Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 385781 - sys-apps/logwatch doesn't parse SSH logs correctly
Summary: sys-apps/logwatch doesn't parse SSH logs correctly
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL: http://sourceforge.net/tracker/index....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-05 20:03 UTC by Muelli
Modified: 2013-01-16 18:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Muelli 2011-10-05 20:03:13 UTC
Logwatch mails many lines it didn't parse:

 **Unmatched Entries**
 SSH: Server;Ltype: Version;Remote: 83.143.40.122-35122;Protocol: 2.0;Client: libssh-0.11 : 1 time(s)
 SSH: Server;Ltype: Version;Remote: 194.105.17.167-56911;Protocol: 2.0;Client: libssh-0.1 : 1 time(s)
 SSH: Server;Ltype: Version;Remote: 50.7.233.202-53533;Protocol: 2.0;Client: libssh-0.1 : 1 time(s)
 SSH: Server;Ltype: Version;Remote: 83.143.40.122-58825;Protocol: 2.0;Client: libssh-0.11 : 1 time(s)
 SSH: Server;Ltype: Version;Remote: 83.143.40.122-60873;Protocol: 2.0;Client: libssh-0.11 : 1 time(s)


Reproducible: Always



Expected Results:  
I expected it to parse the lines and not mail them to me.

http://forums.gentoo.org/viewtopic-t-894104-start-0.html

http://sourceforge.net/tracker/index.php?func=detail&aid=3257504&group_id=312875&atid=1316824
Comment 1 Hans de Graaff gentoo-dev Security 2013-01-10 08:58:54 UTC
This has been fixed upstream but there has not been a release yet. Any chance that we can include this fix? Logwatch emails for any system with a publicly available SSH with HPN enabled (the default) can grow very large and thus unusable if the server sees a lot of traffic (or probes).
Comment 2 SpanKY gentoo-dev 2013-01-11 04:16:40 UTC
(In reply to comment #1)

feel free to make whatever commits you like to logwatch
Comment 3 Hans de Graaff gentoo-dev Security 2013-01-16 18:14:52 UTC
Hmm, actually the fix hasn't been applied upstream, but since the patch is straightforward I've added it to the tree: logwatch-7.4.0-r1