[Logcheck-devel] Bug#616659: Ignore rule for "rsyslog HUPed" not valid anymore?

Andrei Popescu andreimpopescu at gmail.com
Sun Mar 6 10:59:23 UTC 2011


Package: logcheck-database
Version: 1.3.13
Severity: minor

Hi,

It seems the rule

^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] rsyslogd was HUPed, type '(restart|lightweight)'\.$

does not catch rsyslog HUP's anymore, AFAICT due to the ", type..." part 
which is not present anymore.

Thanks,
Andrei

----- Forwarded message from logcheck system account <xxxxxxxxxxxxxx at xxxxxxx> -----

Date: Fri,  4 Mar 2011 07:02:03 +0200 (EET)
From: logcheck system account <xxxxxxxxxxxxxx at xxxxxxx>
To: xxxxxxxxxxxxxx at xxxxxxx
Subject: xxxxx.xxxxxxx 2011-03-04 07:02 System Events

This email is sent by logcheck. If you no longer wish to receive
such mails, you can either deinstall the logcheck package or modify
its configuration file (/etc/logcheck/logcheck.conf).

System Events
=-=-=-=-=-=-=
Mar  4 06:25:14 xxxxx rsyslogd: [origin software="rsyslogd" swVersion="5.7.6" x-pid="1348" x-info="http://www.rsyslog.com"] rsyslogd was HUPed


----- End forwarded message -----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 490 bytes
Desc: Digital signature
URL: <http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20110306/74ecb90c/attachment.pgp>


More information about the Logcheck-devel mailing list