|
||||||
| Forums FAQ | Members List | Search | Today's Posts | Mark Forums Read |
| Unreviewed How To and FAQ POST HERE: Tips and solutions for SUSE Linux from the community. (Please do not post questions) |
![]() |
|
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
Jim Henderson wrote:
> On Thu, 05 Nov 2009 22:05:41 +0000, cjcox wrote: > >> Hmmm... I'd say reducing your log sizes by literraly GIGABYTES daily is >> a good thing... yes?? > > GB? That would seem to indicate a bad logrotate policy to me. Possibly. But probably NOT just a logrotate policy, but we could take the logs during the day and somehow shuttle them off somewhere... but when you're dealing with this much data, it's a difficult problem no matter how you slice it up. (which is why I love solutions that try to reduce the volume of data to begin with). |
|
|||
|
On Sat, 07 Nov 2009 21:34:32 +0000, Chris Cox wrote:
> Jim Henderson wrote: >> On Thu, 05 Nov 2009 22:05:41 +0000, cjcox wrote: >> >>> Hmmm... I'd say reducing your log sizes by literraly GIGABYTES daily >>> is a good thing... yes?? >> >> GB? That would seem to indicate a bad logrotate policy to me. > > Possibly. But probably NOT just a logrotate policy, but we could take > the logs during the day and somehow shuttle them off somewhere... but > when you're dealing with this much data, it's a difficult problem no > matter how you slice it up. Yeah, other things would contribute as well. I've got a kernel module that gives me a useless message on an OES2 server - in that it doesn't identify the module that's actually having the problem. I get about 3 messages a second in my logs as a result. One of these days I'll track it down. > (which is why I love solutions that try to reduce the volume of data to > begin with). You and me alike. :-) Jim -- Jim Henderson openSUSE Forums Moderator |
|
|||
|
At some time I also had SSH pointing outside on port 22, and saw a lot of brute force attacks on that port, with a lot of interesting user names.
To fix it I installed an SSH filter. Unfortunately I forgot the name of that tool and can't find it online. The tool was a wrapper for SSH that will detect brute force attacks, then after a few attempts, it will add the attacker's IP to the firewall blocking rules (iptables) and remove it after a certain elapsed time. |
|
||||
|
Quote:
I'm no network manager but this is an interesting thread. So after some googling I found the above article. Makes for interesting reading.
__________________
Lord Flasheart: Always treat your plane like you treat your woman. Lieutenant George: Take her home at the weekend to meet your mother? Lord Flasheart: No, get inside her five times a day and take her to heaven and back! |
![]() |
|
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|