Scott Silva wrote:

> > So...  Anyone know what might have changed to stop logwatch from
>  
>
>>gathering as much useful information?  Did one of the log formats
>>change in either Sendmail or MdF that might cause it to not be
>>grepped out properly by logwatch?
>>
>>Of course, that wouldn't have stopped Logwatch from gathering the
>>useful summary information that it used to about top relays,
>>volumes handled, etc.
>>
>>Thanks,
>>
>>-Philip
>>
>>
>>    
>>
>You might increase the default logging level. In
>/etc/logwatch/conf/logwatch.conf add the line
>Detail = Medium
>  
>

That turns it up for everything, and the Sendmail logging
still skips a lot of Milter stuff.  I'm convinced that Milters
should have their own logging rules.

 
--------------------- sendmail Begin ------------------------ 

 
 
 STATISTICS
 ----------
 
 Bytes Transferred:      2503233
 Messages Processed:     467
 Addressed Recipients:   478
 
 Headers added by Milter:
     X-Scanned-By: MIMEDefang : 465
 
 SMTP SESSION, MESSAGE, OR RECIPIENT ERRORS
 ------------------------------------------
 
 Client quit before communicating: [Occurrences >= 1]
     [211.22.77.11]   1 Time(s)
        Total:  1
 
 1 warnings of delayed delivery after 4 hours
 
 Mail Rejected:
     Message rejected; scored too high on the Spam test.:
         To: <[EMAIL PROTECTED]>: 1 Time(s)
     Service unavailable:
         To: <[EMAIL PROTECTED]>,<[EMAIL PROTECTED]>: 1 Time(s)
         To: <[EMAIL PROTECTED]>: 1 Time(s)
        Total:  3
 
 Mail Deferred:
     451 4.7.1 Please try again later:
         To: <[EMAIL PROTECTED]>: 1 Time(s)
         To: <[EMAIL PROTECTED]>: 3 Time(s)
     Connection timed out with ns.chinanet.cn.net.:
         To: <[EMAIL PROTECTED]>: 4 Time(s)
     Connection timed out with wanadoo.co.uk.:
         To: <[EMAIL PROTECTED]>: 45 Time(s)
        Total:  53
 
 Total SMTP Session, Message, and Recipient Errors handled by Sendmail:  58
 
 **Unmatched Entries**
    Milter delete (noop): header: X-Spam-Score: 430 Time(s)
    ruleset=check_relay, arg1=[193.120.103.14], arg2=193.120.103.14, 
relay=hiteched-adsl.adsl.esat.net [193.120.103.14] (may be forged), reject=421 
4.3.2 Connection rate limit exceeded.: 7 Time(s)
    ruleset=check_relay, arg1=[221.210.133.68], arg2=221.210.133.68, 
relay=[221.210.133.68], reject=421 4.3.2 Connection rate limit exceeded.: 3 
Time(s)
    ruleset=check_relay, arg1=[221.211.24.185], arg2=221.211.24.185, 
relay=[221.211.24.185], reject=421 4.3.2 Connection rate limit exceeded.: 3 
Time(s)
    ruleset=check_relay, arg1=[222.171.46.134], arg2=222.171.46.134, 
relay=[222.171.46.134], reject=421 4.3.2 Connection rate limit exceeded.: 3 
Time(s)
    ruleset=check_relay, arg1=[221.221.172.34], arg2=221.221.172.34, 
relay=[221.221.172.34], reject=421 4.3.2 Connection rate limit exceeded.: 2 
Time(s)
    ruleset=check_relay, arg1=junior.physik.fu-berlin.de, arg2=130.133.35.30, 
relay=junior.physik.fu-berlin.de [130.133.35.30], reject=421 4.3.2 Connection 
rate limit exceeded.: 1 Time(s)
    ruleset=check_relay, arg1=[222.171.42.39], arg2=222.171.42.39, 
relay=[222.171.42.39], reject=421 4.3.2 Connection rate limit exceeded.: 1 
Time(s)
    ruleset=check_relay, arg1=[222.171.220.50], arg2=222.171.220.50, 
relay=[222.171.220.50], reject=421 4.3.2 Connection rate limit exceeded.: 1 
Time(s)
    ruleset=check_relay, arg1=ns0.itmm.net, arg2=210.251.89.34, 
relay=ns0.itmm.net [210.251.89.34], reject=421 4.3.2 Connection rate limit 
exceeded.: 1 Time(s)
    ruleset=check_relay, arg1=gate-isdn.admin.theplanet.net, 
arg2=195.92.70.130, relay=gate-isdn.admin.theplanet.net [195.92.70.130], 
reject=421 4.3.2 Connection rate limit exceeded.: 1 Time(s)
    ruleset=check_relay, arg1=205.red-213-37-217.user.auna.net, 
arg2=213.37.217.205, relay=205.red-213-37-217.user.auna.net [213.37.217.205], 
reject=421 4.3.2 Connection rate limit exceeded.: 1 Time(s)
 
 ---------------------- sendmail End ------------------------- 

_______________________________________________
NOTE: If there is a disclaimer or other legal boilerplate in the above
message, it is NULL AND VOID.  You may ignore it.

Visit http://www.mimedefang.org and http://www.roaringpenguin.com
MIMEDefang mailing list [email protected]
http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Reply via email to