|
watchfor
/(panic|halt|SunOS Release)/
mail=nomo,subject=swatch(panic or halt ??)
#
FTP
# FTP SUCCESS
watchfor /FTP
LOGIN FROM/
mail=nomo,subject=swatch(ftp
success user&addr)
#
FTP FAILED(TCP_WRAPPERS)
watchfor /in.ftpd/&&/refused connect/
mail=nomo,subject=swatch(ftp refused host)
#
FTP FAILED(NO WRAPPERS)
watchfor /ftpd/&&/failed
login from/
mail=nomo,subject=swatch(ftp
refused host)
watchfor /telnet/&&/from/
mail=nomo,subject=swatch(telnet
from ??)
#
POP3
# POP3 SUCCESS
# POP3 FROM
watchfor /pop3/&&/from/
mail=nomo,subject=swatch(pop3 from)
#
POP3 USER
watchfor /in.apop3d/&&/local0.info/
mail=nomo,subject=swatch(pop3 user)
#
POP3 FAILED
# POP3 FAILED(APOP BUT PASSWD IS INCORRECT)
watchfor /in.apop3d/&&/authentication failure/
mail=nomo,subject=swatch(pop3 passwd not correct)
# POP3 USER UNKNOWN(NOT APOP)
watchfor /in.apop3d/&&/ERR Password supplied/
mail=nomo,subject=swatch(pop3 user unknown)
#
SSH
# SSH SUCCESS
watchfor /sshd/&&/Password/&&/accepted/
mail=nomo,subject=swatch(ssh user)
#
SSH FAILED
watchfor /sshd/&&/refused connect/
mail=nomo,subject=swatch(ssh refused from)
#
etc
watchfor /syslogd: going down/
mail=nomo,subject=swatch(syslogd stopped)
|