OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: plogsumm reports

From: Jorey Bump (listjoreybump.com)
Date: Thu Feb 01 2007 - 11:10:18 CST


Rocco Scappatura wrote:

> For example, I would like to get a report of the IPs whose try to relay
> messages trhough my SMTP relay server.
>
> I know that a such report can not to say the truth as the IP can be
> spoofed, but I want to have a view of the clients that (try to)
> establish an SMTP connection with my SMTP server.
>
> Infact, every night between the 00:00 and the 01:00 I see an huge number
> received by Postfix, and I can figure out why this happen and who is the
> guilty..
>
> Can I get a such report from pflogsumm, or what tool can I use to get
> such informations?

I heartily recommend Mike Capella's Postfix filter for logwatch:

  http://www.mikecappella.com/logwatch/

It has configurable levels of reporting, and very readable output.