Search found 6 matches

by rick111
30 Oct 2015, 11:25
Forum: General Discussion (csf)
Topic: postfix sasl custom regex not working
Replies: 4
Views: 7738

Re: postfix sasl custom regex not working

reference as I come back to this post to help configure the rule, you change the custom_log location in /etc/csf/csf.conf

and for debian the mail file is /var/log/mail.log

to restart csf
su
csf -r (however i think it's lfd you need to restart which i did via webmin)
by rick111
10 Oct 2014, 09:29
Forum: General Discussion (csf)
Topic: logscanner ignore help
Replies: 1
Views: 2241

Re: logscanner ignore help

^(\S+|\S+\s+\d+\s+\S+) [^\s\.]+ [^\s\.]+ mail auditd\[\d+\]: Audit daemon rotating log files

If I don't post back again, it's because the above has worked.
by rick111
04 Oct 2014, 06:47
Forum: General Discussion (csf)
Topic: logscanner ignore help
Replies: 1
Views: 2241

logscanner ignore help

/var/log/messages:
Oct 3 14:57:01 mail auditd[1882]: Audit daemon rotating log files

ignore rule: ^(\S+|\S+\s+\d+\s+\S+) [^\s\.]+ mail auditd\[\d+\]:

Still reporting though?
by rick111
09 Sep 2013, 17:00
Forum: General Discussion (csf)
Topic: postfix sasl custom regex not working
Replies: 4
Views: 7738

Re: postfix sasl custom regex not working

I was editing /etc/cfs/regex.custom.pm instead of /usr/local/csf/bin/regex.custom.pm..................

fixed now
by rick111
09 Sep 2013, 14:30
Forum: General Discussion (csf)
Topic: postfix sasl custom regex not working
Replies: 4
Views: 7738

Re: postfix sasl custom regex not working

So something strange happened over the weekend. With all my tests I couldn't ban SASL fails, but then I got this. Sep 8 19:41:17 li622-171 postfix/smtpd[16954]: warning: unknown[89.248.172.122]: SASL LOGIN authentication failed: authentication failure Sep 8 19:43:29 li622-171 postfix/smtpd[16954]: w...
by rick111
05 Sep 2013, 14:08
Forum: General Discussion (csf)
Topic: postfix sasl custom regex not working
Replies: 4
Views: 7738

postfix sasl custom regex not working

Hi I've read through quite a few posts on this forum and no one else seems to have the issue I'm having. I can't even get csf to register the postfix sasl attacks. Centos 6.3 /etc/csf/regex.custom.pm if (($lgfile eq $config{CUSTOM1_LOG}) and ($line =~ /^\S+\s+\d+\s+\S+ \S+ postfix\/smtpd\[\d+\]: war...