Page 1 of 1

logscanner ignore help

Posted: 04 Oct 2014, 06:47
by rick111
/var/log/messages:
Oct 3 14:57:01 mail auditd[1882]: Audit daemon rotating log files

ignore rule: ^(\S+|\S+\s+\d+\s+\S+) [^\s\.]+ mail auditd\[\d+\]:

Still reporting though?

Re: logscanner ignore help

Posted: 10 Oct 2014, 09:29
by rick111
^(\S+|\S+\s+\d+\s+\S+) [^\s\.]+ [^\s\.]+ mail auditd\[\d+\]: Audit daemon rotating log files

If I don't post back again, it's because the above has worked.