PDA

Bekijk de volledige versie : setting up email notification from syslog.log?



bibi-phoque
06-03-2009, 14:12
Hello,
My syslog.log would reach 100 MB per week and I usually just look for ftp and http access. To make it easier (as it is such a big file), I would like to setup triggers, for instance send an email when somebody connects to my ftp.
Anybody got a script that could do that running on is wl500?
Cheers,
Yann

bibi-phoque
09-03-2009, 15:39
Anybody?
:(

velcrow
10-03-2009, 13:10
Don't know if this will help - but I used it to send emails to myself from the asus

http://wl500g.info/showthread.php?p=119188&highlight=velcrow#post119188

bibi-phoque
18-03-2009, 11:48
Thanks, this will help to generate the email, however I have no idea how to setup the trigger.
Also, do you know how to stop iptables event going to the syslog.log? This is crazy, my syslog is about 300MB and I cleared it last week!

bibi-phoque
18-03-2009, 12:02
Actually, what is the appropriate level for syslog, when I'm only interested in ftp login and http activity? Right now my level is 7, I just switched it to 6 and it didn't change anything.

My syslog.log is spammed with iptables logs, making it unreadable. I get this 2 or 3 times per second:

Mar 18 14:51:20 kernel: DROP IN=br0 OUT= MAC= SRC=192.168.1.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0xC0 TTL=1 ID=37041 PROTO=2
Mar 18 14:51:26 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:62 SRC=10.67.128.1 DST=255.255.255.255 LEN=354 TOS=0x00 PREC=0x00 TTL=255 ID=18761 PROTO=UDP SPT=67 DPT=68 LEN=334
Mar 18 14:51:36 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:62 SRC=10.67.128.1 DST=255.255.255.255 LEN=354 TOS=0x00 PREC=0x00 TTL=255 ID=18888 PROTO=UDP SPT=67 DPT=68 LEN=334
Mar 18 14:51:37 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:62 SRC=10.67.128.1 DST=255.255.255.255 LEN=354 TOS=0x00 PREC=0x00 TTL=255 ID=18922 PROTO=UDP SPT=67 DPT=68 LEN=334
Mar 18 14:51:37 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:62 SRC=10.67.128.1 DST=255.255.255.255 LEN=354 TOS=0x00 PREC=0x00 TTL=255 ID=18928 PROTO=UDP SPT=67 DPT=68 LEN=334
Mar 18 14:51:47 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19155 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:51:47 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19158 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:51:59 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19375 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:51:59 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:60 SRC=10.67.128.1 DST=255.255.255.255 LEN=352 TOS=0x00 PREC=0x00 TTL=255 ID=19378 PROTO=UDP SPT=67 DPT=68 LEN=332
Mar 18 14:52:03 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19437 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:52:04 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:60 SRC=10.67.128.1 DST=255.255.255.255 LEN=352 TOS=0x00 PREC=0x00 TTL=255 ID=19453 PROTO=UDP SPT=67 DPT=68 LEN=332
Mar 18 14:52:13 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19652 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:52:13 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:60 SRC=10.67.128.1 DST=255.255.255.255 LEN=352 TOS=0x00 PREC=0x00 TTL=255 ID=19670 PROTO=UDP SPT=67 DPT=68 LEN=332
Mar 18 14:52:21 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:62 SRC=10.67.128.1 DST=255.255.255.255 LEN=354 TOS=0x00 PREC=0x00 TTL=255 ID=19847 PROTO=UDP SPT=67 DPT=68 LEN=334
Mar 18 14:52:28 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=19948 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:52:30 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:60 SRC=10.67.128.1 DST=255.255.255.255 LEN=352 TOS=0x00 PREC=0x00 TTL=255 ID=19989 PROTO=UDP SPT=67 DPT=68 LEN=332
Mar 18 14:52:56 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=20453 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:52:56 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:64 SRC=10.67.128.1 DST=255.255.255.255 LEN=356 TOS=0x00 PREC=0x00 TTL=255 ID=20456 PROTO=UDP SPT=67 DPT=68 LEN=336
Mar 18 14:53:03 kernel: ACCEPT IN=vlan1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1d:a2:e7:dd:05:08:00:45:0 0:01:60 SRC=10.67.128.1 DST=255.255.255.255 LEN=352 TOS=0x00 PREC=0x00 TTL=255 ID=20645 PROTO=UDP SPT=67 DPT=68 LEN=332