit/s)?$
  110. FaxGetty\[[0-9]+\]: RECV FAX \([0-9]+\): recvq/fax[0-9]+\.tif from .*, route to .*, [0-9]+ pages in [0-9]+:[0-9]+$
  111. FaxGetty\[[0-9]+\]: RECV FAX: bin/faxrcvd "recvq/fax[0-9]+\.tif" "ttyS[012]" "[0-9]+"( "")+$
  112. FaxGetty\[[0-9]+\]: ANSWER: Ring detected without successful handshake$
  113. FaxGetty\[[0-9]+\]: ANSWER: FAX CONNECTION DEVICE '[^[:blank:]']+'$
  114. FaxQueuer\[[0-9]+\]: SUBMIT JOB [0-9]+$
  115. FaxSend\[[0-9]+\]: SEND FAX: JOB [0-9]+ DEST [0-9]+ COMMID [0-9]+$
  116. HylaFAX\[[0-9]+\]: Filesystem has SysV-style file creation semantics.$
  117. ### ignore.d.server/imp
  118. IMP\[[0-9]+\]: Login .* to .*:143 as .*
  119. ### ignore.d.server/libgpmg1
  120. [[:alnum:]]+: /dev/gpmctl: No such file or directory$
  121. ### ignore.d.server/libpam-modules
  122. pam_limits\[[0-9]+\]: default limits skipped for 'root'$
  123. ### ignore.d.server/mailutils-imap4d
  124. gnu-imap4d\[[0-9]+\]: Incoming connection opened$
  125. gnu-imap4d\[[0-9]+\]: connect from [\.0-9]+$
  126. gnu-imap4d\[[0-9]+\]: User '[[:alnum:]]+' logged in$
  127. gnu-imap4d\[[0-9]+\]: Session timed out for user: [[:alnum:]]+$
  128. gnu-imap4d\[[0-9]+\]: got signal Alarm clock$
  129. ### ignore.d.server/misc
  130. # Figure out if these belong to dhcp or dhcp3-common (or dhclient?)
  131. dhcpd.*: Reclaiming( REQUESTed) abandoned IP address [\.0-9]+
  132. dhcpd.*: already acking lease
  133. dhcpd.*: send_packet: Connection refused
  134. dhcpd.*: fallback_discard: Connection refused
  135. # These show up when isdnutils is installed, but isn't strictly related to those packages
  136. kernel: isdn_net: call from [,0-9]+ -> [0-9]+$
  137. kernel: isdn_net: Service-Indicator not [0-9], ignored$
  138. # This one shows up with firewalls blocking SMB ports non-silently
  139. kernel: Packet log: input DENY .*:(137|138) .*:(137|138) .*$
  140. kernel: Shorewall:net2all:DROP:.* (SPT|DPT)=(13[789]|445) .*$
  141. ### ignore.d.server/murasaki
  142. murasaki\.usb\[[0-9]+\]: found depended module="[[:alnum:]]+"$
  143. murasaki\.(usb|net)\[[0-9]+\]: try expanding "\[net\]"$
  144. murasaki\.(usb|net)\[[0-9]+\]: dependent\(net\) is found$
  145. murasaki\.(usb|net)\[[0-9]+\]: net device is (added|removed|(un)?register(e)?d)$
  146. murasaki\.(usb|net)\[[0-9]+\]: Execuing "net" "(stop|start)"$
  147. murasaki\.(usb|net)\[[0-9]+\]: execute if(up|down) (eth|(i)?ppp|irda)[0-9]$
  148. murasaki\.usb\[[0-9]+\]: (MATCH\(audio\) -> match_flags:[[:alnum:]]+ )?vendor:[[:alnum:]]+ product:[[:alnum:]]+ Dclass:[[:alnum:]]+ Dsubclass:[[:alnum:]]+ Dprotocol:[[:alnum:]]+ Iclass:[[:alnum:]]+ Isubclass:[[:alnum:]]+ Iprotocol:[[:alnum:]]+$
  149. ### ignore.d.server/nagios
  150. nagios: Auto-save of retention data completed successfully\. $
  151. nagios: LOG ROTATION: DAILY $
  152. ### ignore.d.server/netatalk.changes
  153. afpd\[[0-9]+\]: ([^[:space:]:]+: E:AFPDaemon: )?afp_alarm: child timed out$
  154. afpd\[[0-9]+\]: ([^[:space:]:]+: I:AFPDaemon: )?Connection terminated$
  155. afpd\[[0-9]+\]: ([^[:space:]:]+: I:AFPDaemon: )?[\.[:alnum:]]+ read, [\.[:alnum:]]+ written$
  156. afpd\[[0-9]+\]: ([^[:space:]:]+: I:AFPDaemon: )?login [[:alnum:]]+ \(uid [0-9]+, gid [0-9]+\)( AFP2\.2)?$
  157. afpd\[[0-9]+\]: ([^[:space:]:]+: I:Default: )?(server_child\[[0-9]+\] [0-9]+ )?(done|exited 1)$
  158. afpd\[[0-9]+\]: ([^[:space:]:]+: I:Default: )?ASIP session:[0-9]+\([0-9]+\) from [\.:0-9]+\([0-9]+\)$
  159. afpd\[[0-9]+\]: ([^[:space:]:]+: I:Default: )?CNID DB initialized using Sleepycat Software: Berkeley DB( [\.0-9]+: \([^\(]+\))?$
  160. afpd\[[0-9]+\]: ([^[:space:]:]+: I:UAMSDaemon: )?((dhx|cleartext|randnum/rand2num) )?login: [[:alnum:]]+$
  161. afpd\[[0-9]+\]: ([^[:space:]:]+: I:UAMSDaemon: )?uams_dhx_pam.c :PAM: PAM (Auth OK!|Success -- Success)$
  162. afpd\[[0-9]+\]: (afp_flushfork|afp_read|getforkparms): (ad_refresh|of_find): (No such file or directory|No such process|Permission denied)$
  163. afpd\[[0-9]+\]: (atp_rresp|afp_die: asp_shutdown): Connection timed out$
  164. afpd\[[0-9]+\]: (registering [[:alnum:]]+ \(uid [0-9]+\) on [\.0-9]+ as|removed) /[^[:space:]]+/net[\.0-9]+node[0-9]+$
  165. afpd\[[0-9]+\]: [_[:alnum:]]+(\(-?[0-9]+\))?: stat [^:]+: (No such file or directory|Permission denied)$
  166. afpd\[[0-9]+\]: asp_alrm: [0-9]+ timed out$
  167. afpd\[[0-9]+\]: dsi_stream_(read\(-1\)|write): Connection reset by peer$
  168. afpd\[[0-9]+\]: dsi_stream_read\(0\): (No such file or directory|No such process|Permission denied)$
  169. afpd\[[0-9]+\]: dsi_stream_read\(0\): Success$
  170. afpd\[[0-9]+\]: error stat'ing /[^[:space:]]+/net[\.0-9]+node[0-9]+: No such file or directory$
  171. afpd\[[0-9]+\]: login noauth$
  172. afpd\[[0-9]+\]: logout [[:alnum:]]+$
  173. afpd\[[0-9]+\]: session from [\.:0-9]+ on [\.:0-9]+$
  174. afpd\[[0-9]+\]: using codepage directory: /etc/netatalk/nls/maccode\.[\.a-z0-9-]+$
  175. atalkd\[[0-9]+\]: as_timer sendto: Network is unreachable $
  176. atalkd\[[0-9]+\]: zip (ignoring gnireply|gnireply from [\.0-9]+ \([[:alnum:]]+ [[:alnum:]]+\)) $
  177. papd\[[0-9]+\]: child [0-9]+ done$
  178. papd\[[0-9]+\]: child [0-9]+ for "[^[:space:]]+" from [\.0-9]+$
  179. ### ignore.d.server/netsaint
  180. netsaint: (HOST|SERVICE) (ALERT|NOTIFICATION|FLAPPING ALERT): .*$
  181. netsaint: Auto-save of retention data completed successfully\. $
  182. netsaint: Caught SIGTERM, shutting down\.\.\. $
  183. netsaint: Entering active mode\.\.\. $
  184. netsaint: NetSaint [\.0-9]+ starting\.\.\. \(PID=[0-9]+\) $
  185. ### ignore.d.server/nfs-kernel-server
  186. mountd\[[0-9]+\]: NFS mount of /[^[:space:]]+ attempted from [\.0-9]+$
  187. mountd\[[0-9]+\]: /[^[:space:]]+ has been mounted by [\.0-9]+$
  188. rpc\.mountd: authenticated unmount request from [\.0-9]+:[0-9]+ for /[^[:space:]]* \(/[^[:space:]\)]*\) $
  189. ### ignore.d.server/non-debian
  190. # These entries are for syslogd open for remote hosts
  191. # (and advertised through DHCP)
  192. #
  193. # HP printers
  194. printer: peripheral low-power state$
  195. printer: paper out$
  196. printer: error cleared$
  197. printer: powered up$
  198. printer: ready to print$
  199. ### ignore.d.server/ntp-simple.changes
  200. ntpd\[[0-9]+\]: kern_enable is 1$
  201. ntpd\[[0-9]+\]: kernel time discipline status [0-9]+$
  202. ntpd\[[0-9]+\]: precision = [0-9]+ usec$
  203. ntpd\[[0-9]+\]: signal_no_reset: signal 13 had flags [0-9]+$
  204. ntpd\[[0-9]+\]: using kernel phase-lock loop [0-9]+$
  205. ### ignore.d.server/pop-before-smtp
  206. pop-before-smtp\[[0-9]+\]: (opening|closing) relay for [\.0-9]+( --- not in mynetworks)?$
  207. ### ignore.d.server/postfix
  208. postfix/[[:alnum:]]+\[[0-9]+\]: table has changed -- exiting$
  209. postfix/cleanup\[[0-9]+\]: warning: premature end-of-input from cleanup socket while reading input attribute name$
  210. postfix/local\[[0-9]+\]: warning: unable to create lock file /var/mail/[[:alnum:]]+\.lock: Permission denied$
  211. postfix/master\[[0-9]+\]: reload configuration$
  212. postfix/n?qmgr\[[0-9]+\]: [A-Z0-9]+: skipped, still being delivered$
  213. postfix/postfix-script: refreshing the Postfix mail system$
  214. postfix/smtp\[[0-9]+\]: [A-Z0-9]+: enabling PIX <CRLF>\.<CRLF> workaround for [^[:space:]]+\[[\.0-9]+\]$
  215. postfix/smtp\[[0-9]+\]: [^[:space:]]+ status=deferred \(connect to [^[:space:]]+: (Connection refused|server refused mail service)\)$
  216. postfix/smtp\[[0-9]+\]: connect to [^[:space:]]+: (Connection (refused|reset by peer|timed out)|read timeout|server (refused mail service|dropped connection)|No route to host) \(port 25\)$
  217. postfix/smtp\[[0-9]+\]: warning: bad size limit "truncates" in EHLO reply from [^[:space:]]+$
  218. postfix/smtp\[[0-9]+\]: warning: host [^[:space:]]+\[[\.0-9]+\] (greeted me|replied to HELO/EHLO) with my own hostname [^[:space:]]+$
  219. postfix/smtp\[[0-9]+\]: warning: no MX host for [^[:space:]]+ has a valid A record$
  220. postfix/smtpd?\[[0-9]+\]: warning: (numeric|malformed) domain name in resource data of MX record for [^[:space:]]+: [^[:space:]]*$
  221. postfix/smtpd?\[[0-9]+\]: warning: valid_hostname: (empty hostname|invalid character [0-9]+\(decimal\): [^[:space:]]+)$
  222. postfix/smtpd\[[0-9]+\]: (lost connection|timeout) after [^ ]+ from [^[:space:]]+\[[\.0-9]+\]$
  223. postfix/smtpd\[[0-9]+\]: warning: Illegal address syntax from [^[:space:]\[]+\[[\.0-9]+\] in MAIL command: <[^[:space:]>]+>$
  224. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+ sent (message header|mail content) instead of SMTP command:
  225. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+: address not listed for hostname [^[:space:]]+$
  226. postfix/smtpd\[[0-9]+\]: warning: [^[:space:]]+: hostname [^[:space:]]+ verification failed: Host (name has no address|not found)$
  227. ### ignore.d.server/postgresql
  228. postgres\[[0-9]+\]: \[[0-9-]+\] \^ICPU .* sec elapsed .* sec\.$
  229. postgres\[[0-9]+\]: \[[0-9-]+\] \^ITotal CPU .* sec elapsed .* sec\.$
  230. ### ignore.d.server/ppp
  231. chat\[[0-9]+\]: abort on \(.*\)$
  232. chat\[[0-9]+\]: expect \(.*\)$
  233. chat\[[0-9]+\]: send \(AT.*\^M\)$
  234. chat\[[0-9]+\]: -- got it$
  235. chat\[[0-9]+\]: AT.*\^M\^M$
  236. chat\[[0-9]+\]: \^M$
  237. chat\[[0-9]+\]: CONNECT$
  238. chat\[[0-9]+\]: OK$
  239. chat\[[0-9]+\]: send \(\\d\)$
  240. ### ignore.d.server/proftpd
  241. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]\[]+\[[\.0-9]+\]\) - FTP session opened\. $
  242. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]\[]+\[[\.0-9]+\]\) - FTP login timed out, disconnected\. $
  243. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]\[]+\[[\.0-9]+\]\) - USER [^[:space:]]+: no such user found from .*\[[\.0-9]+\] to [\.0-9]+:21 $
  244. proftpd\[[0-9]+\]: [^[:space:]]+ \([^[:space:]\[]+\[[\.0-9]+\]\) - no such user '[^[:space:]]+' $
  245. proftpd\[[0-9]+\]: connect from [\.0-9]+ $
  246. proftpd\[[0-9]+\]: No certificate files found! $
  247. proftpd\[[0-9]+\]: [^[:space:]]+ ([^[:space:]\[]+\[[\.0-9]\]) - Refused PORT.* (address mismatch)\. $
  248. ### ignore.d.server/rpld
  249. rpld\[[0-9]+\]: client [:a-f0-9]+ requested block [\.0-9]+$
  250. ### ignore.d.server/samba
  251. smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4\. Error = (No route to host|Connection reset by peer)$
  252. smbd\[[0-9]+\]: \[[/0-9]+ [0-9:]+, [0-9]+\] lib/util_sock.c:read(_socket)?_data\([0-9]+\)$
  253. ### ignore.d.server/sfs-client
  254. : nfsmounter: mounted /sfs/\.linuxmnt/[^[:blank:]]+:[0-9a-z]+/r$
  255. : sfsrwcd: [^[:blank:]]+:[0-9a-z]+ deleted$
  256. ### ignore.d.server/sfs-server
  257. : sfsauthd: serving [^:]+:[0-9a-z]+$
  258. : sfssd: accepted connection from [\.0-9]+$
  259. ### ignore.d.server/spamassassin
  260. spamd\[[0-9]+\]: Creating default_prefs
  261. spamd\[[0-9]+\]: connection from .* at port
  262. spamd\[[0-9]+\]: clean message for
  263. spamd\[[0-9]+\]: identified spam for
  264. spamd\[[0-9]+\]: skipped large message in
  265. ### ignore.d.server/squid
  266. squid\[[0-9]+\]: Finished. Wrote [0-9]+ entries\.$
  267. squid\[[0-9]+\]: Took [\.0-9]+ seconds \([\.0-9]+ entries/sec\)\.$
  268. squid\[[0-9]+\]: (Closing Pinger socket|Pinger socket opened) on FD [0-9]+$
  269. squid\[[0-9]+\]: (access|store)LogRotate: Rotating(\.)?$
  270. squid\[[0-9]+\]: NETDB state saved;$
  271. squid\[[0-9]+\]: helperOpenServers: Starting [0-9]+ '.*' processes
  272. squid\[[0-9]+\]: logfileRotate: /var/log/squid/(access|store).log$
  273. squid\[[0-9]+\]: sslReadServer: FD [0-9]+: read failure: \(104\) Connection reset by peer $
  274. squid\[[0-9]+\]: storeDirWriteCleanLogs: Starting\.\.\.$
  275. squid\[[0-9]+\]: urlParse: Illegal character in hostname '[^']+' $
  276. ### ignore.d.server/ssh
  277. sshd\[[0-9]+\]: syslogin_perform_logout: logout\(\) returned an error$
  278. sshd\[[0-9]+\]: Could not reverse map address .*\.
  279. sshd\[[0-9]+\]: Connection closed by .*
  280. sshd\[[0-9]+\]: Did not receive ident(ification)? string from [\.0-9]+$
  281. sshd\[[0-9]+\]: scanned from [\.0-9]+ with SSH-1\.0-SSH_Version_Mapper\. Don't panic\.$
  282. sshd\[[0-9]+\]: Disconnecting: Your ssh version is too old and is no longer supported\. Please install a newer version\.$
  283. sshd\[[0-9]+\]: Accepted (keyboard-interactive|publickey) for [[:alnum:]]+ from [\.0-9]+ port [0-9]+ ssh2$
  284. sshd\[[0-9]+\]: warning: /etc/hosts.deny, line 15: can't verify hostname: gethostbyname(.*) failed
  285. sshd\[[0-9]+\]: refused connect from .*
  286. sshd\[[0-9]+\]: Received disconnect from [\.0-9]+: 11: Disconnect requested by Windows SSH Client.$
  287. sshd\[[0-9]+\]: subsystem request for sftp$
  288. ### ignore.d.server/ssmtp
  289. sSMTP mail\[[0-9]+\]: .* sent mail for root
  290. ### ignore.d.server/tftpd
  291. in.tftpd\[[0-9]+\]: RRQ from.*filename.*
  292. in.tftpd\[[0-9]+\]: tftp: client does not accept options
  293. ### ignore.d.server/tmp
  294. ## imp
  295. IMP\[[0-9]+\]: FAILED .* to .*:143 as .*
  296. ## libpam-modules
  297. PAM_unix\[[0-9]+\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service
  298. # old-style pam entries (no longer provided by logcheck but needed on woody)
  299. PAM_.*: .* session (opened|closed) for user .*
  300. ## netatalk
  301. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: (PAM Auth OK!|Success -- .*|User entered a null value -- .*)
  302. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument)
  303. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: User entered a null value -- No such file or directory
  304. afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied
  305. afpd\[[0-9]+\]: bad function 7A
  306. atalkd\[[0-9]+\]: as_timer sendto: Netvaerket er ikke tilgaengeligt
  307. ## hylafax-server
  308. FaxGetty\[[0-9]+\]: ANSWER: Can not lock modem device
  309. gnome-name-server\[[0-9]+\]: server_is_alive: .*
  310. ## uw-imap
  311. i(map|pop3)d\[[0-9]+\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\]
  312. ## ppp
  313. ipppd\[[0-9]+\]: Connect\[0\]: /dev/ippp[0-9], fd: 12
  314. ## misc
  315. kernel: Disorder[0-9] [0-9] [0-9] f[0-9] s[0-9] rr[0-9]
  316. kernel: IP_MASQ:reverse ICMP: failed checksum from .*!
  317. kernel: OPEN: [\.0-9]* -> [\.0-9]* UDP, port: [0-9]* -> [0-9]*
  318. kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\)
  319. kernel: Shorewall:net2all:DROP:.*$
  320. kernel: lp[0-9]: compatibility mode
  321. kernel: Undo( partial)? (Hoe|loss|retrans)
  322. printer: offline or intervention needed
  323. ## Non-UDMA hd cable
  324. kernel: hda: status timeout: status=0xd0 \{ Busy \}
  325. kernel: hda: no DRQ after issuing WRITE
  326. kernel: ide0: reset: success
  327. ## Postfix SASL not working
  328. postfix/smtpd\[[0-9]+\]: unable to open Berkeley db /etc/sasldb: No such file or directory
  329. ## ntp-simple
  330. ntpd\[[0-9]+\]: synchronisation lost
  331. ntpd\[[0-9]+\]: synchronisation lost
  332. ntpd\[[0-9]+\]: time reset [\.0-9-]* .
  333. ntpd\[[0-9]+\]: time reset [\.0-9-]+ s
  334. ## portsentry
  335. portsentry\[[0-9]+\]: attackalert: .*
  336. ## pump
  337. pumpd\[[0-9]+\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument
  338. ## samba
  339. smbd\[[0-9]+\]: read_socket_data: recv failure for 4. Error = No route to host
  340. smbd\[[0-9]+\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ !
  341. smbd\[[0-9]+\]: \[[/[0-9]]+ [:[0-9]]+, 0\] smbd/service.c:find_service\([0-9]+\)
  342. smbd\[[0-9]+\]: yield_connection: tdb_delete for name failed with error Record does not exist\.
  343. smbd\[[0-9]+\]: \[.*\] smbd/connection.c:yield_connection\([0-9]+\)
  344. smbd\[[0-9]+\]: \[.*\] passdb/pampass.c:smb_pam_passcheck\([0-9]+\)
  345. sshd\[[0-9]+\]: Failed password for .*
  346. sshd\[[0-9]+\]: packet_set_maxsize: setting to 4096
  347. ## postfix
  348. postfix.*\[[0-9]+\]: .* from=<groove@mailomat.grooveattack.com>
  349. postfix/smtpd\[[0-9]+\]: warning: Illegal address syntax from [\.[:alnum:]-]+\[[\.0-9]+\] in MAIL command: <C:\\Email\\Headers\\fresh froms 5-1\.txt>
  350. ## Tulle getting spammed
  351. tulle postfix/smtpd\[[0-9]+\]: too many errors after RCPT from unknown\[\.0-9]+[\]
  352. rpc.mountd: authenticated mount request from .* for .*
  353. ## snort
  354. snort: .*FrontPage
  355. snort: IDS015 - RPC - portmap-request-status:
  356. snort: IDS029 - SCAN-Possible Queso Fingerprint attempt:
  357. snort: IDS115 - MISC-Traceroute-UDP:
  358. snort: IDS212 - MISC - DNS Zone Transfer:
  359. snort: IDS226 - CVE-1999-0172 - CGI-formmail:
  360. snort: IDS246 - MISC - Large ICMP Packet:
  361. snort: IIS-
  362. snort: MISC-Attempted Sun RPC high port access:
  363. snort: NETBIOS-SMB-C:
  364. snort: NETBIOS-SMB-CD...:
  365. snort: NMAP TCP ping!:
  366. snort: RPC Info Query:
  367. snort: SCAN-SYN FIN:
  368. snort: spp_http_decode: IIS Unicode attack detected:
  369. snort: spp_portscan: End of portscan
  370. snort: spp_portscan: PORTSCAN DETECTED
  371. snort: spp_portscan: portscan status from
  372. snort: WEB-../..:
  373. snort: WEB-CGI-upload.pl:
  374. ## postgres
  375. postgres\[[0-9]+\]: \[[0-9-]+\] DEBUG: .*
  376. postgres\[[0-9]+\]: \[[0-9-]+\] Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.
  377. postgres\[[0-9]+\]: \[[0-9-]+\] [0-9]*; Re-using: Free/Avail. Space .* EndEmpty/Avail\. Pages .* CPU .* sec\.
  378. ## amavis
  379. amavis\[[0-9]+\]: warning - MIME::Parser error: .*
  380. ### ignore.d.server/ucd-snmp
  381. ucd-snmp\[[0-9]+\]: Connection from .*
  382. ### ignore.d.server/uw-imap.changes
  383. i(map|pop(2|3))d\[[0-9]+\]: (Broken pipe|Command stream end of file|Connection (reset by peer|timed out))(,)? while (reading (authentication|line|literal|char)|writing text) (user=.* )?host=(([^[:space:]]+ )?\[[\.0-9]+\]|NON-IPv4|UNKNOWN)$
  384. i(map|pop3)d\[[0-9]+\]: (Login|Auth|Authenticated|Logout|Autologout) user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)( nmsgs=[0-9]+(/[0-9]+)?( ndele=[0-9]+)?)?$
  385. i(map|pop3)d\[[0-9]+\]: Killed \(lost mailbox lock\) user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|NON-IPv4|UNKNOWN)$
  386. i(map|pop3)d\[[0-9]+\]: Moved [0-9]+ bytes of new mail to [^[:space:]]+ from [^[:space:]]+ host= (([^[:space:]]+ )?\[[\.0-9]+\]|NON-IPv4|UNKNOWN)$
  387. imapd\[[0-9]+\]: (port (143|220)|imap|imaps SSL) service init from
  388. imapd\[[0-9]+\]: No route to host, while reading line user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)$
  389. ipop3d\[[0-9]+\]: Error opening or locking INBOX user=.* host=(([^[:space:]]+ )?\[[\.0-9]+\]|UNKNOWN)$
  390. ipop3d\[[0-9]+\]: Expunge ignored on readonly mailbox$
  391. ipop3d\[[0-9]+\]: Mailbox is open by another process, access is readonly$
  392. ipop3d\[[0-9]+\]: Trying to get mailbox lock from process [0-9]+$
  393. ipop[2|3]d\[[0-9]+\]: (connect|pop3(s SSL)? service init) from [\.0-9]+$
  394. ### ignore.d.workstation/bind
  395. named\[[0-9]+\]: ns_forw: sendto\(\[[\.0-9]+\]\.[0-9]+\): Network is unreachable$
  396. named\[[0-9]+\]: deleting interface \[[\.0-9]+\]\.[0-9]+$
  397. named\[[0-9]+\]: listening on \[[\.0-9]+\]\.[0-9]+ \([^[:space:]+\)$
  398. ### ignore.d.workstation/devfsd
  399. devfsd\[[0-9]+\]: Caught SIGHUP$
  400. devfsd\[[0-9]+\]: read config file: "/etc/devfsd.conf"$
  401. ### ignore.d.workstation/dhcp-client
  402. dhclient(-2.2.x)?: No working leases in persistent database( - sleeping)?\.$
  403. dhclient(-2.2.x)?: Sleeping\.$
  404. dhclient(-2.2.x)?: No DHCPOFFERS received\.$
  405. dhclient(-2.2.x)?: receive_packet failed on eth[0-9]: Network is down$
  406. ### ignore.d.workstation/gconf.changes
  407. gconfd \([^[:space:]]+\): CORBA_ORB_destroy: ORB still has [0-9]+ refs\.$
  408. gconfd \([^[:space:]]+\): Exiting$
  409. gconfd \([^[:space:]]+\): GConf server is not in use, shutting down\.$
  410. gconfd \([^[:space:]]+\): Resolved address "xml:readonly:/[^[:space:]]+" to a read-only config source at position [0-9]+$
  411. gconfd \([^[:space:]]+\): Resolved address "xml:readwrite:/[^[:space:]]+" to a writable config source at position [0-9]+$
  412. gconfd \([^[:space:]]+\): starting \(version [\.0-9]+\), pid [0-9]+ user '[^[:space:]]+'$
  413. ### ignore.d.workstation/gconf.da_DK
  414. gconfd \([^[:space:]]+\): Afslutter$
  415. gconfd \([^[:space:]]+\): Bestemte adressen "xml:readonly:/[^[:space:]]+" til en skrivebeskyttet konfigureringskilde ved position [0-9]+$
  416. gconfd \([^[:space:]]+\): Bestemte adressen "xml:readwrite:/[^[:space:]]+" til en skrivbar konfigureringskilde ved position [0-9]+$
  417. gconfd \([^[:space:]]+\): GConf-server er ikke i brug, lukker ned\.$
  418. gconfd \([^[:space:]]+\): Kunne ikke fjerne kataloget '/[^[:space:]]+' fra XML-bagendemellemlageret fordi den ikke er synkroniseret med disken\.$
  419. gconfd \([^[:space:]]+\): Modtog signal 15, lukker pænt ned$
  420. gconfd \([^[:space:]]+\): starter \(version [\.0-9]+\), pid [0-9]+ bruger '[^[:space:]]+'$
  421. ### ignore.d.workstation/laptop-net
  422. ifd\[[0-9]+\]: executing: '/usr/share/laptop-net/link-change eth[0-9]+ unwatched ((((up|down),(running|stopped),(dis)?connected|unknown)|unknown)( )?){2}'$
  423. ifd\[[0-9]+\]: eth[0-9]+ is unavailable$
  424. ### ignore.d.workstation/libgnorba
  425. gnome-name-server\[[0-9]+\]: starting
  426. gnome-name-server\[[0-9]+\]: name server starting
  427. gnome-name-server\[[0-9]+\]: server_is_alive: .*
  428. ### ignore.d.workstation/misc
  429. # Linux Thin clients
  430. syslogd started: BusyBox v[\.0-9]+ \([^[:space:]]+\)$
  431. init: Entering runlevel: 2
  432. rpc.mountd: authenticated mount request from 192\.168\..* for /home/opt/ltsp/i386 \(/home/opt/ltsp/i386\)
  433. ### ignore.d.workstation/ntpdate
  434. ntpdate\[[0-9]+\]: can't find host$
  435. ntpdate\[[0-9]+\]: no servers can be used, exiting$
  436. ntpdate\[[0-9]+\]: step time server [\.0-9]+ offset [\.0-9]+ sec$
  437. ### ignore.d.workstation/oaf
  438. oafd: server_is_alive: cnx\[IDL:Bonobo/ConfigDatabase:1\.0\] = ([0-9a-f]+|\(nil\))$
  439. ### ignore.d.workstation/pmud
  440. pmud\[[0-9]+\]: running /etc/power/pwrctl (maximum|minimum|sleep|wakeup|lid-(closed|opened)) (ac|battery)$
  441. pmud\[[0-9]+\]: lid closed: request sleep$
  442. pmud\[[0-9]+\]: going to sleep$
  443. pmud\[[0-9]+\]: initiating user requested sleep$
  444. pmud\[[0-9]+\]: system awake again$
  445. ### ignore.d.workstation/sfs-client
  446. : sfsrwcd: reloaded resolv.conf file$
  447. : sfsrwcd: changing nameserver to [\.0-9]+$