Project

General

Profile

Actions

Bug #12747

open

System log is filled by sshguard

Added by Steve Wheeler about 2 years ago. Updated about 1 month ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Logging
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Plus-Next
Release Notes:
Default
Affected Version:
2.6.0
Affected Architecture:
All

Description

sshguard has to restart when he logs are rotated in 2.6 in order to monitor the current file. When it does so it logs the service restart.
In an even moderately busy firewall this can produce a lot of log entries to the point it starts to hide other more important logs.
It appears to restart whenever any log is rotated, is that actually required?

For example on a test system where an IPSec tunnel is configured but never connects the ipsec log rotates frequently resulting in a system log:

Jan 31 00:25:00     sshguard     29496     Exiting on signal.
Jan 31 00:25:00     sshguard     9940     Now monitoring attacks.
Jan 31 03:17:00     sshguard     9940     Exiting on signal.
Jan 31 03:17:00     sshguard     60321     Now monitoring attacks.
Jan 31 06:09:00     sshguard     60321     Exiting on signal.
Jan 31 06:09:00     sshguard     83661     Now monitoring attacks.
Jan 31 09:01:00     sshguard     83661     Exiting on signal.
Jan 31 09:01:00     sshguard     93166     Now monitoring attacks.
Jan 31 11:53:00     sshguard     93166     Exiting on signal.
Jan 31 11:53:00     sshguard     94019     Now monitoring attacks. 

It's possible to mitigate this to some extent by increasing the log file size reducing the rotation frequency.


Files

clipboard-202204221938-uajpw.png (9.84 KB) clipboard-202204221938-uajpw.png Marle Cua-chin, 04/22/2022 06:38 AM
clipboard-202206300621-7gjov.png (135 KB) clipboard-202206300621-7gjov.png Franck Ck, 06/30/2022 05:21 AM
clipboard-202309230719-waesz.png (85.5 KB) clipboard-202309230719-waesz.png Jonathan Stafford, 09/23/2023 11:19 AM
clipboard-202309230720-yhwfb.png (21.2 KB) clipboard-202309230720-yhwfb.png Jonathan Stafford, 09/23/2023 11:20 AM
Actions

Also available in: Atom PDF