Fedora Linux Support Community & Resources Center
  #1  
Old 23rd January 2010, 06:36 PM
UsagiChan Offline
Registered User
 
Join Date: Jan 2006
Posts: 13
windows_xp_2003firefox
Logwatch issue

I occasionally see messages in my logwatch report then cannot find the actual log entry. Is there any way I can have logwatch give a clearer report?
an example:

vsftpd:
Unknown Entries:
authentication failure; logname= uid=0 euid=0 tty=ftp ruser=a-specific-user
rhost=67.215.229.226 : 7 Time(s)
check pass; user unknown: 7 Time(s)

Someone obviously tried to break into my FTP server at some time during the day. However I haven't a clue where I can find the specific entry so I can send it to the company and ask them to stop this person.

How can I get Logwatch to report the exact location of the log involved and the exact time? When I tried to search /var/logs/*.* I for the IP came up empty.

thanks
Reply With Quote
  #2  
Old 23rd January 2010, 07:22 PM
madhavdiwan Offline
Registered User
 
Join Date: Jun 2009
Posts: 472
windows_xp_2003firefox
try not being so specific in your search string.. *.* implies only files with . in the filename.. also .. your search is not recursive

try grep -r 'IPADDRESS' /var/log/*

remember to use quotes around the Ip Address

as for logwatch .. you can configure it in /etc/logwatch/conf/logwatch.conf for localized configuration.. this overrides the defaults in /usr/share/logwatch/default.conf/logwatch.conf , changing the amount of detail in the report might tell you enough .. or you can really customize it .. be careful, you could spend months getting your report to look JUST right, this is a really powerful utility with access to any log file you point out to it.
Reply With Quote
  #3  
Old 24th January 2010, 05:04 AM
UsagiChan Offline
Registered User
 
Join Date: Jan 2006
Posts: 13
windows_xp_2003firefox
Thanks

Quote:
try grep -r 'IPADDRESS' /var/log/*
That works
Reply With Quote
Reply

Tags
logwatch

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Logwatch issue sector Servers & Networking 1 12th October 2009 05:56 PM
Logwatch reports empty!! how to debug logwatch? paul sanz Using Fedora 1 26th June 2008 10:29 AM


Current GMT-time: 12:15 (Wednesday, 22-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat