[Logcheck-devel] Bug#277782: logcheck reports "Could not run logtail or save output" and fails

curious curious at curious.org
Fri Oct 22 09:02:59 UTC 2004


Package: logcheck
Version: 1.2.28
Severity: important


logcheck sends the following email, without the expected log data:
Warning: If you are seeing this message, your log files may not have
been
checked!

Details:
Could not run logtail or save output

Check temporary directory: /tmp/logcheck.mNAra3

declare -x HOME="/var/lib/logcheck"
declare -x LANG="en_US"
declare -x LANGUAGE="en_US:en_GB:en"
declare -x LOGNAME="logcheck"
declare -x MAILTO="root"
declare -x OLDPWD
declare -x
PATH="/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin"
declare -x PWD="/var/lib/logcheck"
declare -x SHELL="/bin/sh"
declare -x SHLVL="2"

{{{{Inserting all sorts of related information that may or maynot be
helpful ;) }}}}

----
# whereis logtail;
logtail: /usr/sbin/logtail /usr/share/man/man8/logtail.8.gz


-----
# logtail
No logfile to read. Use -f switch.
{logtail -f /var/log/syslog shows the syslog and adds syslog.offset to
/var/log directory}


-----


# ls -l /var/log/syslog
-rw-r-----  1 root adm 2450 2004-10-22 04:53 /var/log/syslog
-----
# cat /etc/group | grep logcheck
adm:x:4:logcheck
logcheck:x:104:


-----
# su -s /bin/bash -c "/usr/sbin/logcheck -d" logcheck

D: [1098435481] Turning debug mode on
D: [1098435481] Sourcing - /etc/logcheck/logcheck.conf
D: [1098435481] Finished getopts c:dhH:l:L:m:opr:RsS:tTuvw
D: [1098435481] Trying to get lockfile: /var/lock/logcheck.lock
D: [1098435481] Running lockfile-touch /var/lock/logcheck.lock
D: [1098435481] cleanrules: /etc/logcheck/cracking.d/logcheck
D: [1098435481] cleanrules: /etc/logcheck/violations.d/logcheck
D: [1098435481] cleanrules: /etc/logcheck/violations.d/su
D: [1098435481] cleanrules: /etc/logcheck/violations.d/sudo
D: [1098435481] cleanrules: /etc/logcheck/violations.ignore.d/hotplug
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-bind
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-courier
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-cyrus
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-innd
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-postfix
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-sendmail_tmp
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-spamd
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-squid
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-su
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-sudo
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-usb
D: [1098435481] cleanrules:
/etc/logcheck/violations.ignore.d/logcheck-winbind
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/anon-proxy
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/arpwatch
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/automount
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/bind
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/courier
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/cron
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/cyrus
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/dhclient
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/dhcp
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/dovecot
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/gps
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/imapproxy
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/imp
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/innd
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/ipppd
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/isdnlog
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/isdnutils
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/logcheck
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/nagios
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/nfs
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/nntpcache
D: [1098435481] cleanrules: /etc/logcheck/ignore.d.server/ntp
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/oidentd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/openvpn
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/pdns
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/perdition
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/postfix
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/ppp
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/proftpd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/rpc_statd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/rsnapshot
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/samba
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/scponly
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/spamd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/squid
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/ssh
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/stunnel
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/ucd-snmp
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/uptimed
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.server/userv
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/bind
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/cron
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/imap
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/logcheck
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/postfix
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/ppp
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/proftpd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/qpopper
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/squid
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/ssh
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/stunnel
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/sysklogd
D: [1098435482] cleanrules: /etc/logcheck/ignore.d.paranoid/telnetd
D: [1098435482] logoutput called with file: /var/log/syslog
D: [1098435482] Running logtail: /var/log/syslog
D: [1098435482] error: Killing lockfile-touch - 8567
D: [1098435482] error: Removing lockfile: /var/lock/logcheck.lock
D: [1098435482] Error: Could not run logtail or save output
D: [1098435482] Cleanup: Removing - /tmp/logcheck.fa1vVs



-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: powerpc (ppc)
Kernel: Linux 2.6.8-powerpc
Locale: LANG=en_US, LC_CTYPE=en_US

Versions of packages logcheck depends on:
ii  adduser          3.59                    Add and remove users and groups
ii  cron             3.0pl1-86               management of regular background p
ii  debconf [debconf 1.4.30.8                Debian configuration management sy
ii  debianutils      2.8.4                   Miscellaneous utilities specific t
ii  exim [mail-trans 3.36-11                 An MTA (Mail Transport Agent)
ii  lockfile-progs   0.1.10                  Programs for locking and unlocking
ii  logcheck-databas 1.2.28                  A database of system log rules for
ii  logtail          1.2.28                  Print log file lines that have not
ii  mailx            1:8.1.2-0.20040524cvs-1 A simple mail user agent
ii  perl             5.8.4-2.3               Larry Wall's Practical Extraction 
ii  sysklogd [system 1.4.1-15                System Logging Daemon

-- debconf information:
  logcheck/changes:
* logcheck/install-note:





More information about the Logcheck-devel mailing list