Re: security logs being mailed to root

From: epilogue (epilogue_at_allstream.net)
Date: 03/04/05

  • Next message: David Kelly: "Re: Detected Ethernet Cards Fail To Configure At Boot"
    Date: Fri, 4 Mar 2005 17:58:09 -0500
    To: sn1tch <dot.sn1tch@gmail.com>
    
    

    On Fri, 4 Mar 2005 14:06:03 -0500
    sn1tch <dot.sn1tch@gmail.com> wrote:

    > On Fri, 04 Mar 2005 12:34:36 -0600, Kevin Kinsey <kdk@daleco.biz>
    wrote:
    > > exp@netbox.yi.org wrote:
    > >
    > > >On Fri, Mar 04, 2005 at 08:59:45AM -0500, sn1tch wrote:
    > > >
    > > >
    > > >>When I ran FBSD 5.2.1 I used to get the daily, weekly, and monthly
    > > >>security logs and such mailed to root...now since I did a clean
    > > >>install with 5.3 I no longer get anything, when I log in I have no
    > > >>mail...what gives? I enjoyed reading them .. is there a way to get
    > > >>that functionality back?
    > > >>
    > > >>
    > > >>Thanks,
    > > >>Joe
    > > >>
    > > >>
    > > >5.3 also does this by default. Are you sure your computer
    > > >is turned on at the times these mails are sent, in /etc/crontab?
    > > >
    > > >
    > >
    > > And ...
    > >
    > > If the logs and such exist, then syslogd is probably OK. Otherwise
    > > check syslogd first.
    > >
    > > Next, make sure that crond is running. Don't know why it wouldn't
    > > be, be might as well check.
    > >
    > > Then, check sendmail. Depending on settings, this might be the
    > > issue. If syslogd is working as expected, you should find a note
    > > in /var/mail/maillog (about 3:0x a.m. system time) that shows a mail
    > > going to "root@somebox.tld".
    > >
    > > Which brings us to /etc/mail/aliases. Is the alias for "root"
    pointing
    > > to your email address?
    > >
    > > I'm sure there's stuff I may have missed as well, but here's the
    start
    > > of a debug checklist.
    > >
    > > HTH,
    > >
    > > Kevin Kinsey
    >
    > Crontab doesnt have any listings and rc.conf shows this...
    >
    > sendmail_enable="NONE"
    > syslogd_flags="-ss"

    a) jsyk, the prefered syntax has switched from 'NONE' to what is
    currently described in 'man rc.sendmail'

    b) see the last e-mail I sent you for two solutions to this issue.

    hth,
    epi

    > and in /etc/periodic there are dail weekly monthly and security
    > folders. I chose not to build sendmail at all, or any type of mail
    > server for that matter, but why would that affect it because a friend
    > of mine has a fresh install of 5.3 and he gets the logs, no problems.
    > Would a specific option in a custom kernel cause it to not send.
    >
    > syslog.conf shows
    >
    > security.* /var/log/security
    >
    > is there anything else I can show you guys/girls to help out?
    >
    > Thanks for the help
    > _______________________________________________
    > freebsd-questions@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    > To unsubscribe, send any mail to
    "freebsd-questions-unsubscribe@freebsd.org"
    >
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: David Kelly: "Re: Detected Ethernet Cards Fail To Configure At Boot"

    Relevant Pages

    • Re: [fw-wiz] syslog and network management
      ... Good idea to try a different syslogd. ... I don't need it to do any filtering (not by apps, ... recieve logs (checking to see if it needs to add host and timestamp to the ... we noticed a LOT of missing logs, when we changed to the default debian ...
      (Firewall-Wizards)
    • syslogd: Could not completely output pending messages while preparing re-configuration
      ... Every 3:10 in the morning on Sunday, it logs: ... It seems like syslogd is buffering some of the output. ... # if a non-loghost machine chooses to have authentication messages ...
      (comp.unix.solaris)
    • Re: Prevent remote root logins
      ... autorized admins log on remotely with their personal accounts created ... Example: user evilguy, ... uid=0, copies a special syslogd to the box, kills and restarts syslogd ... you're cracked, and logging won't help you, because the logs are no ...
      (comp.os.linux.security)
    • 2.6.10-rc3, syslogd hangs then processes get stuck in schedule_timeout
      ... usually after logs have been rotated and a dvd has been written. ... If the problem is detected early enough, syslogd can be manually killed ... least 2.6.8.1, both smp and nosmp. ... #3 0x0804f8dc in optind ...
      (Linux-Kernel)
    • Re: System Quits Responding-Swap Issue Or What?
      ... syslogd: dirtied inode 273702on hda3 ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
      (Debian-User)