Hello everyone and Linux Guru's
Here I've sort a problem, dealing with swatch.
I wonder why my swatch configuration can't sending an email notification to my mail, which I mean to sent the output file into email.
Swatch running like a charm on my system and success to give the log files for the file that swatch monitoring..
here's my output
Code:
root@ubuntusecurity:/home/andrewraharjo# swatch -c /root/.swatchrc -t /var/log/auth.log
*** swatch version 3.2.3 (pid:6773) started at Mon Nov 29 19:33:39 WIT 2010
Nov 29 19:34:46 ubuntusecurity sudo: pam_unix(sudo:auth): authentication failure; logname=andrewraharjo uid=0 euid=0 tty=/dev/pts/2 ruser=andrewraharjo rhost=ubuntusecurity user=andrewraharjo
Nov 29 19:35:31 ubuntusecurity sudo: andrewraharjo : 3 incorrect password attempts ; TTY=pts/2 ; PWD=/home/andrewraharjo ; USER=root ; COMMAND=us
Nov 29 19:35:45 ubuntusecurity sudo: andrewraharjo : TTY=pts/2 ; PWD=/home/andrewraharjo ; USER=root ; COMMAND=/bin/su
here's my swatch configuration files
Code:
#SWATCH CONFIG FILE
watchfor = /FAILED su for root/
echo bold
exec echo "Subject: auth:FAILED su for root\n\n$_\n" | sendmail "andrew2raharjo@gmail.com"
watchfor /sudo:/
echo bold
exec echo "Subject: auth:FAILED su for root\n\n$_\n" | sendmail "andrew2raharjo@gmail.com"
throttle 01:00
watchfor /sudo:.*command not allowed/
exec echo "Subject: auth:FAILED su for root\n\n$_\n" | sendmail "andrew2raharjo@gmail.com"
echo bold red
my question is;
Why I didn't get any alert message (email notification to
andrew2raharjo@gmail.com) from swatch for printed log on my system ?
Please somebody help me, any suggestion, I will appreciate it...I'm totally desperate about my system. I getting confused....
Best Regards,
Andrew