Red Hat Bugzilla – Bug 162947
egrep problems cause empty report section
Last modified: 2007-11-30 17:11:09 EST
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
Description of problem:
logwatch in FC4 appears to have changed /etc/log.d/scripts/shared/onlycontains and /etc/log.d/scripts/shared/remove, specifically in the way that egrep is called. In FC3, my ipchains logs would be summarized in the Kernel section of the dayily logwatch report. In FC4, I've been seeing only the following:
--------------------- Kernel Begin ------------------------
egrep: module: No such file or directory
---------------------- Kernel End -------------------------
I didn't have time to troubleshoot the problem too much, but was able to resolve the immediate problem by replacing both scripts with the version from an FC3 system (logwatch-5.2.2-1). By downgrading the files (/etc/log.d/scripts/shared/onlycontains and /etc/log.d/scripts/shared/remove), I was able to regain normal operation of the Kernel log summary.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
Install an FC4 system, all entries in the "Kernel" section of the syslog summary will be supressed and an "egrep: module: No such file or directory" error will be listed instead.
Expected Results: I expect the same log summarization as experienced in FC3.
I'm listing the severity as high since this has been my primary way of monitoring ipchains log entries and is probably the case for others as well. In that sense, there is a loss of data and this is potentially a security problem.
Created attachment 116618 [details]
diff of the new v6 (.orig) scripts vs the old v5 scripts
Attached is a diff of the downgrade that I performed. It appears that the new
v6 logwatch scripts are perl scripts? Whereas the old v5 scripts are sh
Thank you for your notice,
this bug is fixed in new devel version (logwatch-6.1.2-2).
If there is any problem, please reopen this bug.
Isn't this problem important enough to push the new 'logwatch' for FC4 updates?
I have the same feeling as Jan - why isn't this going to be pushed as an FC4
At the very least, can the URL to the logwatch-6.1.2-2 RPM be provided?
Looking at the logwatch.org website, their most recent RPM is only 6.1.2-1.
URL for RawHide i386 logwatch-6.1.2-2 RPM:
I update logwatch fc4 version too (fixed fc4 version is logwatch-6.1.2-1.fc4,
there are fixed several other bugs). This version will be in fc4 updates soon.
*** Bug 166864 has been marked as a duplicate of this bug. ***