Your message dated Tue, 8 Aug 2017 21:41:44 +0200
with message-id <eac85f4e-67f0-5540-efac-0f11cdce1...@debian.org>
and subject line Re: logcheck: Regular expressions for rsyslog no longer match
has caused the Debian Bug report #848963,
regarding logcheck: Regular expressions for rsyslog no longer match
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
848963: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848963
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: logcheck
Version: 1.3.17
Severity: normal

Currently, rsyslog has the following regexps:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] start$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] exiting on 
signal [0-9]+.$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] rsyslogd 
was HUPed$

However, for a few weeks the following lines appear in the logs:
Dec 19 17:26:51 samd liblogging-stdlog:  [origin software="rsyslogd" 
swVersion="8.23.0" x-pid="806" x-info="http://www.rsyslog.com";] start
Dec 19 17:31:52 samd liblogging-stdlog:  [origin software="rsyslogd" 
swVersion="8.23.0" x-pid="806" x-info="http://www.rsyslog.com";] rsyslogd was 
HUPed

(Note rsyslogd → liblogging-stdlog)

-- System Information:
Debian Release: stretch/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) (ignored: LC_ALL 
set to de_DE.UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages logcheck depends on:
ii  adduser                                    3.115
ii  cron                                       3.0pl1-128
ii  exim4-daemon-light [mail-transport-agent]  4.88~RC6-1
ii  lockfile-progs                             0.1.17
ii  logtail                                    1.3.17
ii  mime-construct                             1.11+nmu2
ii  rsyslog [system-log-daemon]                8.23.0-2

Versions of packages logcheck recommends:
ii  logcheck-database  1.3.17

Versions of packages logcheck suggests:
pn  syslog-summary  <none>

-- Configuration Files:
/etc/logcheck/logcheck.conf [Errno 13] Keine Berechtigung: 
u'/etc/logcheck/logcheck.conf'
/etc/logcheck/logcheck.logfiles [Errno 13] Keine Berechtigung: 
u'/etc/logcheck/logcheck.logfiles'

-- no debconf information

-- 
      Dr. Helge Kreutzmann                     deb...@helgefjell.de
           Dipl.-Phys.                   http://www.helgefjell.de/debian.php
        64bit GNU powered                     gpg signed mail preferred
           Help keep free software "libre": http://www.ffii.de/

Attachment: signature.asc
Description: Digital signature


--- End Message ---
--- Begin Message ---
Version: 8.28.0-1

On Wed, 21 Dec 2016 11:16:00 +0100 Helge Kreutzmann
<deb...@helgefjell.de> wrote:
> Package: logcheck
> Version: 1.3.17
> Severity: normal
> 
> Currently, rsyslog has the following regexps:
> ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
> swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] start$
> ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
> swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] exiting 
> on signal [0-9]+.$
> ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" 
> swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] rsyslogd 
> was HUPed$
> 
> However, for a few weeks the following lines appear in the logs:
> Dec 19 17:26:51 samd liblogging-stdlog:  [origin software="rsyslogd" 
> swVersion="8.23.0" x-pid="806" x-info="http://www.rsyslog.com";] start
> Dec 19 17:31:52 samd liblogging-stdlog:  [origin software="rsyslogd" 
> swVersion="8.23.0" x-pid="806" x-info="http://www.rsyslog.com";] rsyslogd was 
> HUPed
> 

I guess this was a bug in rsyslog, that the process name was not
properly set. I.e. a proper fix is not to change the logcheck rules but
to set the process name.
With 8.28.0 this seems to be the case, so closing this bug report:

Aug 08 21:41:25 pluto rsyslogd[24624]:  [origin software="rsyslogd"
swVersion="8.28.0" x-pid="24624" x-info="http://www.rsyslog.com";]
rsyslogd was HUPed

Michael

-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

Attachment: signature.asc
Description: OpenPGP digital signature


--- End Message ---

Reply via email to