Viruses counted by mailgraph and viruses counted on /var/log/messages do not match

View: New views
2 Messages — Rating Filter:   Alert me  

Viruses counted by mailgraph and viruses counted on /var/log/messages do not match

by Juan Albacar :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi everybody,
First of all, I would like to thank the author for this useful tool, keep it
up!!

I am using Centos 4.5 + postfix + amavisd-new + clamd (clamAV). All was
working fine until I think of checking the results in virus counting. So for
this purpouse, I count the viruses found in  /var/log/messages, where clamAV
reports when a virus is found. I did some 'greps' and got the result. I
realized then, that the results were not the same as the results from
mailgraph, mailgraph counted less viruses.

Anyone that has checked the virus results and has the same problem??

Thank you


--
Unsubscribe mailto:mailgraph-request@...?subject=unsubscribe
Help        mailto:mailgraph-request@...?subject=help
Archive     http://lists.ee.ethz.ch/mailgraph
WebAdmin    http://lists.ee.ethz.ch/lsg2.cgi


Re: Viruses counted by mailgraph and viruses counted on /var/log/messages do not match

by Leon Kolchinsky-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

> Hi everybody,
> First of all, I would like to thank the author for this useful tool, keep
> it
> up!!
>
> I am using Centos 4.5 + postfix + amavisd-new + clamd (clamAV). All was
> working fine until I think of checking the results in virus counting. So
> for
> this purpouse, I count the viruses found in  /var/log/messages, where
> clamAV
> reports when a virus is found. I did some 'greps' and got the result. I
> realized then, that the results were not the same as the results from
> mailgraph, mailgraph counted less viruses.
>
> Anyone that has checked the virus results and has the same problem??
>
> Thank you
>

AFAIK mailgraph is showing you the stats on a 24 hour scale so you really
have to check malware in your logs for the latest 24 hours, i.e. not only in
the current maillog file but also in the last rotated (every night at my
place) log.


Regards,
Leon Kolchinsky

--
Unsubscribe mailto:mailgraph-request@...?subject=unsubscribe
Help        mailto:mailgraph-request@...?subject=help
Archive     http://lists.ee.ethz.ch/mailgraph
WebAdmin    http://lists.ee.ethz.ch/lsg2.cgi