lfd seems to stop checking after log rotation
Posted: 08 Feb 2007, 00:22
Running latest csf, RHEL 4.4, latest kernel, generic linux
We have an application that ssh's into a server every hour. We'll see this being logged in lfd.log and ignored as it should, then suddenly the logging stops in lfd.log, even though the logins continue. During these times, actual brute force attacks go unblocked as well. A "service lfd restart" seems to jumpstart things again.
After examining the times, it seems to coincide with log rotations each night. If we /dev/null a logfile does this cause lfd a problem? We use a simple devnull copy for our system logs after being zipped. Our workaround for now is a nightly restart of lfd.
Rob
We have an application that ssh's into a server every hour. We'll see this being logged in lfd.log and ignored as it should, then suddenly the logging stops in lfd.log, even though the logins continue. During these times, actual brute force attacks go unblocked as well. A "service lfd restart" seems to jumpstart things again.
After examining the times, it seems to coincide with log rotations each night. If we /dev/null a logfile does this cause lfd a problem? We use a simple devnull copy for our system logs after being zipped. Our workaround for now is a nightly restart of lfd.
Rob