LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 11-14-2014, 09:48 AM   #1
battles
Member
 
Registered: Apr 2014
Distribution: Debian GNU/Linux 7.5 (wheezy)
Posts: 258

Rep: Reputation: Disabled
incron problem


I am using incron to monitor the /var/log/auth.log file with the incrontab -e parameter below. incron is firing the icronBanSSH.sh correctly however, when an access_log is rolled over and compressed and a new empty access_log is created, incron no longer fires cronBanSSH.sh. It is as if incron looses track of the (new) empty access_log. Has anyone had this problem? If I go and do a incrontab -e and modify the incron file, it starts firing again. I guess I could kill and restart incron when I detect a new access_log file has been created, but this seems to be a bug in incron.

/var/log/auth.log IN_MODIFY /etc/SSH404Block/icronBanSSH.sh

Any other suggestions?
Thanks.
 
Old 11-15-2014, 07:47 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608Reputation: 3608
It's about tracking the file descriptor the log file uses. If you use logrotate then you could use the post section to restart things. BTW, is there a particular reason why you're using such a kludge instead of say fail2ban?
 
Old 11-15-2014, 07:59 PM   #3
battles
Member
 
Registered: Apr 2014
Distribution: Debian GNU/Linux 7.5 (wheezy)
Posts: 258

Original Poster
Rep: Reputation: Disabled
Thanks. I'll look into this 'post section'. Right now I am killing incron when logrotate happens and restarting one minute after.
I have written my own fail2ban routine that suits our needs better and incron is used to start it upon log changes.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Command associated with Incron not getting executed Bharath_ Linux - Newbie 3 05-15-2013 11:44 AM
Incron Job not executing Bharath_ Linux - Newbie 1 05-14-2013 09:19 PM
incron experiences - what do you think? billymayday Linux - Software 4 11-20-2008 10:17 AM
LXer: Triggering Commands On File/Directory Changes With Incron LXer Syndicated Linux News 0 09-02-2008 01:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 03:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration