summaryrefslogtreecommitdiff
path: root/logcheck/violations.ignore.d/local
blob: 3363b60e8fd5599c9ded2850dcf3ddd52d5c6777 (plain)
  1. ### violations.ignore.d/bind
  2. named\[[0-9]+\]: zone .*: refresh: failure trying master .*: timed out
  3. named\[[0-9]+\]: client [\.0-9]+#[0-9]+: update forwarding denied
  4. ### violations.ignore.d/dhcp-client
  5. dhcpd-2.2.x: (send_packet|fallback_discard): Connection refused
  6. dhclient-2.2.x: receive_packet failed on eth[0-9]: Network is down
  7. ### violations.ignore.d/misc
  8. # This one shows up with firewalls blocking SMB ports non-silently
  9. kernel: Packet log: input DENY eth[0-9]+ PROTO=17 .*:137 .*:137 L=78 S=0x00 I=[0-9]+ F=0x0000 T=[0-9]+ \(#[0-9]+\)
  10. ### violations.ignore.d/netsaint
  11. netsaint: SERVICE ALERT:.*;PING;CRITICAL;.*;PING CRITICAL - Packet loss =.*%, RTA =.*ms
  12. netsaint: SERVICE ALERT:.*;ROUTER;CRITICAL;.*;CRITICAL - Plugin timed out after 10 seconds
  13. netsaint: SERVICE ALERT:.*;ROUTER;OK;.*;PING OK - Packet loss =.*%, RTA =.*ms
  14. netsaint: SERVICE FLAPPING ALERT:.*;PING;STOPPED; Service appears to have stopped flapping (.*% change < .*% threshold)
  15. netsaint: SERVICE FLAPPING ALERT:.*;PING;STARTED; Service appears to have started flapping (.*% change >.*% threshold)
  16. netsaint: SERVICE ALERT: mail;SMTP;CRITICAL;.*;Connection refused by host
  17. netsaint: SERVICE NOTIFICATION:.*;CRITICAL;notify-by-.*;Connection refused by host
  18. netsaint: SERVICE ALERT: mail;SMTP;OK;.* OK - 0 second response time
  19. netsaint: HOST ALERT:.*;DOWN;SOFT;.*;CRITICAL.*
  20. netsaint: HOST ALERT:.*;UP;SOFT;.*;PING OK.*
  21. ### violations.ignore.d/pmud
  22. pmud\[[0-9]+\]: Sleep for this PMU unsupported: will shutdown the machine on sleep request
  23. ### violations.ignore.d/postfix
  24. postfix/(qmgr|smtp)\[[0-9]+\]: .* status=deferred \(connect to .*: (Connection refused|server refused mail service)\)
  25. postfix/cleanup\[[0-9]+\]: [A-Z0-9]+: message-id=<[^[:space:]]+@Debug>
  26. postfix/local\[[0-9]+\]: warning: unable to create lock file /var/mail/[[:alnum:]]+\.lock: Permission denied
  27. postfix/smtp\[[0-9]+\]: .* status=bounced \(bad host/domain syntax: "[^[:space:]]+"\)
  28. postfix/smtp\[[0-9]+\]: .* status=bounced \(Name service error for .*: Host not found\)
  29. postfix/smtp\[[0-9]+\]: .* status=bounced \(host .* said: 550 .* (User unknown; rejecting|Relaying denied|unknown or illegal alias: [^[:space:]]+)\)
  30. postfix/smtp\[[0-9]+\]: .* status=bounced \(host .* said: 552 header content rejected: see .*\)
  31. postfix/smtp\[[0-9]+\]: .* status=deferred \(host .* said: 450 <[^[:space:]]+>: Sender address rejected: Domain not found\)
  32. postfix/smtp\[[0-9]+\]: .* status=deferred \(host .* said: 450 <[^[:space:]]+>: Recipient address rejected: Recipient mailbox is full\)
  33. postfix/smtp\[[0-9]+\]: .* status=deferred \(host .* said: 451 Transaction failed.\)
  34. postfix/smtp\[[0-9]+\]: connect to [^[:space:]]+\[[\.0-9]+\]: (Connection refused|server refused mail service) \(port 25\)
  35. postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 550 <[^[:space:]]+>: User unknown; from=<[^[:space:]]+> to=<[^[:space:]]+>
  36. postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 554 Service unavailable; .* blocked using .*; from=<[^[:space:]]+> to=<[^[:space:]]+>
  37. postfix/smtpd\[[0-9]+\]: reject: RCPT from [^[:space:]]+\[[\.0-9]+\]: 554 <[^[:space:]]+>: (Recipient address rejected: )?(Relay a|A)ccess denied; from=<[^[:space:]]+> to=<[^[:space:]]+>
  38. postfix/smtpd\[[0-9]+\]: warning: .*: hostname .* verification failed: Host not found
  39. postfix/smtp\[[0-9]+\]: [A-Z0-9]+: to=<[^[:space:]]+>, relay=127\.0\.0\.1\[127\.0\.0\.1\], delay=[0-9]+, status=bounced \(host 127\.0\.0\.1\[127\.0\.0\.1\] said: 550 Message content rejected, id=[^[:space:]]+\)
  40. ### violations.ignore.d/proftpd
  41. proftpd\[[0-9]+\]: .* \(.*\) - USER anonymous \(Login failed\): Can't find user\.
  42. ### violations.ignore.d/samba
  43. smbd\[[0-9]+\]: read(_socket)?_data: (read|recv) failure for 4\. Error = (No route to host|Connection reset by peer)
  44. ### violations.ignore.d/ssh
  45. sshd\[[0-9]+\]: Failed keyboard-interactive for [[:alnum:]]+ from [\.0-9]+ port [0-9]+ ssh2
  46. ### violations.ignore.d/temp
  47. afpd\[[0-9]+\]: afp_flushfork: of_find: Permission denied
  48. afpd\[[0-9]+\]: afp_getsrvrparms: stat /volumes/(km/kmstab/kmstab|kp/kp(/kp|/kpstab|stab/kpstab)|misc/flstab/flstab): Permission denied
  49. afpd\[[0-9]+\]: bad function 7A
  50. afpd\[[0-9]+\]: cnid_open: Cannot establish logfile cleanup lock for database environment .*/\.AppleDB/cnid\.lock \(open\(\) failed\)
  51. afpd\[[0-9]+\]: dsi_stream_read\(0\): Permission denied
  52. afpd\[[0-9]+\]: error removing /.+/net[\.0-9]+node[0-9]+: Permission denied
  53. afpd\[[0-9]+\]: uams_dhx_pam\.c :PAM: PAM_Error: Authentication failure -- (Bad file descriptor|Invalid argument)
  54. IMP\[[0-9]+\]: FAILED .* to .*:143 as .*
  55. i(map|pop3)d\[[0-9]+\]: (AUTHENTICATE (LOGIN|PLAIN) failure|Login failed)( user=.*)? host=(.* )?\[.*\]
  56. kernel: IP_MASQ:reverse ICMP: failed checksum from .*!
  57. kernel: Packet log: input DENY eth1 PROTO=1 0.0.0.0:5 10.0.0.40:1 L=427 S=0xD0 I=0 F=0x4000 T=255 \(#22\)
  58. PAM_unix\[[0-9]+\]: authentication failure; \(uid=0\) -> .* for (imap|netatalk|pop|samba|ssh) service
  59. portsentry\[[0-9]+\]: attackalert: .*
  60. smbd\[[0-9]+\]: smb_pam_passcheck: PAM: smb_pam_auth failed - Rejecting User [[:alnum:]]+ !
  61. smbd\[[0-9]+\]: read_socket_data: recv failure for 4. Error = No route to host
  62. smbd\[[0-9]+\]: yield_connection: tdb_delete for name failed with error Record does not exist\.
  63. sshd\[[0-9]+\]: Failed password for .*
  64. pumpd\[[0-9]+\]: SO_BINDTODEVICE eth0 \(4\) failed: Invalid argument
  65. postfix/smtpd\[[0-9]+\]: reject: .*: 550 <.*>: User unknown; .*
  66. postfix/smtpd\[[0-9]+\]: reject: .*: 554 <.*>: Recipient address rejected: User unknown; .*
  67. postfix.*\[[0-9]+\]: .* from=<(groove@mailomat.grooveattack.com|refused@maila.com)>
  68. snort: spp_http_decode: IIS Unicode attack detected: