OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: plogsumm reports

From: MrC (lists-postfixcappella.us)
Date: Thu Feb 01 2007 - 11:15:03 CST


> Rocco Scappatura wrote:
>
> > For example, I would like to get a report of the IPs whose try to
> > relay messages trhough my SMTP relay server.
> >
> > I know that a such report can not to say the truth as the IP can be
> > spoofed, but I want to have a view of the clients that (try to)
> > establish an SMTP connection with my SMTP server.
> >
> > Infact, every night between the 00:00 and the 01:00 I see an huge
> > number received by Postfix, and I can figure out why this
> happen and
> > who is the guilty..
> >
> > Can I get a such report from pflogsumm, or what tool can I
> use to get
> > such informations?
>
> I heartily recommend Mike Capella's Postfix filter for logwatch:
>
> http://www.mikecappella.com/logwatch/
>
> It has configurable levels of reporting, and very readable output.
>

Thanks for the plug Jorey.

Rocco - if you don't see what you need, feel free to reply on/off list and
I'll see what I can do to accommodate your request.

If you don't already have logwatch installed, you can use the script almost
standalone. See the README for details.

MrC