|
Packit |
57988d |
##################################################################
|
|
Packit |
57988d |
#
|
|
Packit |
57988d |
# Written by S. Schimkat <www.schimkat.dk>.
|
|
Packit |
57988d |
#
|
|
Packit |
57988d |
# Find latest version here: www.schimkat.dk/clamav
|
|
Packit |
57988d |
#
|
|
Packit |
57988d |
##################################################################
|
|
Packit |
57988d |
|
|
Packit |
57988d |
########################################################
|
|
Packit |
57988d |
## Copyright (c) 2008 S. Schimkat
|
|
Packit |
57988d |
## Covered under the included MIT/X-Consortium License:
|
|
Packit |
57988d |
## http://www.opensource.org/licenses/mit-license.php
|
|
Packit |
57988d |
## All modifications and contributions by other persons to
|
|
Packit |
57988d |
## this script are assumed to have been donated to the
|
|
Packit |
57988d |
## Logwatch project and thus assume the above copyright
|
|
Packit |
57988d |
## and licensing terms. If you want to make contributions
|
|
Packit |
57988d |
## under your own copyright or a different license this
|
|
Packit |
57988d |
## must be explicitly stated in the contribution an the
|
|
Packit |
57988d |
## Logwatch project reserves the right to not accept such
|
|
Packit |
57988d |
## contributions. If you have made significant
|
|
Packit |
57988d |
## contributions to this script and want to claim
|
|
Packit |
57988d |
## copyright please contact logwatch-devel@lists.sourceforge.net.
|
|
Packit |
57988d |
#########################################################
|
|
Packit |
57988d |
|
|
Packit |
57988d |
$Detail = $ENV{'LOGWATCH_DETAIL_LEVEL'};
|
|
Packit |
57988d |
my $IgnoreUnmatched = $ENV{'clamav_ignoreunmatched'} || 0;
|
|
Packit |
57988d |
|
|
Packit |
57988d |
while (defined($ThisLine = <STDIN>)) {
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (
|
|
Packit |
57988d |
( $ThisLine =~ /^clamav-milter (startup|shutdown) succeeded$/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^Database has changed, loading updated database/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^Quarantined infected mail as/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^\w+ quarantined as/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^ClamAv: mi_stop/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ m#^\/tmp\/clamav-.* .* FOUND# ) or
|
|
Packit |
57988d |
# These two go along with "max-children limit" so we ignore them
|
|
Packit |
57988d |
( $ThisLine =~ /n_children \d+: waiting \d+ seconds for some to exit/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /Finished waiting, n_children = \d+/ ) or
|
|
Packit |
57988d |
# These 3 precede "correctly reloaded" (we hope)
|
|
Packit |
57988d |
# - Toss-up: Keep "correctly reloaded" or "Protecting against"?
|
|
Packit |
57988d |
( $ThisLine =~ /^Database has changed, loading updated database/ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^Loaded ClamAV \d+\./ ) or
|
|
Packit |
57988d |
( $ThisLine =~ /^ClamAV: Protecting against \d+ viruses/ ) or
|
|
Packit |
57988d |
0 ) {
|
|
Packit |
57988d |
# We do not care about these.
|
|
Packit |
57988d |
} elsif (($ThisLine =~ /clean message from/)) {
|
|
Packit |
57988d |
$CleanMessage++;
|
|
Packit |
57988d |
} elsif (($ThisLine =~ /.*: (.+?) Intercepted virus/i ) or
|
|
Packit |
57988d |
($ThisLine =~ /Message from .* to .* infected by (.+)/)) {
|
|
Packit |
57988d |
$VirusList{$1}++;
|
|
Packit |
57988d |
} elsif (($ChildLimit) = ($ThisLine =~ /hit max-children limit \((\d+ >= \d+)\): waiting for some to exit/)) {
|
|
Packit |
57988d |
$MaxChildrenLimit{$ChildLimit}++;
|
|
Packit |
57988d |
} elsif (($ThisLine =~ /^Stopping/)) {
|
|
Packit |
57988d |
$DaemonStop++;
|
|
Packit |
57988d |
} elsif (($ThisLine =~ /^(Starting|\+\+\+ Started)/)) {
|
|
Packit |
57988d |
$DaemonStart++;
|
|
Packit |
57988d |
} elsif (($Viruses) = ($ThisLine =~ /^Database correctly reloaded \((\d+) (signatures|viruses)\)/i )) {
|
|
Packit |
57988d |
$DatabaseReloads++;
|
|
Packit |
57988d |
$DatabaseViruses = $Viruses;
|
|
Packit |
57988d |
} else {
|
|
Packit |
57988d |
$OtherList{$ThisLine}++;
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (($DaemonStop) and ($Detail >= 5)) {
|
|
Packit |
57988d |
print "\nDaemon stopped: " . $DaemonStop . " Time(s)\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (($DaemonStart) and ($Detail >= 5)) {
|
|
Packit |
57988d |
print "\nDaemon started: " . $DaemonStart . " Time(s)\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (($DatabaseReloads) and ($Detail >= 5)) {
|
|
Packit |
57988d |
print "\nVirus database reloaded $DatabaseReloads time(s) (last time with $DatabaseViruses viruses)\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (keys %MaxChildrenLimit) {
|
|
Packit |
57988d |
print "\nHit max-children limit:\n";
|
|
Packit |
57988d |
foreach $Limit (sort {$a cmp $b} keys %MaxChildrenLimit) {
|
|
Packit |
57988d |
print ' Limit ' . $Limit . ' children(s) exceeded ' . $MaxChildrenLimit{$Limit} . " Time(s)\n"
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if ($CleanMessage) {
|
|
Packit |
57988d |
print "\nClean messages: " . $CleanMessage . " Message(s)\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if (keys %VirusList) {
|
|
Packit |
57988d |
my $Total = 0;
|
|
Packit |
57988d |
print "\nInfected messages:\n";
|
|
Packit |
57988d |
foreach $Virus (sort {$a cmp $b} keys %VirusList) {
|
|
Packit |
57988d |
print ' ' . $Virus . ": ". $VirusList{$Virus} . " Message(s)\n";
|
|
Packit |
57988d |
$Total += $VirusList{$Virus};
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
print " Total: $Total\n";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
if ((keys %OtherList) and (not $IgnoreUnmatched)){
|
|
Packit |
57988d |
print "\n**Unmatched Entries**\n";
|
|
Packit |
57988d |
foreach my $line (sort {$OtherList{$b}<=>$OtherList{$a} } keys %OtherList) {
|
|
Packit |
57988d |
print "\n $line: $OtherList{$line} Time(s)";
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
}
|
|
Packit |
57988d |
|
|
Packit |
57988d |
exit(0);
|
|
Packit |
57988d |
|
|
Packit |
57988d |
# vi: shiftwidth=3 tabstop=3 syntax=perl et
|
|
Packit |
57988d |
# Local Variables:
|
|
Packit |
57988d |
# mode: perl
|
|
Packit |
57988d |
# perl-indent-level: 3
|
|
Packit |
57988d |
# indent-tabs-mode: nil
|
|
Packit |
57988d |
# End:
|