From da568d73fa99d0d99dce9a79703834d789a4cd47 Mon Sep 17 00:00:00 2001 From: Orion Poplawski Date: Mon, 6 Apr 2015 16:47:44 -0600 Subject: [PATCH] Add missing ignoreregex lines to avoid warnings --- config/filter.d/ejabberd-auth.conf | 2 ++ config/filter.d/groupoffice.conf | 2 +- config/filter.d/named-refused.conf | 2 ++ config/filter.d/nsd.conf | 2 ++ config/filter.d/postfix-sasl.conf | 2 ++ config/filter.d/recidive.conf | 2 ++ config/filter.d/squid.conf | 2 +- 7 files changed, 12 insertions(+), 2 deletions(-) diff --git a/config/filter.d/ejabberd-auth.conf b/config/filter.d/ejabberd-auth.conf index 1e15ebc4..d4de0e81 100644 --- a/config/filter.d/ejabberd-auth.conf +++ b/config/filter.d/ejabberd-auth.conf @@ -17,3 +17,5 @@ # Values: TEXT # failregex = ^(?:\.\d+)? \[info\] <0\.\d+\.\d>@ejabberd_c2s:wait_for_feature_request:\d+ \([^\)]+\) Failed authentication for \S+ from IP $ + +ignoreregex = diff --git a/config/filter.d/groupoffice.conf b/config/filter.d/groupoffice.conf index d5a4e4d8..166c5fea 100644 --- a/config/filter.d/groupoffice.conf +++ b/config/filter.d/groupoffice.conf @@ -8,7 +8,7 @@ failregex = ^\[\]LOGIN FAILED for user: "\S+" from IP: $ - +ignoreregex = # Author: Daniel Black diff --git a/config/filter.d/named-refused.conf b/config/filter.d/named-refused.conf index be997bd4..2d6d8307 100644 --- a/config/filter.d/named-refused.conf +++ b/config/filter.d/named-refused.conf @@ -38,6 +38,8 @@ failregex = ^%(__line_prefix)s(\.\d+)?( error:)?\s*client #\S+( \([\S.]+\) ^%(__line_prefix)s(\.\d+)?( error:)?\s*client #\S+( \([\S.]+\))?: zone transfer '\S+/AXFR/\w+' denied\s*$ ^%(__line_prefix)s(\.\d+)?( error:)?\s*client #\S+( \([\S.]+\))?: bad zone transfer request: '\S+/IN': non-authoritative zone \(NOTAUTH\)\s*$ +ignoreregex = + # DEV Notes: # Trying to generalize the # structure which is general to capture general patterns in log diff --git a/config/filter.d/nsd.conf b/config/filter.d/nsd.conf index cd4ce35f..70b41ca4 100644 --- a/config/filter.d/nsd.conf +++ b/config/filter.d/nsd.conf @@ -24,3 +24,5 @@ _daemon = nsd failregex = ^\[\]%(__prefix_line)sinfo: ratelimit block .* query TYPE255$ ^\[\]%(__prefix_line)sinfo: .* refused, no acl matches\.$ + +ignoreregex = diff --git a/config/filter.d/postfix-sasl.conf b/config/filter.d/postfix-sasl.conf index d232f86e..ed44677c 100644 --- a/config/filter.d/postfix-sasl.conf +++ b/config/filter.d/postfix-sasl.conf @@ -11,4 +11,6 @@ _daemon = postfix/smtpd failregex = ^%(__prefix_line)swarning: [-._\w]+\[\]: SASL (?:LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed(: [ A-Za-z0-9+/]*={0,2})?\s*$ +ignoreregex = + # Author: Yaroslav Halchenko diff --git a/config/filter.d/recidive.conf b/config/filter.d/recidive.conf index 13d2f53a..ebd030a1 100644 --- a/config/filter.d/recidive.conf +++ b/config/filter.d/recidive.conf @@ -29,4 +29,6 @@ _jailname = recidive failregex = ^(%(__prefix_line)s|,\d{3} fail2ban.actions%(__pid_re)s?:\s+)WARNING\s+\[(?!%(_jailname)s\])(?:.*)\]\s+Ban\s+\s*$ +ignoreregex = + # Author: Tom Hendrikx, modifications by Amir Caspi diff --git a/config/filter.d/squid.conf b/config/filter.d/squid.conf index da282692..e26cab9c 100644 --- a/config/filter.d/squid.conf +++ b/config/filter.d/squid.conf @@ -7,7 +7,7 @@ failregex = ^\s+\d\s\s+[A-Z_]+_DENIED/403 .*$ ^\s+\d\s\s+NONE/405 .*$ - +ignoreregex = # Author: Daniel Black