daily autocommit
This commit is contained in:
-166
@@ -131,167 +131,6 @@ maybe chmod 0644 'X11/app-defaults/Xmessage-color'
|
||||
maybe chmod 0644 'X11/rgb.txt'
|
||||
maybe chmod 0644 'adduser.conf'
|
||||
maybe chmod 0755 'aide'
|
||||
maybe chmod 0644 'aide/aide.conf'
|
||||
maybe chmod 0644 'aide/aide.conf.bak'
|
||||
maybe chmod 0755 'aide/aide.conf.d'
|
||||
maybe chmod 0644 'aide/aide.conf.d/10_aide_constants'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_distribution'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_hostname'
|
||||
maybe chmod 0644 'aide/aide.conf.d/10_aide_run'
|
||||
maybe chmod 0755 'aide/aide.conf.d/10_aide_year'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_aide_apache2'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_aide_bind9'
|
||||
maybe chmod 0755 'aide/aide.conf.d/30_inn2_vars'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_acpid'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_adjtime'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_aide'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_alsa'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_amanda-client'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_amanda-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_amavisd-new'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_anacron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_anubis'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apache'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apache2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apcupsd'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_apt'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_apt-file'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listbugs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-listchanges'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt-show-versions'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt_frqchg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt_stable'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_apt_unstable'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_aptitude'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_aptitude_frqchg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_at'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_bind9'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_btmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_checksecurity'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-data'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_clamav-freshclam'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_console-log'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cracklib-runtime'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cron-apt'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_cups'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dbus'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ddclient'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_debconf'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_debsecan'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dhcp3-client'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dhcp3-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dhcpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dlocate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dokuwiki'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dovecot'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_dpkg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_etckeeper'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_exim4_logs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_fail2ban'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_fcron'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_findutils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_gpg'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_hald'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_hapsd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ifplugd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ifupdown'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_inetd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_initramfs-tools'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_initscripts'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_inn2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ippl'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_kerberos'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_laptop-mode-tools'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lastlog'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lib-init-rw'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_libapache2-mod-fastcgi'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_libvirt-bin'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lighttpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_logcheck'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_logrotate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_lvm2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mail'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mailman'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_man'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mdadm'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mlocate'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_modules'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mtab'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_munin'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_munin-nodes'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_mysql-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nagios2'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nagios3'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_network'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nfs'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nrpe'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nscd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_nslcd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ntp-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_openvpn'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_opie-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_pcscd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_php4'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_php5'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_pm-utils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_portmap'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postfix'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postgresql'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_postgrey'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_privoxy'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_proftpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_resolvconf'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rkhunter'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rngd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_root-dotfiles'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rsnapshot'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_rsyslog'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_samba'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_screen'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_slapd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_slrn'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_smartmontools'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_smokeping'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_snmpd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_spamassassin'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_squid'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-agent'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_ssh-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_sudo'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_svn-server'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_syslog'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_tetex-bin'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_tiger'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_torrus'
|
||||
maybe chmod 0755 'aide/aide.conf.d/31_aide_trac'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_tt-rss'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_udev'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_util-linux'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_utmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_vpnc'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_webalizer'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_wpasupplicant'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_wtmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-common'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_x11-xkb-utils'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xdm'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xfree86-common'
|
||||
maybe chmod 0644 'aide/aide.conf.d/31_aide_xinetd'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_dev'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_etc'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_proc_sys'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_run'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_tmp'
|
||||
maybe chmod 0644 'aide/aide.conf.d/70_aide_var'
|
||||
maybe chmod 0644 'aide/aide.conf.d/99_aide_root'
|
||||
maybe chmod 0755 'aide/aide.settings.d'
|
||||
maybe chmod 0755 'aide/aide.settings.d/10_aide_sourceslist'
|
||||
maybe chmod 0644 'aide/aide.settings.d/31_aide_apt_settings'
|
||||
maybe chmod 0644 'aide/aide.settings.d/31_aide_svn-server_settings'
|
||||
maybe chmod 0644 'aide/aide.settings.d/31_aide_trac_settings'
|
||||
maybe chmod 0644 'aliases'
|
||||
maybe chmod 0644 'aliases.db'
|
||||
maybe chmod 0755 'alternatives'
|
||||
@@ -585,7 +424,6 @@ maybe chmod 0700 'cron.daily'
|
||||
maybe chmod 0644 'cron.daily/.placeholder.disabled'
|
||||
maybe chmod 0755 'cron.daily/00logwatch'
|
||||
maybe chmod 0755 'cron.daily/acct'
|
||||
maybe chmod 0755 'cron.daily/aide'
|
||||
maybe chmod 0755 'cron.daily/apt-compat'
|
||||
maybe chmod 0755 'cron.daily/apt-show-versions'
|
||||
maybe chmod 0755 'cron.daily/apt.disabled'
|
||||
@@ -646,7 +484,6 @@ maybe chmod 0644 'debian_version'
|
||||
maybe chmod 0644 'debsums-ignore'
|
||||
maybe chmod 0755 'default'
|
||||
maybe chmod 0644 'default/acct'
|
||||
maybe chmod 0644 'default/aide'
|
||||
maybe chmod 0644 'default/amavis-mc'
|
||||
maybe chmod 0644 'default/amavisd-snmp-subagent'
|
||||
maybe chmod 0644 'default/bsdmainutils'
|
||||
@@ -3429,7 +3266,6 @@ maybe chgrp 'logcheck' 'logcheck/ignore.d.paranoid/incron'
|
||||
maybe chmod 0644 'logcheck/ignore.d.paranoid/incron'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.paranoid/logcheck'
|
||||
maybe chmod 0644 'logcheck/ignore.d.paranoid/logcheck'
|
||||
maybe chmod 0644 'logcheck/ignore.d.paranoid/mariadb-server-10_6'
|
||||
maybe chmod 0644 'logcheck/ignore.d.paranoid/mariadb-server-10_7'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.paranoid/postfix'
|
||||
maybe chmod 0644 'logcheck/ignore.d.paranoid/postfix'
|
||||
@@ -3580,7 +3416,6 @@ maybe chgrp 'logcheck' 'logcheck/ignore.d.server/login'
|
||||
maybe chmod 0644 'logcheck/ignore.d.server/login'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.server/maradns'
|
||||
maybe chmod 0644 'logcheck/ignore.d.server/maradns'
|
||||
maybe chmod 0644 'logcheck/ignore.d.server/mariadb-server-10_6'
|
||||
maybe chmod 0644 'logcheck/ignore.d.server/mariadb-server-10_7'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.server/mldonkey-server'
|
||||
maybe chmod 0644 'logcheck/ignore.d.server/mldonkey-server'
|
||||
@@ -3760,7 +3595,6 @@ maybe chgrp 'logcheck' 'logcheck/ignore.d.workstation/logcheck'
|
||||
maybe chmod 0644 'logcheck/ignore.d.workstation/logcheck'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.workstation/login'
|
||||
maybe chmod 0644 'logcheck/ignore.d.workstation/login'
|
||||
maybe chmod 0644 'logcheck/ignore.d.workstation/mariadb-server-10_6'
|
||||
maybe chmod 0644 'logcheck/ignore.d.workstation/mariadb-server-10_7'
|
||||
maybe chgrp 'logcheck' 'logcheck/ignore.d.workstation/net-acct'
|
||||
maybe chmod 0644 'logcheck/ignore.d.workstation/net-acct'
|
||||
|
||||
-196
@@ -1,196 +0,0 @@
|
||||
# AIDE conf
|
||||
|
||||
# The daily cron job depends on these paths
|
||||
database=file:/var/lib/aide/aide.db
|
||||
database_out=file:/var/lib/aide/aide.db.new
|
||||
database_new=file:/var/lib/aide/aide.db.new
|
||||
gzip_dbout=yes
|
||||
|
||||
# Set to no to disable summarize_changes option.
|
||||
summarize_changes=yes
|
||||
|
||||
# Set to no to disable grouping of files in report.
|
||||
grouped=yes
|
||||
|
||||
# standard verbose level
|
||||
verbose = 6
|
||||
|
||||
# Set to yes to print the checksums in the report in hex format
|
||||
report_base16 = no
|
||||
|
||||
# if you want to sacrifice security for speed, remove some of these
|
||||
# checksums. Whirlpool is broken on sparc and sparc64 (see #429180,
|
||||
# #420547, #152203).
|
||||
Checksums = sha256+sha512+rmd160+haval+gost+crc32+tiger
|
||||
|
||||
# The checksums of the databases to be printed in the report
|
||||
# Set to 'E' to disable.
|
||||
database_attrs = Checksums
|
||||
|
||||
# check permissions, owner, group and file type
|
||||
OwnerMode = p+u+g+ftype
|
||||
|
||||
# Check size and block count
|
||||
Size = s+b
|
||||
|
||||
# Files that stay static
|
||||
InodeData = OwnerMode+n+i+Size+l+X
|
||||
StaticFile = m+c+Checksums
|
||||
|
||||
# Files that stay static but are copied to a ram disk on startup
|
||||
# (causing different inode)
|
||||
RamdiskData = InodeData-i
|
||||
|
||||
# Check everything
|
||||
Full = InodeData+StaticFile
|
||||
|
||||
# Files that change their mtimes or ctimes but not their contents
|
||||
VarTime = InodeData+Checksums
|
||||
|
||||
# Files that are recreated regularly but do not change their contents
|
||||
VarInode = VarTime-i
|
||||
|
||||
# Files that change their contents during system operation
|
||||
VarFile = OwnerMode+n+l+X
|
||||
|
||||
# Directories that change their contents during system operation
|
||||
VarDir = OwnerMode+n+i+X
|
||||
|
||||
# Directories that are recreated regularly and change their contents
|
||||
VarDirInode = OwnerMode+n+X
|
||||
|
||||
# Directories that change their mtimes or ctimes but not their contents
|
||||
VarDirTime = InodeData
|
||||
|
||||
# Logs are special: they are continously written to, may be compressed
|
||||
# have their file name changed in different, mutually incompatibly ways
|
||||
# and apprear and vanish at will. Handling this is a a complex and error-
|
||||
# prone issue.
|
||||
#
|
||||
# This is best broken down in a number of small tasks:
|
||||
#
|
||||
#
|
||||
# (A)
|
||||
# While a live log is being written to, it doesn't change its mode and
|
||||
# inode and its size only increases.
|
||||
#
|
||||
# (B)
|
||||
# When a live log is rotated for the first time, it should not change
|
||||
# its mode, may change its inode, and its size decreases. The size
|
||||
# decrease may not be noticed by aide if the file had size x at the last
|
||||
# aide run, was rotated in the mean time and was written to so that it
|
||||
# had a size > x at the next aide run.
|
||||
#
|
||||
# (C)
|
||||
# When a log is compressed, this looks to aide like the uncompressed
|
||||
# file vanished (or was replaced by another file) and the compressed
|
||||
# file appeared out of the blue. There is (currently) no way to
|
||||
# associate the (gone) uncompressed file's contents with the (new)
|
||||
# compressed file's contents
|
||||
#
|
||||
# (D)
|
||||
# The actual log rotation may rename foo.{x}.bar to foo.{x+1}.bar without
|
||||
# changing the other properties of the file
|
||||
#
|
||||
# (E)
|
||||
# If only a given number of log generations is to be kept, foo.{y}.bar may
|
||||
# vanish, but usually only when no foo.{z}.bar exists for z>y.
|
||||
#
|
||||
# (F)
|
||||
# The set of files foo.{x}.bar to foo.{y}.bar is called a "log series"
|
||||
# in aide terms, with the lowest x being called the "LoSerMember" element
|
||||
# and the highest y being called the "HiSerMember" element, and the z
|
||||
# with x<z<y simple called "SerMember". The Lo and Hi members need to
|
||||
# be special cased in aide configuration.
|
||||
#
|
||||
#
|
||||
# This is an example of the normal life of a log named foo in a logrotate
|
||||
# configuration using a configuration at it is commonly used in Debian
|
||||
# (from old to new):
|
||||
# 1 logrotate deletes HiSerMember foo.{y}.gz
|
||||
# 2 logrotate rotates SerMember foo.{z-1}.gz to foo.{z}.gz for all
|
||||
# z with 3<z<=y. This includes rotation of foo.{y-1}.gz to
|
||||
# foo.{y}.gz and foo.2.gz to foo.3.gz
|
||||
# 3 logrotate compresses foo.1 to foo.2.gz, creating LoSerMember foo.2.gz
|
||||
# 4 logrotate rotates foo to foo.1 (a simple rename)
|
||||
# 5 logrotate creates new, empty foo
|
||||
# 6 foo daemon logs to foo - foo grows in size
|
||||
#
|
||||
# we need the following rules:
|
||||
# /var/log/foo$ Log
|
||||
# /var/log/foo$ FreqRotLog
|
||||
# this takes care of the growing live log (step 7). The "Log" rule
|
||||
# is appropriate for logs that are not rotated daily as rotation
|
||||
# might be reported (if the file size has decreased since the last
|
||||
# aide run). For daily rotated logs, the "FreqRotLog" may be more
|
||||
# appropriate.
|
||||
# /var/log/foo\.1$ LowLog
|
||||
# this takes care of step 5.
|
||||
# /var/log/foo\.2\.gz$ LoSerMemberLog
|
||||
# this allows yet unknown new files to appear with a \.2\.gz extension,
|
||||
# covering step 3.
|
||||
# /var/log/foo\.[3..y-1]\.gz$ SerMemberLog
|
||||
# this watches the log files as they wander through the Series,
|
||||
# changing only their file name but not their contents or metadata,
|
||||
# covering step 2.
|
||||
# Please note that [3..y-1] needs to be a manually crafted regexp covering
|
||||
# all numbers between 3 and y-1.
|
||||
# /var/log/foo\.y\.gz$ HiSerMemberLog
|
||||
# finally, the last element of the Series is allowed to vanish without
|
||||
# being reported, covering step 1.
|
||||
#
|
||||
# Please note that these example rules need to be adapted to the logrotate
|
||||
# configuration for the log. Compression may be disabled or lead to a different
|
||||
# extension, the dateext option may be used, old logs might be held in a
|
||||
# different place, a log series does not necessarily need to be compressed etc.
|
||||
#
|
||||
# Please note that savelog rotates the live log to .0 and not to .1 as it
|
||||
# is logrotates (changeable) default.
|
||||
|
||||
|
||||
# Logs grow in size. Log rotation of these logs will be reported, so
|
||||
# this should only be used for logs that are not rotated daily.
|
||||
Log = OwnerMode+n+S+X
|
||||
|
||||
# Logs that are frequently rotated
|
||||
FreqRotLog = Log-S
|
||||
|
||||
# The first instance of a rotated log: After the log has stopped being
|
||||
# written to, but before rotation
|
||||
LowLog = Log-S
|
||||
|
||||
# Rotated logs change their file name but retain all their other properties
|
||||
SerMemberLog = Full+I
|
||||
|
||||
# The first instance of a compressed, rotated log: After a LowLog was
|
||||
# compressed.
|
||||
LoSerMemberLog = SerMemberLog+ANF
|
||||
|
||||
# The last instance of a compressed, rotated log: After this name, a log
|
||||
# will be removed
|
||||
HiSerMemberLog = SerMemberLog+ARF
|
||||
|
||||
# Not-yet-compressed log created by logrotate's dateext option:
|
||||
# These files appear one rotation (renamed from the live log) and are gone
|
||||
# the next rotation (being compressed)
|
||||
LowDELog = SerMemberLog+ANF+ARF
|
||||
|
||||
# Compressed log created by logrotate's dateext option: These files appear
|
||||
# once and are not touched any more.
|
||||
SerMemberDELog = Full+ANF
|
||||
|
||||
# For daemons that log to a variable file name and have the live log
|
||||
# hardlinked to a static file name
|
||||
LinkedLog = Log-n
|
||||
|
||||
# exeptions
|
||||
!/usr/src
|
||||
!/backup
|
||||
!/proc
|
||||
!/sys
|
||||
!/var/www/vhosts/solusar.de
|
||||
!/var/opt/vmail
|
||||
!/run
|
||||
!/var/log
|
||||
!/var/lib/postgresql/12/main/base
|
||||
!/var/lib/mysql/mysql
|
||||
@@ -1,184 +0,0 @@
|
||||
# AIDE conf
|
||||
|
||||
# The daily cron job depends on these paths
|
||||
database=file:/var/lib/aide/aide.db
|
||||
database_out=file:/var/lib/aide/aide.db.new
|
||||
database_new=file:/var/lib/aide/aide.db.new
|
||||
gzip_dbout=yes
|
||||
|
||||
# Set to no to disable summarize_changes option.
|
||||
summarize_changes=yes
|
||||
|
||||
# Set to no to disable grouping of files in report.
|
||||
grouped=yes
|
||||
|
||||
# standard verbose level
|
||||
verbose = 6
|
||||
|
||||
# Set to yes to print the checksums in the report in hex format
|
||||
report_base16 = no
|
||||
|
||||
# if you want to sacrifice security for speed, remove some of these
|
||||
# checksums. Whirlpool is broken on sparc and sparc64 (see #429180,
|
||||
# #420547, #152203).
|
||||
Checksums = sha256+sha512+rmd160+haval+gost+crc32+tiger
|
||||
|
||||
# The checksums of the databases to be printed in the report
|
||||
# Set to 'E' to disable.
|
||||
database_attrs = Checksums
|
||||
|
||||
# check permissions, owner, group and file type
|
||||
OwnerMode = p+u+g+ftype
|
||||
|
||||
# Check size and block count
|
||||
Size = s+b
|
||||
|
||||
# Files that stay static
|
||||
InodeData = OwnerMode+n+i+Size+l+X
|
||||
StaticFile = m+c+Checksums
|
||||
|
||||
# Files that stay static but are copied to a ram disk on startup
|
||||
# (causing different inode)
|
||||
RamdiskData = InodeData-i
|
||||
|
||||
# Check everything
|
||||
Full = InodeData+StaticFile
|
||||
|
||||
# Files that change their mtimes or ctimes but not their contents
|
||||
VarTime = InodeData+Checksums
|
||||
|
||||
# Files that are recreated regularly but do not change their contents
|
||||
VarInode = VarTime-i
|
||||
|
||||
# Files that change their contents during system operation
|
||||
VarFile = OwnerMode+n+l+X
|
||||
|
||||
# Directories that change their contents during system operation
|
||||
VarDir = OwnerMode+n+i+X
|
||||
|
||||
# Directories that are recreated regularly and change their contents
|
||||
VarDirInode = OwnerMode+n+X
|
||||
|
||||
# Directories that change their mtimes or ctimes but not their contents
|
||||
VarDirTime = InodeData
|
||||
|
||||
# Logs are special: they are continously written to, may be compressed
|
||||
# have their file name changed in different, mutually incompatibly ways
|
||||
# and apprear and vanish at will. Handling this is a a complex and error-
|
||||
# prone issue.
|
||||
#
|
||||
# This is best broken down in a number of small tasks:
|
||||
#
|
||||
#
|
||||
# (A)
|
||||
# While a live log is being written to, it doesn't change its mode and
|
||||
# inode and its size only increases.
|
||||
#
|
||||
# (B)
|
||||
# When a live log is rotated for the first time, it should not change
|
||||
# its mode, may change its inode, and its size decreases. The size
|
||||
# decrease may not be noticed by aide if the file had size x at the last
|
||||
# aide run, was rotated in the mean time and was written to so that it
|
||||
# had a size > x at the next aide run.
|
||||
#
|
||||
# (C)
|
||||
# When a log is compressed, this looks to aide like the uncompressed
|
||||
# file vanished (or was replaced by another file) and the compressed
|
||||
# file appeared out of the blue. There is (currently) no way to
|
||||
# associate the (gone) uncompressed file's contents with the (new)
|
||||
# compressed file's contents
|
||||
#
|
||||
# (D)
|
||||
# The actual log rotation may rename foo.{x}.bar to foo.{x+1}.bar without
|
||||
# changing the other properties of the file
|
||||
#
|
||||
# (E)
|
||||
# If only a given number of log generations is to be kept, foo.{y}.bar may
|
||||
# vanish, but usually only when no foo.{z}.bar exists for z>y.
|
||||
#
|
||||
# (F)
|
||||
# The set of files foo.{x}.bar to foo.{y}.bar is called a "log series"
|
||||
# in aide terms, with the lowest x being called the "LoSerMember" element
|
||||
# and the highest y being called the "HiSerMember" element, and the z
|
||||
# with x<z<y simple called "SerMember". The Lo and Hi members need to
|
||||
# be special cased in aide configuration.
|
||||
#
|
||||
#
|
||||
# This is an example of the normal life of a log named foo in a logrotate
|
||||
# configuration using a configuration at it is commonly used in Debian
|
||||
# (from old to new):
|
||||
# 1 logrotate deletes HiSerMember foo.{y}.gz
|
||||
# 2 logrotate rotates SerMember foo.{z-1}.gz to foo.{z}.gz for all
|
||||
# z with 3<z<=y. This includes rotation of foo.{y-1}.gz to
|
||||
# foo.{y}.gz and foo.2.gz to foo.3.gz
|
||||
# 3 logrotate compresses foo.1 to foo.2.gz, creating LoSerMember foo.2.gz
|
||||
# 4 logrotate rotates foo to foo.1 (a simple rename)
|
||||
# 5 logrotate creates new, empty foo
|
||||
# 6 foo daemon logs to foo - foo grows in size
|
||||
#
|
||||
# we need the following rules:
|
||||
# /var/log/foo$ Log
|
||||
# /var/log/foo$ FreqRotLog
|
||||
# this takes care of the growing live log (step 7). The "Log" rule
|
||||
# is appropriate for logs that are not rotated daily as rotation
|
||||
# might be reported (if the file size has decreased since the last
|
||||
# aide run). For daily rotated logs, the "FreqRotLog" may be more
|
||||
# appropriate.
|
||||
# /var/log/foo\.1$ LowLog
|
||||
# this takes care of step 5.
|
||||
# /var/log/foo\.2\.gz$ LoSerMemberLog
|
||||
# this allows yet unknown new files to appear with a \.2\.gz extension,
|
||||
# covering step 3.
|
||||
# /var/log/foo\.[3..y-1]\.gz$ SerMemberLog
|
||||
# this watches the log files as they wander through the Series,
|
||||
# changing only their file name but not their contents or metadata,
|
||||
# covering step 2.
|
||||
# Please note that [3..y-1] needs to be a manually crafted regexp covering
|
||||
# all numbers between 3 and y-1.
|
||||
# /var/log/foo\.y\.gz$ HiSerMemberLog
|
||||
# finally, the last element of the Series is allowed to vanish without
|
||||
# being reported, covering step 1.
|
||||
#
|
||||
# Please note that these example rules need to be adapted to the logrotate
|
||||
# configuration for the log. Compression may be disabled or lead to a different
|
||||
# extension, the dateext option may be used, old logs might be held in a
|
||||
# different place, a log series does not necessarily need to be compressed etc.
|
||||
#
|
||||
# Please note that savelog rotates the live log to .0 and not to .1 as it
|
||||
# is logrotates (changeable) default.
|
||||
|
||||
|
||||
# Logs grow in size. Log rotation of these logs will be reported, so
|
||||
# this should only be used for logs that are not rotated daily.
|
||||
Log = OwnerMode+n+S+X
|
||||
|
||||
# Logs that are frequently rotated
|
||||
FreqRotLog = Log-S
|
||||
|
||||
# The first instance of a rotated log: After the log has stopped being
|
||||
# written to, but before rotation
|
||||
LowLog = Log-S
|
||||
|
||||
# Rotated logs change their file name but retain all their other properties
|
||||
SerMemberLog = Full+I
|
||||
|
||||
# The first instance of a compressed, rotated log: After a LowLog was
|
||||
# compressed.
|
||||
LoSerMemberLog = SerMemberLog+ANF
|
||||
|
||||
# The last instance of a compressed, rotated log: After this name, a log
|
||||
# will be removed
|
||||
HiSerMemberLog = SerMemberLog+ARF
|
||||
|
||||
# Not-yet-compressed log created by logrotate's dateext option:
|
||||
# These files appear one rotation (renamed from the live log) and are gone
|
||||
# the next rotation (being compressed)
|
||||
LowDELog = SerMemberLog+ANF+ARF
|
||||
|
||||
# Compressed log created by logrotate's dateext option: These files appear
|
||||
# once and are not touched any more.
|
||||
SerMemberDELog = Full+ANF
|
||||
|
||||
# For daemons that log to a variable file name and have the live log
|
||||
# hardlinked to a static file name
|
||||
LinkedLog = Log-n
|
||||
@@ -1,2 +0,0 @@
|
||||
@@define IP4ADDRESS (25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])(\.(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])){3}
|
||||
@@define IP6ADDRESS ((:(:[0-9A-Fa-f]{1,4}){1,7}|::|[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,6}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,5}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,4}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,3}|::|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){1,2}|::|:[0-9A-Fa-f]{1,4}(::[0-9A-Fa-f]{1,4}|::|:[0-9A-Fa-f]{1,4}(::|:[0-9A-Fa-f]{1,4}))))))))|(:(:[0-9A-Fa-f]{1,4}){0,5}|[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,4}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,3}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4}){0,2}|:[0-9A-Fa-f]{1,4}(:(:[0-9A-Fa-f]{1,4})?|:[0-9A-Fa-f]{1,4}(:|:[0-9A-Fa-f]{1,4})))))):(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])(\.(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9]?[0-9])){3})
|
||||
@@ -1,15 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
if [ -e "/etc/debian_version" ]; then
|
||||
echo "@@ifndef DEBIANVERSION"
|
||||
echo "@@define DEBIANVERSION Debian/$(head -n 1 /etc/debian_version)"
|
||||
echo "@@endif"
|
||||
fi
|
||||
if [ -x "/usr/bin/lsb_release" ]; then
|
||||
for parm in id description release codename; do
|
||||
PARM="$LSB_$(echo $parm | tr 'a-z' 'A-Z')"
|
||||
echo "@@ifndef $PARM"
|
||||
echo "@@define $PARM $(/usr/bin/lsb_release --short --$parm | sed 's/[[:space:]]\+/_/g')"
|
||||
echo "@@endif"
|
||||
done
|
||||
fi
|
||||
@@ -1,19 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
escapere()
|
||||
{
|
||||
sed 's/\./\\./g'
|
||||
}
|
||||
|
||||
if [ -n "$(hostname --fqdn)" ]; then
|
||||
echo "@@define FQDN $(hostname --fqdn | escapere)"
|
||||
fi
|
||||
if [ -n "$(hostname)" ]; then
|
||||
echo "@@define HOSTNAME $(hostname | escapere)"
|
||||
fi
|
||||
if [ -n "$(dnsdomainname)" ]; then
|
||||
echo "@@define DNSDOMAINNAME $(dnsdomainname | escapere)"
|
||||
fi
|
||||
if [ -n "$(dpkg --print-architecture)" ]; then
|
||||
echo "@@define ARCH $(dpkg --print-architecture)"
|
||||
fi
|
||||
@@ -1,20 +0,0 @@
|
||||
# Please note: always remove leading and trailing slashes in path macros
|
||||
# var/run -> run
|
||||
@@ifndef RUN
|
||||
@@define RUN run
|
||||
@@endif
|
||||
# var/lock -> run/lock
|
||||
@@ifndef RUNLOCK
|
||||
@@define RUNLOCK run/lock
|
||||
@@endif
|
||||
# lib/init/rw -> run
|
||||
@@ifndef LIBINITRW
|
||||
@@define LIBINITRW run
|
||||
@@endif
|
||||
|
||||
|
||||
# Please note: mind the trailing slash after transition
|
||||
# dev/\. -> run/
|
||||
@@ifndef DEVDOT
|
||||
@@define DEVDOT run/
|
||||
@@endif
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
echo "@@define YEAR4D $(date +%Y)"
|
||||
@@ -1,5 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ -e /etc/apache2/mods-enabled/suexec.load ]; then
|
||||
echo "@@define APACHE2_SUEXEC 1"
|
||||
fi
|
||||
@@ -1,19 +0,0 @@
|
||||
#! /bin/bash
|
||||
# this script automatically sets the BINDCHROOT variable to the
|
||||
# directory that bind chroots to via configuration in
|
||||
# /etc/default/bind9. This is only going to work if your /etc/default/bind9
|
||||
# is not too modified.
|
||||
#
|
||||
# If you want to use this magic, just uncomment it.
|
||||
# You can also manually set the chroot directory in a non-executable
|
||||
# file: @@define BINDCHROOT /var/cache/bind
|
||||
|
||||
# # Automagically extract chroot directory
|
||||
# . /etc/default/bind9
|
||||
# set $OPTIONS
|
||||
# for i in $@;do
|
||||
# if [ "$1" == "-t" ]
|
||||
# then echo "@@define BINDCHROOT $2"; break
|
||||
# else shift
|
||||
# fi
|
||||
# done
|
||||
@@ -1,10 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if [ -e /etc/news/innfeed.conf ]; then
|
||||
echo -n "@@define INN2_INNFEED_OUTFEEDS ("
|
||||
< /etc/news/innfeed.conf \
|
||||
sed -n '/^[[:space:]]*peer[[:space:]]/{s/^[[:space:]]*peer[[:space:]]\+\([-\.a-z0-9]\+\).*/\1/;p;}' | \
|
||||
tr '\n' '|' |\
|
||||
sed 's/|$/)/'
|
||||
echo
|
||||
fi
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/log/acpid$ Log
|
||||
/var/log/acpid\.1$ LowLog
|
||||
/var/log/acpid\.2\.gz$ LoSerMemberLog
|
||||
/var/log/acpid\.3\.gz$ SerMemberLog
|
||||
/var/log/acpid\.4\.gz$ HiSerMemberLog
|
||||
/@@{RUN}/acpid\.(socket|pid)$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/etc/adjtime$ VarFile
|
||||
@@ -1,13 +0,0 @@
|
||||
/var/lib/aide/aide\.db(\.new)?$ VarFile
|
||||
!/var/lib/aide/aide\.conf\.autogenerated$
|
||||
/var/lib/aide$ VarDir
|
||||
/var/log/aide/aide\.log(\.0)?$ LowLog
|
||||
/var/log/aide/aide\.log\.1\.gz$ LoSerMemberLog
|
||||
/var/log/aide/aide\.log\.[2-5]\.gz$ SerMemberLog
|
||||
/var/log/aide/aide\.log\.6\.gz$ HiSerMemberLog
|
||||
/var/log/aide$ VarDir
|
||||
!/@@{RUN}/aide$
|
||||
!/@@{RUN}/aide\.lock$
|
||||
!/@@{RUN}/aide/cron\.daily\.lock$
|
||||
!/@@{RUN}/aide/cron\.daily$
|
||||
!/@@{RUN}/aide/cron\.daily/((error|a(run|err))log|mailfile)$
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/alsa/asound\.state$ VarFile
|
||||
@@ -1,9 +0,0 @@
|
||||
@@define AMANDALOG var/log/amanda
|
||||
|
||||
/var/lib/dumpdates$ VarFile
|
||||
!/@@{AMANDALOG}/amandad/amandad\.@@{YEAR4D}[0-9]{10}\.debug$
|
||||
/@@{AMANDALOG}/(amandad|client)$ VarDir
|
||||
@@ifdef AMANDABACKUPSET
|
||||
/@@{AMANDALOG}/client/@@{AMANDABACKUPSET}$ VarDir
|
||||
@@endif
|
||||
!/@@{AMANDALOG}/client/[^/]+/(sendsize|killpgrp|sendbackup|selfcheck)\.@@{YEAR4D}[0-9]{10}\.debug$
|
||||
@@ -1,101 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
if ! [ -d /etc/amanda ]; then
|
||||
exit 0
|
||||
fi
|
||||
for configfile in $(find /etc/amanda -name amanda.conf); do
|
||||
config="$(dirname $configfile)"
|
||||
cd $config
|
||||
CONF="${config##*/}"
|
||||
AMANDA_TAPEDEV="$(amgetconf $CONF tapedev)"
|
||||
AMANDA_TAPEDEV="${AMANDA_TAPEDEV#file:}"
|
||||
if [ -d "$AMANDA_TAPEDEV" ]; then
|
||||
echo "@@define AMANDA_TAPEDEV $AMANDA_TAPEDEV"
|
||||
for slot in $(find $AMANDA_TAPEDEV -type d -regex '.*/slot[0-9]+' -printf "%P\n"); do
|
||||
if [ -f "disklist" ]; then
|
||||
while read host dev rest; do
|
||||
if echo $host | grep -q '^\(#.*\)\?$'; then continue; fi
|
||||
dev="$(echo $dev | sed 's|/|_|g')"
|
||||
echo "!@@{AMANDA_TAPEDEV}/$slot/[0-9]{5}[-\.]$host\.$dev\.[0123]$"
|
||||
done < disklist
|
||||
fi
|
||||
cat <<EOF
|
||||
@@{AMANDA_TAPEDEV}/$slot/00000[-\.]$CONF-$(printf "%03d" ${slot#slot})$ VarFile
|
||||
!@@{AMANDA_TAPEDEV}/$slot/[0-9]{5}[-\.]TAPEEND$
|
||||
@@{AMANDA_TAPEDEV}/$slot$ VarDir
|
||||
EOF
|
||||
done
|
||||
cat <<EOF
|
||||
@@{AMANDA_TAPEDEV}/(data|info)$ VarFile
|
||||
@@{AMANDA_TAPEDEV}$ VarDir
|
||||
EOF
|
||||
fi
|
||||
AMANDA_LOGDIR="$(amgetconf $CONF logdir)"
|
||||
if [ -n "$AMANDA_LOGDIR" ]; then
|
||||
cat <<EOF
|
||||
@@define AMANDA_LOGDIR $AMANDA_LOGDIR
|
||||
@@{AMANDA_LOGDIR}/log\.@@{YEAR4D}[0-9]{4}\.0$ LowDELog
|
||||
@@{AMANDA_LOGDIR}/oldlog/log\.@@{YEAR4D}[0-9]{4}\.0$ SerMemberDELog
|
||||
@@{AMANDA_LOGDIR}/amdump\.1$ LoSerMemberLog
|
||||
@@{AMANDA_LOGDIR}/amdump\.[2-8]$ SerMemberLog
|
||||
@@{AMANDA_LOGDIR}/amdump\.9$ HiSerMemberLog
|
||||
@@{AMANDA_LOGDIR}(/oldlog)?$ VarDir
|
||||
EOF
|
||||
fi
|
||||
AMANDA_INDEXDIR="$(amgetconf $CONF indexdir)"
|
||||
if [ -n "$AMANDA_INDEXDIR" ]; then
|
||||
echo "@@define AMANDA_INDEXDIR $AMANDA_INDEXDIR"
|
||||
if [ -f "disklist" ]; then
|
||||
while read host dev rest; do
|
||||
if echo $host | grep -q '^\(#.*\)\?$'; then continue; fi
|
||||
dev="$(echo $dev | sed 's|/|_|g')"
|
||||
echo "!@@{AMANDA_INDEXDIR}/$host/$dev/@@{YEAR4D}[0-9]{4}_[0123]\.gz$"
|
||||
echo "@@{AMANDA_INDEXDIR}/$host/$dev$ VarDir"
|
||||
done < disklist
|
||||
fi
|
||||
fi
|
||||
AMANDA_CHANGERFILE="$(amgetconf $CONF changerfile)"
|
||||
AMANDA_CHANGERDIR="${AMANDA_CHANGERFILE%/changer}"
|
||||
if [ -n "$AMANDA_CHANGERDIR" ]; then
|
||||
echo "@@define AMANDA_CHANGERDIR $AMANDA_CHANGERDIR"
|
||||
echo "@@{AMANDA_CHANGERDIR}/(changer-(access|clean|slot)|tapelist(\.yesterday)?)$ VarFile"
|
||||
echo "@@{AMANDA_CHANGERDIR}$ VarDir"
|
||||
fi
|
||||
AMANDA_INFOFILE="$(amgetconf $CONF infofile)"
|
||||
if [ -n "$AMANDA_INFOFILE" ]; then
|
||||
echo "@@define AMANDA_INFOFILE $AMANDA_INFOFILE"
|
||||
if [ -f "disklist" ]; then
|
||||
while read host dev rest; do
|
||||
if echo $host | grep -q '^\(#.*\)\?$'; then continue; fi
|
||||
dev="$(echo $dev | sed 's|/|_|g')"
|
||||
echo "@@{AMANDA_INFOFILE}/$host/$dev/info$ VarFile"
|
||||
echo "@@{AMANDA_INFOFILE}/$host/$dev$ VarDir"
|
||||
done < disklist
|
||||
fi
|
||||
fi
|
||||
# this is hardcoded since amgetconf refuses to deliver diskdir
|
||||
AMANDA_HOLDING="/srv/amanda/holding"
|
||||
if [ -n "$AMANDA_HOLDING" ]; then
|
||||
echo "$AMANDA_HOLDING$ VarDir"
|
||||
fi
|
||||
echo "@@define AMANDALOG /var/log/amanda/server/$CONF"
|
||||
cat <<EOF
|
||||
!@@{AMANDALOG}/(amcheck|amlogroll|amreport|amtrm(idx|log)|chunker|driver|dumper|planner|taper)\.@@{YEAR4D}[0-9]{10}\.debug$
|
||||
!@@{AMANDALOG}/(chunker|dumper)\.@@{YEAR4D}[0-9]{13}\.debug$
|
||||
@@{AMANDALOG}$ VarDir
|
||||
/var/log/amanda/server$ VarDir
|
||||
EOF
|
||||
done
|
||||
|
||||
cat <<EOF
|
||||
@@define AMANDALOG /var/log/amanda/amandad
|
||||
!@@{AMANDALOG}/(amandad)\.@@{YEAR4D}[0-9]{10}\.debug$
|
||||
@@{AMANDALOG}$ VarDir
|
||||
/tmp/amanda$ VarDir
|
||||
EOF
|
||||
|
||||
#cat <<EOF
|
||||
#!@@{AMANDATMP}/(amandad|amcheck|amtrm(idx|log)|killpgrp|selfcheck|sendbackup|sendsize)\.@@{YEAR4D}[0-9]{10}\.debug$
|
||||
#@@{AMANDATMP}$ RamdiskData-Size
|
||||
#/var/lib/dumpdates$ VarFile
|
||||
#EOF
|
||||
@@ -1,9 +0,0 @@
|
||||
/@@{RUN}/amavis/amavisd.lock$ VarFile
|
||||
/var/lib/amavis/tmp$ VarDir
|
||||
!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}$
|
||||
!/var/lib/amavis/tmp/amavis-[0-9]{8}T[0-9]{6}-[0-9]{5}/(email\.txt|parts)$
|
||||
/var/lib/amavis/db/__db.[0-9]{3} VarFile
|
||||
/var/lib/amavis/db/(cache(-expiry)?|snmp|nanny)\.db$ VarFile
|
||||
/var/lib/amavis/.spamassassin$ VarDir
|
||||
/var/lib/amavis/.spamassassin/bayes_(toks|seen)$ VarFile
|
||||
/var/lib/amavis/.spamassassin/auto-whitelist$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/var/spool/anacron/cron\.(monthly|weekly|daily)$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/anubis\.pid$ VarFile
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/log/apache/(access|error)\.log$ Log
|
||||
/var/log/apache/(access|error)\.log\.1$ LowLog
|
||||
/var/log/apache/(access|error)\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/apache/(access|error)\.log\.[0-9]+\.gz$ SerMemberLog
|
||||
/var/log/apache$ VarDir
|
||||
/@@{RUN}/apache\.pid$ VarFile
|
||||
@@ -1,15 +0,0 @@
|
||||
@@ifdef APACHE2_SUEXEC
|
||||
@@define APACHE2_LOGS (access|error|suexec)
|
||||
@@else
|
||||
@@define APACHE2_LOGS (access|error)
|
||||
@@endif
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\.log$ Log
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\.log\.1$ LowLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\.log\.([3-9]|[1-4][0-9]|5[0-1])\.gz$ SerMemberLog
|
||||
/var/log/apache2/@@{APACHE2_LOGS}\.log\.52\.gz$ HiSerMemberLog
|
||||
|
||||
/@@{RUN}/apache2\.pid$ VarFile
|
||||
/@@{RUN}/apache2/ssl_scache$ VarFile
|
||||
/var/log/apache2$ VarDir
|
||||
/@@{RUN}/apache2$ VarDirInode
|
||||
@@ -1,3 +0,0 @@
|
||||
/var/log/apcupsd\.events$ Log
|
||||
/@@{RUN}/apcupsd\.pid$ VarFile
|
||||
/@@{RUNLOCK}/LCK\.\.$ VarFile
|
||||
@@ -1,80 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
. "$UPAC_settingsd/10_aide_sourceslist"
|
||||
VARDIR="/var/lib/apt"
|
||||
LISTSDIR="$VARDIR/lists"
|
||||
CACHEDIR="/var/cache/apt"
|
||||
ARCHIVESDIR="$CACHEDIR/archives"
|
||||
LOGDIR="/var/log/apt"
|
||||
IGNORE_ARCHIVES=""
|
||||
IGNORE_FRQCHG=""
|
||||
APT_VERS=""
|
||||
|
||||
if [ -x "$UPAC_confd/31_local_apt_settings" ]; then
|
||||
. "$UPAC_confd/31_local_apt_settings"
|
||||
echo "WARNING: usage of $UPAC_confd/31_local_apt_settings is deprecated, please use $UPAC_settingsd/31_aide_apt_settings" >&2
|
||||
elif [ -r "$UPAC_settingsd/31_aide_apt_settings" ]; then
|
||||
# pull in configuration
|
||||
. "$UPAC_settingsd/31_aide_apt_settings"
|
||||
fi
|
||||
|
||||
echo '@@define TRANSLATIONS (ca|cs|da|de|de_DE|en|eo|es|eu|fi|fr|hr|hu|id|it|ja|km|ko|nb|nl|pl|pt|pt_BR|ro|ru|sk|sr|sv|uk|vi|zh|zh_CN|zh_TW)'
|
||||
|
||||
cat $SOURCESLIST /dev/null | sed 's/ #.*$//' | while read deb uri dist comp; do
|
||||
PROTOCOL="$(echo $uri | sed 's|\([^:]\+\).*|\1|')"
|
||||
if [ "$PROTOCOL" = "http" ] || [ "$PROTOCOL" = "ftp" ]; then
|
||||
HOST="$(echo $uri | sed -e 's|.*//\([^/[:space:]]\+\).*|\1|' -e 's|\.|\\\.|g')"
|
||||
HOSTPATH="$(echo $uri | sed -e 's|.*//[^/[:space:]]\+/\?||;s|/$||;s|/|_|g;s|^\(.\+\)$|_\1|' -e 's|\.|\\\.|g')"
|
||||
dist="${dist//\//_}"
|
||||
if [ -n "$DEBUG" ]; then
|
||||
echo "uri $uri"
|
||||
echo "HOST $HOST"
|
||||
echo "HOSTPATH $HOSTPATH"
|
||||
fi
|
||||
if [ "$deb" = "deb" ]; then
|
||||
for c in $comp; do
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_${c}_binary-@@{ARCH}_Packages(\.IndexDiff)?$ VarFile"
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_(InRelease|Release(\.gpg)?)$ VarFile"
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_${c}_i18n_Translation-@@{TRANSLATIONS}(\.IndexDiff)?$ VarFile"
|
||||
done
|
||||
echo "!${LISTSDIR}/partial/${HOST}${HOSTPATH}_dists_${dist}_Release\.gpg\.reverify$"
|
||||
elif [ "$deb" = "deb-src" ]; then
|
||||
for c in $comp; do
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_${c}_source_(Sources|Release)$ VarFile"
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_${c}_source_Sources(\.IndexDiff)?$ VarFile"
|
||||
echo "$LISTSDIR/${HOST}${HOSTPATH}_dists_${dist}_(InRelease|Release(\.gpg)?)$ VarFile"
|
||||
done
|
||||
fi
|
||||
else
|
||||
: # other protocols are not supported. If you feel like they should
|
||||
: # please give a good reason and probably a patch.
|
||||
fi
|
||||
echo -e "\n\n"
|
||||
done
|
||||
|
||||
echo "${LISTSDIR}(/partial)?$ VarDir"
|
||||
echo "${LISTSDIR}/lock$ VarFile"
|
||||
echo "${VARDIR}/periodic/(download-upgradeable|update)-stamp$ VarTime"
|
||||
echo "${VARDIR}/extended_states$ VarFile"
|
||||
echo "${VARDIR}$ VarDir"
|
||||
|
||||
echo "${LOGDIR}/(term|history)\.log$ Log"
|
||||
echo "${LOGDIR}/(term|history)\.log\.1\.gz$ LoSerMemberLog"
|
||||
echo "${LOGDIR}/(term|history)\.log\.([2-9]|1[0-1])\.gz$ SerMemberLog"
|
||||
echo "${LOGDIR}/(term|history)\.log\.12\.gz$ HiSerMemberLog"
|
||||
echo "${LOGDIR}$ VarDir"
|
||||
|
||||
echo "/var/backups/apt\.extended_states\.0$ LowLog"
|
||||
echo "/var/backups/apt\.extended_states\.1\.gz$ LoSerMemberLog"
|
||||
echo "/var/backups/apt\.extended_states\.[2345]\.gz$ SerMemberLog"
|
||||
echo "/var/backups/apt\.extended_states\.6\.gz$ HiSerMemberLog"
|
||||
|
||||
if [ "$IGNORE_ARCHIVES" = "yes" ]; then
|
||||
echo "!$ARCHIVESDIR/[-a-zA-Z0-9%\.~_+]+_(@@{ARCH}|all)\.deb$"
|
||||
fi
|
||||
|
||||
if [ "$IGNORE_FRQCHG" = "yes" ]; then
|
||||
echo "$ARCHIVESDIR(/partial|/lock)?$ VarDir"
|
||||
echo "$CACHEDIR/(src)?pkgcache\.bin$ VarFile"
|
||||
echo "$CACHEDIR$ VarDir"
|
||||
fi
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
. "$UPAC_settingsd/10_aide_sourceslist"
|
||||
|
||||
cat $SOURCESLIST /dev/null | sed 's/ #.*$//' | while read deb uri dist comp; do
|
||||
PROTOCOL="$(echo $uri | sed 's|\([^:]\+\).*|\1|')"
|
||||
HOST="$(echo $uri | sed -e 's|.*//\([^/[:space:]]\+\).*|\1|' -e 's|\.|\\\.|g')"
|
||||
HOSTPATH="$(echo $uri | sed -e 's|.*//[^/[:space:]]\+/\?||;s|/$||;s|/|_|g;s|^\(.\+\)$|_\1|' -e 's|\.|\\\.|g')"
|
||||
if [ "$PROTOCOL" = "http" ] || [ "$PROTOCOL" = "ftp" ]; then
|
||||
for c in $comp; do
|
||||
echo "/var/cache/apt/apt-file/"${HOST//\./\\\.}${HOSTPATH}"_dists_"${dist//\//_}"_"${c}"_Contents-@@{ARCH}\.(gz|IndexDiff)$ VarFile"
|
||||
done
|
||||
fi
|
||||
done
|
||||
|
||||
echo "/var/cache/apt/apt-file$ VarDir"
|
||||
@@ -1,4 +0,0 @@
|
||||
##+# this needs to go in the package
|
||||
!/var/cache/apt-listbugs/%2Findices%2Findex.db-(critical|grave|serious)\.gz$
|
||||
#!/var/cache/apt-listbugs/%2F~taru%2Fapt-listbugs%2Fdb-h%2F[0-9]{2}%2F[0-9]{6}\.status$
|
||||
/var/cache/apt-listbugs$ VarDir
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/apt/listchanges\.db$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/apt-show-versions/(files|ipackages|apackages)$ VarFile
|
||||
/var/cache/apt-show-versions$ VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
# this has been replaced by the scripted rule file 31_aide_apt
|
||||
# this file can be removed
|
||||
@@ -1,2 +0,0 @@
|
||||
# this has been replaced by the scripted rule file 31_aide_apt
|
||||
# this file can be removed
|
||||
@@ -1,2 +0,0 @@
|
||||
# this has been replaced by the scripted rule file 31_aide_apt
|
||||
# this file can be removed
|
||||
@@ -1,13 +0,0 @@
|
||||
/var/log/aptitude$ Log
|
||||
/var/log/aptitude\.1\.gz$ LoSerMemberLog
|
||||
/var/log/aptitude\.[2-5]\.gz$ SerMemberLog
|
||||
/var/log/aptitude\.6\.gz$ HiSerMemberLog
|
||||
/var/backups/aptitude\.pkgstates\.0$ LowLog
|
||||
/var/backups/aptitude\.pkgstates\.1\.gz$ LoSerMemberLog
|
||||
/var/backups/aptitude\.pkgstates\.[2345]\.gz$ SerMemberLog
|
||||
/var/backups/aptitude\.pkgstates\.6\.gz$ HiSerMemberLog
|
||||
/var/lib/aptitude/pkgstates(\.old)?$ VarFile
|
||||
/var/lib/aptitude$ VarDir
|
||||
!/@@{RUNLOCK}/aptitude$
|
||||
/root/\.(aptitude|debtags)$ VarDir
|
||||
/root/\.aptitude/config$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
# removed, rules are contained in 31_aide_aptitude
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/spool/cron/at(spool|jobs)$ VarDir
|
||||
/@@{RUN}/atd\.pid$ VarFile
|
||||
@@ -1,13 +0,0 @@
|
||||
@@ifdef BINDCHROOT
|
||||
@@{BINDCHROOT}/dev/log$ LowLog
|
||||
@@{BINDCHROOT}/dev VarDir
|
||||
@@endif
|
||||
@@{BINDCHROOT}/var/log/bind/queries\.log$ Log
|
||||
@@{BINDCHROOT}/var/log/bind/queries\.log\.0$ LoSerMemberLog
|
||||
@@{BINDCHROOT}/var/log/bind/queries\.log\.[1-8]$ SerMemberLog
|
||||
@@{BINDCHROOT}/var/log/bind/queries\.log\.9$ HiSerMemberLog
|
||||
@@{BINDCHROOT}/var/log/bind VarDir
|
||||
@@{BINDCHROOT}/@@{RUN}/named/(session\.key|named\.pid)$ VarFile
|
||||
@@{BINDCHROOT}/@@{RUN}/named$ VarDirInode
|
||||
@@{BINDCHROOT}/var/cache/bind$ VarDir
|
||||
@@{BINDCHROOT}/var/cache/bind/[-[:alnum:].]+$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/log/btmp$ Log
|
||||
/var/log/btmp\.1$ LowLog
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/log/setuid/setuid.changes$ Log
|
||||
/var/log/setuid/setuid.changes\.1$ LoSerMemberLog
|
||||
/var/log/setuid/setuid.changes\.[2-9]$ SerMemberLog
|
||||
/var/log/setuid/setuid.changes\.10$ HiSerMemberLog
|
||||
/var/log/setuid/setuid.(today|yesterday)$ VarFile
|
||||
/var/log/setuid$ VarDir
|
||||
@@ -1,8 +0,0 @@
|
||||
/var/log/clamav/clamav\.log$ Log
|
||||
/var/log/clamav/clamav\.log\.1$ LowLog
|
||||
/var/log/clamav/clamav\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/clamav/clamav\.log\.([3-9]|1[0-1])\.gz$ SerMemberLog
|
||||
/var/log/clamav/clamav\.log\.12\.gz$ HiSerMemberLog
|
||||
/@@{RUN}/clamav/clamd\.(ctl|pid)$ VarFile
|
||||
/var/log/clamav$ VarDir
|
||||
/@@{RUN}/clamav$ VarDirInode
|
||||
@@ -1 +0,0 @@
|
||||
# removed, clamav-data has been removed from Debian
|
||||
@@ -1,10 +0,0 @@
|
||||
/var/log/clamav/freshclam\.log$ Log
|
||||
/var/log/clamav/freshclam\.log\.1$ LowLog
|
||||
/var/log/clamav/freshclam\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/clamav/freshclam\.log\.([3-9]|1[0-1])\.gz$ SerMemberLog
|
||||
/var/log/clamav/freshclam\.log\.12\.gz$ HiSerMemberLog
|
||||
/var/lib/clamav/(daily|main)\.inc$ VarDir
|
||||
/var/lib/clamav/bytecode\.cld$ VarFile
|
||||
/var/lib/clamav/daily\.inc/daily\.(info|[nmhp]db)$ VarFile
|
||||
/var/lib/clamav/mirrors.dat$ VarFile
|
||||
/@@{RUN}/clamav/freshclam\.pid$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/console-log(/Debian-console-log)?$ VarFile
|
||||
/@@{RUN}/console-log/Debian-console-log/(8-_-_var_-_log_-_exim4_-_mainlog|9-_-_var_-_log_-_syslog_-_syslog)$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/var/cache/cracklib/cracklib_dict\.(hwm|pw(d|i))$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/crond\.(pid|reboot)$ VarFile
|
||||
@@ -1,10 +0,0 @@
|
||||
/var/lib/cron-apt/_-_etc_-_cron-apt_-_config/mailchanges/(0-update-|3-download-)[0-9a-f]{32}$ VarFile
|
||||
!/var/lib/cron-apt/lockfile$
|
||||
/var/lib/cron-apt$ VarDir
|
||||
!/tmp/cron-apt\.[a-zA-Z0-9]{6}$
|
||||
!/tmp/cron-apt\.[a-zA-Z0-9]{6}/initlog$
|
||||
/var/log/cron-apt/log$ Log
|
||||
/var/log/cron-apt/log\.1\.gz$ LoSerMemberLog
|
||||
/var/log/cron-apt/log\.[23]\.gz$ SerMemberLog
|
||||
/var/log/cron-apt/log\.4\.gz$ HiSerMemberLog
|
||||
/var/log/cron-apt$ VarDir
|
||||
@@ -1,16 +0,0 @@
|
||||
@@define CUPS_LOGS (access|error|page|cups-pdf)
|
||||
/var/log/cups/@@{CUPS_LOGS}_log$ Log
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\.1\.gz$ LoSerMemberLog
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\.[2-6]\.gz$ SerMemberLog
|
||||
/var/log/cups/@@{CUPS_LOGS}_log\.7\.gz$ HiSerMemberLog
|
||||
/var/log/cups$ VarDir
|
||||
|
||||
/var/cache/cups/(job|remote)\.cache$ VarFile
|
||||
/var/cache/cups/(([0-9]|([1-9]|1[0-9]|2[0-4])[0-9]|25[0-5])\.){3}([0-9]|([1-9]|1[0-9]|2[0-4])[0-9]|25[0-5])\.snmp$ VarTime
|
||||
|
||||
!/var/spool/cups/(c[0-9]{5}|d[0-9]{5}-[0-9]{3})$
|
||||
/var/spool/cups$ VarDir
|
||||
|
||||
!/@@{RUN}/cups/certs/0$
|
||||
/@@{RUN}/cups/(printcap|cups(d\.pid|\.sock))$ VarFile
|
||||
/@@{RUN}/cups(/certs)?$ VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/dbus/(pid|system_bus_socket)$ VarFile
|
||||
/@@{RUN}/dbus$ VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/ddclient/ddclient\.cache$ VarFile
|
||||
/@@{RUN}/ddclient\.pid$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/debconf/(config|templates)\.dat(-old)?$ VarFile
|
||||
/var/cache/debconf$ VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/debsecan/history$ VarFile
|
||||
/var/lib/debsecan$ VarDir
|
||||
@@ -1,3 +0,0 @@
|
||||
@@define INTERFACES eth0
|
||||
/@@{RUN}/dhclient\.@@{INTERFACES}\.pid$ VarFile
|
||||
/var/lib/dhcp(3|)/dhclient\.@@{INTERFACES}\.leases$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/dhcp3/dhcpd.leases~?$ VarFile
|
||||
/var/lib/dhcp3$ VarDir
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/dhcpd\.pid$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/dlocate/(dpkg-list|dlocatedb(|\.stamps|\.old))$ VarFile
|
||||
/var/lib/dlocate$ VarDir
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/lib/dokuwiki/data/cache/[0-9a-f]/[0-9a-f]{32}\.(feed|i|xhtml)$ VarFile
|
||||
/var/lib/dokuwiki/data/(changes\.log|(index|word)\.idx)$ VarFile
|
||||
/var/lib/dokuwiki/data/meta/([a-z]+\.indexed|_dokuwiki\.changes)$ VarFile
|
||||
/var/lib/dokuwiki/data/meta$ VarDir
|
||||
/var/lib/dokuwiki/data/pages/[a-z]+\.txt$ VarFile
|
||||
/var/lib/dokuwiki/data/(attic|cache|locks|pages)$ VarDir
|
||||
@@ -1,5 +0,0 @@
|
||||
/var/lib/dovecot/ssl-parameters\.dat$ VarFile
|
||||
/var/lib/dovecot$ VarDir
|
||||
/@@{RUN}/dovecot/(auth-worker\.[0-9]{4}|master\.pid)$ VarFile
|
||||
/@@{RUN}/dovecot/login/(default|ssl-parameters\.dat)$ VarFile
|
||||
/@@{RUN}/dovecot(/login)?$ VarDirInode
|
||||
@@ -1,13 +0,0 @@
|
||||
/var/lib/dpkg/(available|status)(-old)?$ VarFile
|
||||
/var/lib/dpkg/status\.yesterday(\.[0-9]*)?(\.gz)?$ VarFile
|
||||
/var/lib/dpkg/(info|updates|lock)$ VarDir
|
||||
/var/lib/dpkg$ VarDir
|
||||
/var/log/(alternatives|dpkg)\.log$ Log
|
||||
/var/log/(alternatives|dpkg)\.log\.1$ LowLog
|
||||
/var/log/(alternatives|dpkg)\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/(alternatives|dpkg)\.log\.([3-9]|1[0-1])\.gz$ SerMemberLog
|
||||
/var/log/(alternatives|dpkg)\.log\.12\.gz$ HiSerMemberLog
|
||||
/var/backups/dpkg\.status\.0$ LowLog
|
||||
/var/backups/dpkg\.status\.1\.gz$ LoSerMemberLog
|
||||
/var/backups/dpkg\.status\.[2345]\.gz$ SerMemberLog
|
||||
/var/backups/dpkg\.status\.6\.gz$ HiSerMemberLog
|
||||
@@ -1,2 +0,0 @@
|
||||
/etc/\.git/index$ VarInode
|
||||
/etc/\.git$ VarDirTime
|
||||
@@ -1,11 +0,0 @@
|
||||
/var/spool/exim4/gnutls-params$ VarFile
|
||||
/var/spool/exim4/db/(wait-remote_smtp(_smarthost)?|retry|callout)$ VarFile
|
||||
!/var/spool/exim4/input/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}-[DHJ]$
|
||||
!/var/spool/exim4/msglog/[a-zA-Z0-9]{6}-[a-zA-Z0-9]{6}-[a-zA-Z0-9]{2}$
|
||||
!/var/spool/exim4/gnutls-params$
|
||||
!/var/spool/exim4/.rnd$
|
||||
/var/spool/exim4(/(input|msglog|scan))?$ VarDir
|
||||
/var/lib/exim4/config.autogenerated$ VarFile
|
||||
/@@{RUN}/exim4/exim.pid$ VarFile
|
||||
/var/lib/exim4$ VarDir
|
||||
/@@{RUN}/exim4$ VarDirInode
|
||||
@@ -1,10 +0,0 @@
|
||||
# if your host frequently produces paniclog entries (this happens if
|
||||
# spam or virus scanners are in use), set
|
||||
# @@define EXIM4_LOGS (main|reject|panic)
|
||||
@@define EXIM4_LOGS (main|reject)
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log$ Log
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\.1$ LowLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\.[3-9]\.gz$ SerMemberLog
|
||||
/var/log/exim4/@@{EXIM4_LOGS}log\.10\.gz$ HiSerMemberLog
|
||||
/var/log/exim4$ VarDir
|
||||
@@ -1,7 +0,0 @@
|
||||
/var/log/fail2ban\.log$ Log
|
||||
/var/log/fail2ban\.log\.1$ LowLog
|
||||
/var/log/fail2ban\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/fail2ban\.log\.3\.gz$ SerMemberLog
|
||||
/var/log/fail2ban\.log\.4\.gz$ HiSerMemberLog
|
||||
/@@{RUN}/fail2ban/fail2ban\.(sock|pid)$ VarFile
|
||||
/@@{RUN}/fail2ban$ VarDirInode
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/fcron\.(pid|fifo)$ VarFile
|
||||
/var/spool/fcron/systab$ VarFile
|
||||
/var/spool/fcron$ VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/cache/locate/locatedb$ VarFile
|
||||
/var/cache/locate$ VarDir
|
||||
@@ -1 +0,0 @@
|
||||
/root/.gnupg/random_seed$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/hald/hald\.pid$ VarFile
|
||||
/@@{RUN}/hald$ VarDirInode
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/hdapsd\.pid$ VarFile
|
||||
@@ -1,2 +0,0 @@
|
||||
@@define INTERFACES eth0
|
||||
/@@{RUN}/ifplugd\.@@{INTERFACES}\.pid$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/network/ifstate$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/inetd\.pid$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
/@@{DEVDOT}initramfs$ VarDirInode
|
||||
@@ -1,9 +0,0 @@
|
||||
/var/lib/urandom/random-seed$ VarFile
|
||||
/var/lib/(urandom|initscripts)$ VarDir
|
||||
/var/log/dmesg$ Log
|
||||
/var/log/dmesg\.0$ LowLog
|
||||
/var/log/dmesg\.1\.gz$ LoSerMemberLog
|
||||
/var/log/dmesg\.[23]\.gz$ SerMemberLog
|
||||
/var/log/dmesg\.4\.gz$ HiSerMemberLog
|
||||
/var/log/fsck/check(root|fs)$ VarFile
|
||||
/@@{RUN}/motd$ VarFile
|
||||
@@ -1,25 +0,0 @@
|
||||
@@define NEWSLOGS (errlog|expire\.log|news(\.crit|\.err|\.notice)?|rc\.news|sendsys\.log|unwanted\.log|inn_status\.html|innfeed\.status|expire\.(lastlowmark|list))
|
||||
@@define OLDLOGS (active|errlog|expire\.log|news(\.crit|\.err|\.notice)?|sendsys\.log|unwanted\.log)
|
||||
|
||||
!/var/lib/news/history(\.(dir|hash|index))?$
|
||||
/var/lib/news/(active(\.old)?|newsgroups|\.news\.daily)$ VarFile
|
||||
|
||||
!/var/spool/news/articles(/[-a-z0-9+]+)+$
|
||||
/var/spool/news/overview/group\.index$ VarFile
|
||||
!/var/spool/news/overview(/[a-z0-9])+/[-\.a-z0-9+]+\.(IDX|DAT)$
|
||||
/var/spool/news/overview(/[a-z0-9])+$ VarDir
|
||||
!/var/spool/news/articles/control/(newgroup|checkgroups|rmgroup)/[0-9]*$
|
||||
/var/spool/news/innfeed/@@{INN2_INNFEED_OUTFEEDS}\.(lock|output|input)$ VarFile
|
||||
!/var/spool/news/innfeed/innfeed-dropped\.A[0-9]{6}$
|
||||
/var/spool/news/innfeed$ VarDir
|
||||
/var/spool/news/incoming(/tmp)?$ VarDir
|
||||
|
||||
/@@{RUN}/news/(control|(innd|innfeed|innwatch)\.pid|innwatch\.time|LOCK\.innwatch|nntpin)$ VarFile
|
||||
/@@{RUN}/news$ VarDirInode
|
||||
|
||||
/var/log/news/path/inpaths\.[0-9]{10}$ VarFile+ANF
|
||||
/var/log/news/@@{NEWSLOGS}$ VarFile
|
||||
/var/log/news/OLD/(expire\.log\.0|unwanted\.log)$ VarFile
|
||||
/var/log/news/OLD/@@{OLDLOGS}\.1\.gz$ LoSerMemberLog
|
||||
/var/log/news/OLD/@@{OLDLOGS}\.[0-9]+\.gz$ SerMemberLog
|
||||
/var/log/news(/(path|OLD))?$ VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/ippl/ippl.(pid|conf)$ VarFile
|
||||
/@@{RUN}/ippl$ VarDirInode
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/tmp/krb5kdc_rcache$ VarFile
|
||||
/var/tmp/(nfs|host)_[0-9]+$ VarFile
|
||||
/tmp/krb5cc_machine_[A-Z.]+$ VarFile
|
||||
!/tmp/krb5cc_[0-9]+_[[:alnum:]]+$
|
||||
/var/lib/krb5kdc/principal$ VarFile+s+b+i
|
||||
/var/lib/krb5kdc/principal\.ok$ VarTime
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/laptop-mode-tools/(state(-brightness-command)?|enabled|start-stop-undo-actions|nolm-mountopts)$ VarFile
|
||||
/@@{RUN}/laptop-mode-tools$ VarDirInode
|
||||
/@@{RUNLOCK}/lmt-(req|invoc)\.lock$ VarInode
|
||||
@@ -1 +0,0 @@
|
||||
/var/log/lastlog$ Log
|
||||
@@ -1 +0,0 @@
|
||||
# removed, Debian migrated to /run
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/apache2/fcgid/sock$ VarDir
|
||||
!/var/lib/apache2/fcgid/sock/[0-9]{5}\.[0-9]$
|
||||
@@ -1,9 +0,0 @@
|
||||
/var/(lib|cache)/libvirt/qemu$ VarDir
|
||||
/@@{RUN}/libvirtd\.pid$ VarFile
|
||||
/@@{RUN}/libvirt/libvirt-sock(-ro)?$ VarFile
|
||||
/var/lib/libvirt/qemu/[-[:alnum:]]+\.monitor$ VarInode
|
||||
/var/lib/libvirt/qemu/(save|snapshot)$ VarDir
|
||||
/var/lib/libvirt$ VarDir
|
||||
/@@{RUNLOCK}/libvirt-guests$ VarDirInode
|
||||
/@@{RUN}/libvirt/qemu/[-[:alnum:]]+\.(pid|xml)$ VarFile
|
||||
/@@{RUN}/libvirt(/(qemu|uml-guest))?$ VarDirInode
|
||||
@@ -1,11 +0,0 @@
|
||||
@@define LIGHTTP_LOGS (access|error)
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\.log$ Log
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\.log\.1$ LowLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\.log\.2\.gz$ LoSerMemberLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\.log\.([3-9]|10|11)\.gz$ SerMemberLog
|
||||
/var/log/lighttpd/@@{LIGHTTP_LOGS}\.log\.12\.gz$ HiSerMemberLog
|
||||
|
||||
/@@{RUN}/lighttpd\.pid$ VarFile
|
||||
/@@{RUN}/lighttpd$ VarDirInode
|
||||
|
||||
/tmp/php\.socket-[0-9]$ VarFile
|
||||
@@ -1,3 +0,0 @@
|
||||
/var/lib/logcheck/offset\.var\.log\.(syslog|auth\.log)$ VarFile
|
||||
/var/lib/logcheck$ VarDir
|
||||
/@@{RUNLOCK}/logcheck$ VarDirInode
|
||||
@@ -1 +0,0 @@
|
||||
/var/lib/logrotate/status$ VarFile
|
||||
@@ -1,3 +0,0 @@
|
||||
/etc/lvm/cache/\.cache$ VarInode
|
||||
/etc/lvm/cache$ VarDir
|
||||
/@@{RUNLOCK}/lvm$ VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/mail/[a-z0-9]+$ VarFile
|
||||
/var/mail$ VarDir
|
||||
@@ -1,37 +0,0 @@
|
||||
# maintained on q
|
||||
!/var/lib/mailman/data/(bounce-events|heldmsg-[-[:alnum:]]+)-[[:digit:]]+\.pck$
|
||||
/var/lib/mailman/data$ VarDir
|
||||
!/var/lib/mailman/archives/private/[-[:alnum:]]+/database/@@{YEAR4D}-[[:alnum:]]+-(author|subject|thread|article|date)$
|
||||
!/var/lib/mailman/archives/private/[-[:alnum:]]+/@@{YEAR4D}-[[:alnum:]]+/(author|subject|thread|date|index|[[:digit:]]{5,6})\.html$
|
||||
!/var/lib/mailman/archives/private/[-[:alnum:]]+/@@{YEAR4D}-[[:alnum:]]\.txt(\.gz)?$
|
||||
!/var/lib/mailman/archives/private/[-[:alnum:]]+/attachments/[[:digit:]]{8}/[[:digit:]]{8}/[[:alnum:]\.]+$
|
||||
|
||||
/var/lib/mailman/lists/[-[:alnum:]]+/(config|request|pending)\.pck$ VarFile
|
||||
/var/lib/mailman/lists/[-[:alnum:]]+/(config)\.pck\.last$ VarFile
|
||||
/var/lib/mailman/lists/[-[:alnum:]]+$ VarDir
|
||||
|
||||
/var/lib/mailman/qfiles/(in|archive|bounces|retry|out|virgin)$ VarFile
|
||||
|
||||
/@@{RUNLOCK}/mailman/master-qrunner(\.[[:alnum:]]+\.[[:digit:]]+)?$ VarFile
|
||||
/@@{RUNLOCK}/mailman$ VarDirInode
|
||||
|
||||
@@define LOGFILES4 (vette|error|bounce|digest)
|
||||
/var/log/mailman/@@{LOGFILES4}$ Log
|
||||
/var/log/mailman/@@{LOGFILES4}\.1$ LowLog
|
||||
/var/log/mailman/@@{LOGFILES4}\.2\.gz$ LoSerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES4}\.3\.gz$ SerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES4}\.4\.gz$ HiSerMemberLog
|
||||
|
||||
@@define LOGFILES12 (subscribe|post)
|
||||
/var/log/mailman/@@{LOGFILES12}$ Log
|
||||
/var/log/mailman/@@{LOGFILES12}\.1$ LowLog
|
||||
/var/log/mailman/@@{LOGFILES12}\.2\.gz$ LoSerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES12}\.([3-9]|1[0-1])\.gz$ SerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES12}\.12\.gz$ HiSerMemberLog
|
||||
|
||||
@@define LOGFILES7 (qrunner|fromusenet|locks|smtp(-failure)?)
|
||||
/var/log/mailman/@@{LOGFILES7}$ Log
|
||||
/var/log/mailman/@@{LOGFILES7}\.1$ LowLog
|
||||
/var/log/mailman/@@{LOGFILES7}\.2\.gz$ LoSerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES7}\.[3-6]\.gz$ SerMemberLog
|
||||
/var/log/mailman/@@{LOGFILES7}\.7\.gz$ HiSerMemberLog
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/cache/man/(cat[123456789]|local|opt|fsstnd|oldlocal|X11R6)$ VarDir
|
||||
|
||||
@@define LANGS (ca|cs|da|de(\.UTF-8)?|en|es(\.UTF-8)?|fi|fr(\.(ISO8859-1|UTF-8))?|gl|hr|hu|id|it(\.(ISO8859-1|UTF-8))?|ja(\.UTF-8)?|jp|ko|nl|pl(\.(UTF-8|ISO8859-2))?|pt(_BR)?|ro|ru|sv|sk|sl|tr|vi|zh(_(CH|CN|TW))?)
|
||||
|
||||
/var/cache/man(/@@{LANGS})?/index\.db$ VarFile
|
||||
/var/cache/man(/@@{LANGS})?$ VarDir
|
||||
@@ -1,3 +0,0 @@
|
||||
/@@{RUN}/mdadm/(monitor|autorebuild)\.pid$ VarFile
|
||||
/run/mdadm/m(ap|d[0-9]+-uevent)$ VarInode
|
||||
/@@{RUN}/mdadm$ VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/var/lib/mlocate/mlocate\.db$ VarFile
|
||||
/var/lib/mlocate$ VarDir
|
||||
@@ -1 +0,0 @@
|
||||
/lib/modules/[-0-9\.]*/modules\.dep$ VarFile
|
||||
@@ -1 +0,0 @@
|
||||
# removed, /etc/mtab is now a symlink
|
||||
@@ -1,25 +0,0 @@
|
||||
/var/cache/munin/www/index\.html$ VarFile
|
||||
@@ifdef DNSDOMAINNAME
|
||||
@@ifdef FQDN
|
||||
/var/cache/munin/www/@@{DNSDOMAINNAME}/(index\.html|@@{FQDN}/[-_[:alnum:]]+\.(png|html))$ VarFile
|
||||
/var/lib/munin/@@{DNSDOMAINNAME}/@@{FQDN}-.*\.rrd$ VarFile
|
||||
/@@{RUN}/munin/munin-@@{DNSDOMAINNAME}-@@{FQDN}\.lock$ VarFile
|
||||
@@endif
|
||||
/var/cache/munin/www/@@{DNSDOMAINNAME}/comparison-(month|day|year|week)\.html$ VarFile
|
||||
@@endif
|
||||
!/@@{RUN}/munin/munin-(update|datafile|graph|limits|html)\.lock$
|
||||
/var/lib/munin/(limits|datafiles|munin-(update|graph)\.stats)$ VarFile
|
||||
!/var/lib/munin/munin-(update|graph)\.stats\.tmp$
|
||||
/var/lib/munin/plugin-state/(exim_mailstats(-(([0-9]|([1-9]|1[0-9]|2[0-4])[0-9]|25[0-5])\.){3}([0-9]|([1-9]|1[0-9]|2[0-4])[0-9]|25[0-5]))?|(smart-[sh]d[a-z]|munin-cupsys-pages)\.state)$ VarFile
|
||||
/var/lib/munin/plugin-state/(postfix_mailvolume|_proc_net_tcp[6]?)$ VarFile
|
||||
/var/lib/munin/datafile$ VarFile
|
||||
/var/lib/munin$ VarDir
|
||||
@@define LOGFILES (node|graph|update|html|limits)
|
||||
/var/log/munin/munin-@@{LOGFILES}\.log$ Log
|
||||
/var/log/munin/munin-@@{LOGFILES}\.log\.1\.gz$ LoSerMemberLog
|
||||
/var/log/munin/munin-@@{LOGFILES}\.log\.[2-6]\.gz$ SerMemberLog
|
||||
/var/log/munin/munin-@@{LOGFILES}\.log\.7\.gz$ HiSerMemberLog
|
||||
/var/log/munin$ VarDir
|
||||
!/@@{RUN}/munin/munin-server-socket\.[0-9]+$
|
||||
/@@{RUN}/munin/munin-node\.pid$ VarFile
|
||||
/@@{RUN}/munin$ VarDirInode
|
||||
@@ -1,23 +0,0 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# generate aide exclude patterns for all nodes listed in $MUNINCONF
|
||||
|
||||
MUNINCONF=/etc/munin/munin.conf
|
||||
|
||||
[ -e $MUNINCONF ] || exit 0
|
||||
|
||||
HOSTS=$(grep '^\[[[:alnum:]:.]\+\]' $MUNINCONF | tr -d '[]')
|
||||
|
||||
escape_dots()
|
||||
{
|
||||
echo $1 | sed 's/\./\\\./g'
|
||||
}
|
||||
|
||||
for HOST in $HOSTS; do
|
||||
DOMAIN=$(escape_dots ${HOST#*.})
|
||||
DHOST=$(escape_dots $HOST)
|
||||
|
||||
echo "/var/cache/munin/www/$DOMAIN/(index\.html|$DHOST/[-_[:alnum:]]+\.(png|html))$ VarFile"
|
||||
echo "/var/lib/munin/$DOMAIN/$DHOST-.*\.rrd$ VarFile"
|
||||
echo "/@@{RUN}/munin/munin-(update|datafile|$DOMAIN-$DHOST|limits)\.lock$ VarFile"
|
||||
done
|
||||
@@ -1,8 +0,0 @@
|
||||
/var/lib/mysql$ VarDir
|
||||
/var/lib/mysql/(ibdata1|ib_logfile0)$ VarFile
|
||||
/var/log/mysql$ VarDir
|
||||
/var/log/mysql/mysql-bin\.index$ VarFile
|
||||
!/var/log/mysql/mysql-bin\.[0-9]{3}$
|
||||
!/var/log/mysql/mysql-bin\.[0-9]{6}$
|
||||
/@@{RUN}/mysqld/mysqld\.(sock|pid)$ VarFile
|
||||
/@@{RUN}/mysqld$ VarDirInode
|
||||
@@ -1,10 +0,0 @@
|
||||
/var/cache/nagios2/(objects\.cache|status\.dat)$ VarFile
|
||||
/var/lib/nagios2/(comments|retention)\.dat$ VarFile
|
||||
/var/lib/nagios2/rw/nagios\.cmd$ VarFile
|
||||
/var/lib/nagios2/rw$ VarDir
|
||||
/var/log/nagios2/nagios\.log$ LowLog
|
||||
/var/log/nagios2/archives/nagios-[01][0-9]-[0123][0-9]-@@{YEAR4D}-00\.log$ SerMemberDELog
|
||||
/@@{RUN}/nagios2/nagios2\.pid$ VarFile
|
||||
/var/(cache|lib|log)/nagios2$ VarDir
|
||||
/@@{RUN}/nagios2$ VarDirInode
|
||||
/var/log/nagios2/archives$ VarDir
|
||||
@@ -1,15 +0,0 @@
|
||||
!/var/lib/nagios3/spool/checkresults/[a-zA-Z0-9]{7}(\.ok)?$
|
||||
/var/lib/nagios3/spool/checkresults$ VarDir
|
||||
/var/lib/nagios3/retention\.dat$ VarFile
|
||||
/var/lib/nagios3$ VarDir
|
||||
|
||||
/var/log/nagios3/archives/nagios-[0-9]{2}-[0-9]{2}-[0-9]{4}-[0-9]{2}\.log$ LoSerMemberLog
|
||||
/var/log/nagios3/archives$ VarDir
|
||||
/var/log/nagios3/nagios\.log$ LowLog
|
||||
/var/log/nagios3$ VarDir
|
||||
|
||||
/var/cache/nagios3/(status\.dat|objects\.cache)$ VarFile
|
||||
/var/cache/nagios3$ VarDir
|
||||
|
||||
/@@{RUN}/nagios3/nagios3\.pid$ VarFile
|
||||
/@@{RUN}/nagios3$ VarDirInode
|
||||
@@ -1 +0,0 @@
|
||||
/@@{RUN}/network$ VarDirInode
|
||||
@@ -1,8 +0,0 @@
|
||||
/@@{RUN}/(rpc\.statd|sm-notify)\.pid$ VarFile
|
||||
/var/lib/nfs/state$ VarFile
|
||||
/var/lib/nfs/etab$ VarInode
|
||||
/var/lib/nfs/rpc_pipefs/nfs/clnt[0-9]/(info|krb5|idmap)$ VarTime
|
||||
/var/lib/nfs/rpc_pipefs/nfs/clnt[0-9]$ VarDir
|
||||
/var/lib/nfs/rpc_pipefs/(statd|portmap|nfs|mount|lockd)$ VarDir
|
||||
/var/lib/nfs/rpc_pipefs$ VarDirInode
|
||||
/var/lib/nfs(/v4recovery)?$ VarDir
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/nagios/nrpe\.pid$ VarFile
|
||||
/@@{RUN}/nagios$ VarDirInode
|
||||
@@ -1,3 +0,0 @@
|
||||
/var/cache/nscd/(passwd|group|services)$ VarFile
|
||||
/@@{RUN}/nscd/(socket|nscd\.pid)$ VarFile
|
||||
/@@{RUN}/nscd$ VarDirInode
|
||||
@@ -1,2 +0,0 @@
|
||||
/@@{RUN}/nslcd/(socket|nslcd\.pid)$ VarFile
|
||||
/@@{RUN}/nslcd$ VarDirInode
|
||||
@@ -1,6 +0,0 @@
|
||||
/var/lib/ntp/ntp\.drift$ VarFile
|
||||
/var/lib/ntp$ VarDir
|
||||
!/var/log/ntpstats/peerstats(\.[0-9]{8})?
|
||||
!/var/log/ntpstats/loopstats(\.[0-9]{8})?
|
||||
/var/log/ntpstats$ VarDir
|
||||
/@@{RUN}/ntpd\.pid$ VarFile
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user