Re: [logs] SWATCH configuration

From: Ed Schmollinger (schmolliat_private)
Date: Sat Jan 04 2003 - 09:48:48 PST

  • Next message: Rainer Gerhards: "RE: [logs] Syslog payload format"

    On Fri, Jan 03, 2003 at 05:28:41PM +0000, swatch swatch wrote:
    > I ran 4 different SWATCH instances for the different log files (all with 
    > --daemon at the end) and all processes are running successfully from what i 
    > can tell.  For the first time I was redirected back to the root prompt each 
    > time.  Although, I am still not getting emails into my inbox.  My swatchrc 
    > file is the same as it was in my first posting.  I am stumped unless it is 
    > a firewall issue.  The box SWATCH is running on is on a different subnet 
    > than what I am on.  However, I have configured sendmail to forward emails 
    > to me with a smarthost.  I know this works because i get nightly Tripwire 
    > reports from the same box SWATCH is on.  Therefore, I don't know what I am 
    
    Try running it without --daemon and see if you get any output.  You have
    echo statements in there, so anything that you are expecting to get mail
    about should appear on stdout.
    
    > missing.  Any thoughts?  By the way, each time I edit my swatchrc file i 
    > kill the perl and SWATCH processes and then restart them once the editing 
    > is finished.  I assume that is fine?
    
    Yes, kill-and-restart is necessary.
    
    -- 
    Ed Schmollinger - schmolliat_private
    
    
    

    _______________________________________________ LogAnalysis mailing list LogAnalysisat_private http://lists.shmoo.com/mailman/listinfo/loganalysis



    This archive was generated by hypermail 2b30 : Sat Jan 04 2003 - 10:44:38 PST