Filter/group some of postfix log output
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
logwatch (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: logwatch
On some of my systems, spam filtering with postfix+amavis is implemented. During its operation, it generates quite a lot of messages in the log, of the folowing kind :
postfix/
Summarising the logs, logwatch puts all of them into "Unmatched entries" subsection, so its "Postfix" section in the daily report bloats up the whole message, turning it into quite a big blanket with all of these "lost connection after DATA" lines listed as they are and often taking about 90% of the whole report.
I would propose to filter log records by string "lost connection after DATA (0 bytes)" and don't include these lines in the report, or extract IP addresses from these lines and output only a terse list of them. It would reduce the daily report size and make it shorter and more meaningful.
My Ubuntu is Hardy, and my logwatch is 7.3.6-1ubuntu1 .
This has been resolved since 2007-11-14, version: 1.36.13pre5 of postfix-logwatch.
Due to licensing differences the postfix filter in logwatch is been reverted to a version from several years ago.
Pick up the latest version of postfix-logwatch (under GPLv2) at :
http:// www.mikecappell a.com/logwatch
MrC