[Logwatch] ftpd-messages.conf question

Fishbytes Admin contact@fishbytes.net
Sat, 15 Jun 2002 09:46:47 -0400


This is a multi-part message in MIME format.

------=_NextPart_000_000F_01C21451.910F4A00
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

Given the logfile sample below, I am trying to get ftp session info in my
logwatch report.  I am currently only getting lines from ftpd (line 1 in
sample below).  My ftpd-messages.conf contains the line:

*OnlyService = ftpd

So I added the line:

*OnlyService = ftp

This did not do the trick as I had expected ... still only getting ftpd
info.  Please let me know what I can do to ensure line's such as the second
one below show up in my logwatch report.

Thanx in advance,

Fishbytes

<start /var/log/messages snippet>
Jun 15 09:12:54 someserver ftpd[1071]: wu-ftpd - TLS settings: control
allow, client_cert allow, data allow
Jun 15 09:12:56 someserver ftp(pam_unix)[1071]: session opened for user
someuser by (uid=0)
<end /var/log/messages snippet>

------=_NextPart_000_000F_01C21451.910F4A00
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR></HEAD>
<BODY>
<DIV><FONT face=3DVerdana size=3D2>Given the logfile sample below, I am =
trying to=20
get ftp session info in my logwatch report.&nbsp; I am currently only =
getting=20
lines from ftpd (line 1 in sample below).&nbsp; My ftpd-messages.conf =
contains=20
the line: </FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>*OnlyService =3D ftpd</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>So I added the line:</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>*OnlyService =3D ftp</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>This did not do the trick as I had =
expected ...=20
still only getting ftpd info.&nbsp; Please let me know what I can do to =
ensure=20
line's such as the second one below show up in my logwatch =
report.</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>Thanx in advance,</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>Fishbytes</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DVerdana size=3D2>&lt;start /var/log/messages =
snippet&gt;<BR>Jun 15=20
09:12:54 someserver ftpd[1071]: wu-ftpd - TLS settings: control allow,=20
client_cert allow, data allow<BR>Jun 15 09:12:56 someserver =
ftp(pam_unix)[1071]:=20
session opened for user someuser by (uid=3D0)<BR>&lt;end =
/var/log/messages=20
snippet&gt;</FONT></DIV></BODY></HTML>

------=_NextPart_000_000F_01C21451.910F4A00--