aboutsummaryrefslogtreecommitdiffstats
path: root/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
diff options
context:
space:
mode:
Diffstat (limited to 'roles/host/templates/usr_local_etc_pylogsentinel.conf.j2')
-rw-r--r--roles/host/templates/usr_local_etc_pylogsentinel.conf.j222
1 files changed, 22 insertions, 0 deletions
diff --git a/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2 b/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
new file mode 100644
index 0000000..cb80742
--- /dev/null
+++ b/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
@@ -0,0 +1,22 @@
+[system]
+state_dir = /var/run/pylogsentinel
+max_block_size = 10M
+
+[logs.standard]
+cmd = find / -type f -path '*/var/log/*' ! -name '*access.log' ! -name '*.bz2' ! -name 'dmesg*' ! -name 'syncthing*'
+
+[logs.access]
+paths = /usr/local/jails/containers/ingress/var/log/nginx/access.log
+
+[action.default]
+cmd = echo -e "---------\nMatched $RULE_ID in $FILE at line $LINE, context:\n\n$CONTEXT\n" >> /tmp/pylogsentinel.daily
+
+[rule.error]
+description = Error-like conditions
+pattern = /(error|fatal|exception|killed)/i
+logs = standard
+
+[rule.access]
+description = HTTP code >=500 in access log
+pattern = /HTTP\/[0-9].[0-9]" 5[0-9][0-9]/
+logs = access