On Sunday 23 September 2001 12:26, you wrote: > On Sunday 23 September 2001 09:59, you wrote: > > At 01:15 AM Sunday, 9/23/2001, you wrote -=> > > > > >Sep 23 00:47:12 home portsentry[1073]: attackalert: UDP scan from host: > > >dhcp1.cgocable.net/24.xxx.x.xx to UDP port: 68 > > > > Try adding the following to ../logcheck.ignore > > > > portsentry.*: UDP scan > > OK.. I've tried adding all the entries you've given me, but the log files > are all coming the same way as before. > > I am editing the /etc/logcheck/ignore file which I've checked the path in > logcheck.sh to make sure it's pointing there.. which it is. Oh yah.. well.. all the UDP and Host scans are still coming up (anything that is an "attackalert", but the mail has been filtered out. So I'm editing the right file, but it's not allowing me to filter out the UDP scans...?
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com
