Brent, That version works on both types of logs - You rock!!!
-----Original Message----- From: Brent Gardner [mailto:[email protected]] Sent: Friday, February 26, 2010 8:27 PM To: [email protected] Subject: Re: [qmailtoaster] Re: Optimizing a Server for VM I think I found the problem. Entries in /var/log/maillog look like this: Feb 22 10:04:32 smtp spamdyke[1941]: FILTER_RDNS_MISSING ip: 213.207.169.135 Entries in /var/log/qmail/smtp/current look like this: @400000004b8880e0199c9a3c spamdyke[1941]: FILTER_RDNS_MISSING ip: 213.207.169.135 When the script runs in syslog mode it discards everything out of a log entry up to and including "spamdyke[<pid>]: " and processes the remainder of the entry assuming that it starts at (in the example above) "FILTER_". Before, when the script runs in qmail log mode it only cuts off the timestamp and space. It leaves the "spamdyke[<pid>}: ", but still wants to process the log entry as if it starts with "FILTER_". To the part that cuts off the timestamp I added code that cuts off the "spamdyke[<pid>]: ". I altered my toasters to log to the qmail smtp log so I would have test data. It's working in my tests against either qmail logs or maillog. Brent Gardner [email protected] wrote: > Yes it does have plenty of spamdyke logs in it - I checked to make sure. > > >> Eric- >> >> Does the original script work for you? >> >> I went back to look at the original thread where I got this script: >> >> http://www.mail-archive.com/[email protected]/msg01847.html >> >> The script was written by Felix Buenemann and later altered based on >> input from you and a few others so that it would work with qmail log >> files or maillog files. >> >> Spamdyke on my toasters logs to /var/log/maillog, so I don't have >> genuine qmail logs to run through the script. I took a maillog file, >> copied it to a temp file and converted it into what I think is the >> proper format based on your postings to the spamdyke-users list from >> this time period. Then I copied a bunch of data from a real qmail smtp >> log into the temp file and ran the whole mess through the script and it >> seemed to work OK with out tai64nlocal. It returned the same numbers as >> the original maillog file. >> >> It doesn't work if I pipe the temp file through tai64nlocal. >> >> >> Jack- >> >> After further review I don't think the script is designed to run with a >> qmail smtp log and tai64nlocal, but it should work just fine with a raw >> qmail smtp log file. >> >> The data you ran through from a maillog file produced numbers so low >> that it makes me wonder... Did the qmail smtp log that you ran through >> that produced a bunch of zeroes actually contain any Spamdyke log entries? >> >> >> Brent Gardner >> >> >> >> [email protected] wrote: >> >>> Brent here is what I get: >>> >>> [r...@mail spamdyke]# cat /var/log/qmail/smtp/current | tai64nlocal | >>> ./spamdyke-stats >>> Use of uninitialized value in substr at ./spamdyke-stats line 57, <> >>> line >>> 1 (#1) >>> (W uninitialized) An undefined value was used as if it were already >>> defined. It was interpreted as a "" or a 0, but maybe it was a >>> mistake. >>> To suppress this warning assign a defined value to your variables. >>> >>> To help you figure out what was undefined, perl tells you what >>> operation >>> you used the undefined value in. Note, however, that perl optimizes >>> your >>> program and the operation displayed in the warning may not >>> necessarily >>> appear literally in your program. For example, "that $foo" is >>> usually optimized into "that " . $foo, and the warning will refer to >>> the concatenation (.) operator, even though there is no . in your >>> program. >>> >>> Use of uninitialized value in substr at ./spamdyke-stats line 57, <> >>> line >>> 243 (#1) >>> Use of uninitialized value in substr at ./spamdyke-stats line 57, <> >>> line >>> 420 (#1) >>> >>> ---------------- Summary ---------------- >>> Allowed: 0 0.00% >>> Timeout: 0 0.00% >>> Errors : 0 0.00% >>> Denied : 0 0.00% >>> Total : 0 0.00% >>> >>> >>> >>> >>>> [email protected] wrote: >>>> >>>> >>>>> It works great as long as you are using the default log location for >>>>> Spamdyke (/var/log/maillog). I would love to see it work on the qtp >>>>> defaulted installation though, as I would imagine that's how most >>>>> people >>>>> are implementing it on this list. I am not sure what it needs to make >>>>> it >>>>> work. Maybe I can figure out what it is looking for. I have no clues >>>>> on >>>>> perl scripting, but sometimes can figure out the simple stuff, and I >>>>> am >>>>> betting this is a simple fix. >>>>> >>>>> >>>>> >>>> Seeing as I got this from the Spamdyke mailing list it makes sense that >>>> it works for the default Spamdyke log location but has trouble with >>>> other log options. I seem to remember some discussion on the Spamdyke >>>> mailing list about getting it to work with qmail logs but I don't >>>> remember the details. >>>> >>>> What happens when you pipe a qmail log through tai64nlocal before >>>> sending it to the stats script? >>>> >>>> >>>> Brent Gardner >>>> >>>> >>>> ---------------------------------------------------------------------------- ----- >>>> Qmailtoaster is sponsored by Vickers Consulting Group >>>> (www.vickersconsulting.com) >>>> Vickers Consulting Group offers Qmailtoaster support and >>>> installations. >>>> If you need professional help with your setup, contact them >>>> today! >>>> ---------------------------------------------------------------------------- ----- >>>> Please visit qmailtoaster.com for the latest news, updates, and >>>> packages. >>>> >>>> To unsubscribe, e-mail: >>>> [email protected] >>>> For additional commands, e-mail: >>>> [email protected] >>>> >>>> >>>> >>>> >>>> >>> >>> ---------------------------------------------------------------------------- ----- >>> Qmailtoaster is sponsored by Vickers Consulting Group >>> (www.vickersconsulting.com) >>> Vickers Consulting Group offers Qmailtoaster support and >>> installations. >>> If you need professional help with your setup, contact them today! >>> ---------------------------------------------------------------------------- ----- >>> Please visit qmailtoaster.com for the latest news, updates, and >>> packages. >>> >>> To unsubscribe, e-mail: >>> [email protected] >>> For additional commands, e-mail: >>> [email protected] >>> >>> >>> >>> >> ---------------------------------------------------------------------------- ----- >> Qmailtoaster is sponsored by Vickers Consulting Group >> (www.vickersconsulting.com) >> Vickers Consulting Group offers Qmailtoaster support and >> installations. >> If you need professional help with your setup, contact them today! >> ---------------------------------------------------------------------------- ----- >> Please visit qmailtoaster.com for the latest news, updates, and >> packages. >> >> To unsubscribe, e-mail: >> [email protected] >> For additional commands, e-mail: >> [email protected] >> >> >> >> > > > > ---------------------------------------------------------------------------- ----- > Qmailtoaster is sponsored by Vickers Consulting Group (www.vickersconsulting.com) > Vickers Consulting Group offers Qmailtoaster support and installations. > If you need professional help with your setup, contact them today! > ---------------------------------------------------------------------------- ----- > Please visit qmailtoaster.com for the latest news, updates, and packages. > > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > > --------------------------------------------------------------------------------- Qmailtoaster is sponsored by Vickers Consulting Group (www.vickersconsulting.com) Vickers Consulting Group offers Qmailtoaster support and installations. If you need professional help with your setup, contact them today! --------------------------------------------------------------------------------- Please visit qmailtoaster.com for the latest news, updates, and packages. To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
