Eric, I know how mine came to be in that state now.
Before I reinstalled my server with x86_64, it had also run 0.96.1 (I upgraded to that version of clamav when it came out). Now, upgrading will only create a freshclam.conf_rpmnew file instead of overwriting the old one. I still had the backup of the old server and said freshclam.conf_rpmnew file DID contain the "LogTime yes" directive. Now with the new installation, of course that directive was also used as it was the first time the 0.96.1 version of the clamav package was installed. Can anyone confirm that is what happened to them too? It may be that a fresh install (or --force option to replace files) will cause it and a simple update won't. Martin Am 18.06.2010 um 17:40 schrieb Eric Shubert: > I see from the /usr/share/logwatch/scripts/services/clam-update script that > the date on the 'started' line is used, so it doesn't need the other dates. > Bad assumption on my part. > > I'm getting the same problem as Martin had on only one of several servers. I > though that they were all configured the same (they're all running 0.96.1), > but I checked them out and found that indeed the problem host had "LogTime > yes" uncommented. Finn, I'm sorry I ever doubted you! My apologies. > > That brings 2 questions to mind: > > 1) How did some servers end up with this setting, yet others did not? > > I'm not really worried about this, but it's a little perplexing to me. > Perhaps I turned it on at some point, but there are 2 .rpmsave files, and > both have it commented out. I'm guessing that it had something to do with the > upgrade path. > > 2) Can the logwatch clam-update script be fixed to handle the "LogTime yes" > configuration setting? > > I found a patch for the clam-update script at > http://permalink.gmane.org/gmane.comp.log.logwatch.devel/1622 that I'll try > out. I'll try it with both LogTime settings, and see what happens with > tomorrow's logwatch run. (I'm a little too busy to test it manually). This > patch was first submitted Jul'08 on the logwatch-devel list. I've inquired as > to which release (if any) it's been included with. > > > Also, Martin, is the message you show from the log I take it? What message > are you getting in the logwatch output? I'm getting: > --------------------- clam-update Begin ------------------------ > > Last ClamAV update process started at Thu Jun 17 23:03:32 2010 > > Last Status: > main.cvd is up to date (version: 52, sigs: 704727, f-level: 44, builder: > sven) > daily.cld is up to date (version: 11212, sigs: 96650, f-level: 51, > builder: ccordes) > bytecode.cld is up to date (version: 26, sigs: 3, f-level: 51, builder: > nervous) > > ---------------------- clam-update End ------------------------- > > > -- > -Eric 'shubes' > > Martin Waschbuesch wrote: >> Apparently, when you set logtime to no, logwatch will pick up on a time >> stamp: >> -------------------------------------- >> freshclam daemon 0.96.1 (OS: linux-gnu, ARCH: x86_64, CPU: x86_64) >> ClamAV update process started at Thu Jun 17 12:05:46 2010 >> main.cvd is up to date (version: 52, sigs: 704727, f-level: 44, builder: >> sven) >> daily.cld is up to date (version: 11212, sigs: 96650, f-level: 51, builder: >> ccordes) >> bytecode.cld is up to date (version: 26, sigs: 3, f-level: 51, builder: >> nervous) >> -------------------------------------- >> So, it works again for me! AND you still have date information. >> Thanks, >> Martin >> Am 18.06.2010 um 03:31 schrieb Eric Shubert: >>> Perhaps the clamav-toaster version of freshclam.conf needs updating. >>> >>> Would you care to diff the toaster version with the current stock clamav >>> version? >>> >>> -- >>> -Eric 'shubes' >>> >>> Finn Buhelt wrote: >>>> Hi Eric. >>>> FYI - just checked documentation for freshclam.conf - there's is no >>>> logtime directive according to Manual Reference Pages freshclam.conf (5) ! >>>> /Finn >>>> ----- Original Message ----- From: "Eric Shubert" <[email protected]> >>>> To: <[email protected]> >>>> Sent: Friday, June 18, 2010 12:22 AM >>>> Subject: [qmailtoaster] Re: freshclam & logwatch >>>>> While disabling logtime might get rid of the message, I don't think it's >>>>> the right fix. I would expect that disabling logtime would prohibit >>>>> logwatch from showing *any* freshclam information, as logwatch wouldn't >>>>> be able to tell which messages are from which date. Log messages without >>>>> a time stamp are pretty much useless imo. Unless I'm misunderstanding >>>>> what this option does. I think it's intended for configurations where log >>>>> messages go to the syslog, which puts its own timestamp on messages. >>>>> >>>>> >>>>> Finn Buhelt wrote: >>>>>> Hi Martin. >>>>>> >>>>>> In addition to removing the 1'st line in the logfile do this : >>>>>> >>>>>> In the freshclam.conf file (/etc/freshclam.conf) disable logtime from >>>>>> yes to NO. >>>>>> >>>>>> Regards, >>>>>> >>>>>> Finn Buhelt >>>>>> >>> >>> >>> --------------------------------------------------------------------------------- >>> Qmailtoaster is sponsored by Vickers Consulting Group >>> (www.vickersconsulting.com) >>> Vickers Consulting Group offers Qmailtoaster support and installations. >>> If you need professional help with your setup, contact them today! >>> --------------------------------------------------------------------------------- >>> Please visit qmailtoaster.com for the latest news, updates, and packages. >>> To unsubscribe, e-mail: >>> [email protected] >>> For additional commands, e-mail: [email protected] >>> >>> >> -- >> "I hold it true, whate'er befall; >> I feel it, when I sorrow most; >> 'Tis better to have loved and lost >> Than never to have loved at all." >> Alfred Lord Tennyson 'In Memoriam' >> --------------------------------------------------------------------------------- >> Qmailtoaster is sponsored by Vickers Consulting Group >> (www.vickersconsulting.com) >> Vickers Consulting Group offers Qmailtoaster support and installations. >> If you need professional help with your setup, contact them today! > > > -- > -Eric 'shubes' > > > --------------------------------------------------------------------------------- > Qmailtoaster is sponsored by Vickers Consulting Group > (www.vickersconsulting.com) > Vickers Consulting Group offers Qmailtoaster support and installations. > If you need professional help with your setup, contact them today! > --------------------------------------------------------------------------------- > Please visit qmailtoaster.com for the latest news, updates, and packages. > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > -- "It isn't that they can't see the solution. It is that they can't see the problem." Gilbert K. Chesterton --------------------------------------------------------------------------------- Qmailtoaster is sponsored by Vickers Consulting Group (www.vickersconsulting.com) Vickers Consulting Group offers Qmailtoaster support and installations. If you need professional help with your setup, contact them today! --------------------------------------------------------------------------------- Please visit qmailtoaster.com for the latest news, updates, and packages. To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
