logo
Free, unlimited AI code reviews that run on commit
git-lrc git-lrc GitHub Install Now We'd appreciate a star git-lrc - Free, unlimited AI code reviews that run on commit | Product Hunt git-lrc - Free, unlimited AI code reviews that run on commit | Product Hunt

logcheck — program to scan system logs for interesting lines

Author

       logcheck is developed by Debian logcheck Team at: https://salsa.debian.org/debian/logcheck.

       This manual page was written by Jon Middleton.

                                                                                                     Logcheck(8)

Description

       The  logcheck program helps spot problems and security violations in your logfiles automatically and will
       send the results to you periodically in an e-mail. By default logcheck runs as an hourly cronjob just off
       the hour and after every reboot.

       logcheck supports three level of filtering: "paranoid" is  for  high-security  machines  running  as  few
       services as possible. Don't use it if you can't handle its verbose messages.  "server" is the default and
       contains  rules  for many different daemons.  "workstation" is for sheltered machines and filters most of
       the messages.  The ignore rules work in additive manner. "paranoid" rules  are  also  included  at  level
       "server". "workstation" level includes both "paranoid" and "server" rules.

       The messages reported are sorted into three layers, system events, security events and attack alerts. The
       verbosity  of  system  events  is  controlled by which level you choose, paranoid, server or workstation.
       However, security events and attack alerts are not affected by this.

Examples

logcheck can be invoked directly thanks to su(8) or sudo(8), which change  the  user  ID.  The  following
       example checks the logfiles without updating the offset and outputs everything to STDOUT.

       sudo -u logcheck logcheck -o -t

Exit Status

       0 upon success; 1 upon failure

Files

       /etc/logcheck/logcheck.conf is the main configuration file.

       /etc/logcheck/logcheck.logfiles is the list of files to monitor.

       /etc/logcheck/logcheck.logfiles.d is the directory of lists of files to monitor.

       /usr/share/doc/logcheck-database/README.logcheck-database.gz for hints on how to write, test and maintain
       rules.

Name

       logcheck — program to scan system logs for interesting lines

Options

       A summary of options is included below.

       -cCFG    Overrule default configuration file.

       -d        Debug mode.

       -h        Show usage information.

       -H        Use this hostname string in the subject of logcheck mail.

       -lLOG    Run logfile through logcheck.

       -LCFG    Overrule default logfiles list.

       -DDIR    Overrule default logfiles lists directory.

       -mMAIL   Mail report to recipient.

       -o        STDOUT mode, not sending mail.

       -p        Set the report level to "paranoid".

       -rDIR    Overrule default rules directory.

       -R        Adds "Reboot:" to the email subject line.

       -s        Set the report level to "server".

       -SDIR    Overrule default state directory.

       -t        Testing mode does not update offset.

       -T        Do not remove the TMPDIR.

       -u        Enable syslog-summary.

       -v        Print current version.

       -w        Set the report level to "workstation".

See Also

logtail(8)

Synopsis

logcheck [OPTIONS]

See Also