blob: cf24b206366b952eb2e2727f196ea42c01771742 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
|
[system]
state_dir = /var/run/pylogsentinel
max_block_size = 10M
[logs.standard]
cmd = /usr/local/bin/fd -t f -E 'access.log' -E 'syncthing.log' '^[a-zA-Z-_]+(\.log|\.txt)$' /var/log /usr/local/jails/containers/*/var/log
[logs.arr]
cmd = /usr/local/bin/fd -t f '^[a-zA-Z-_]+(\.log|\.txt)$' /usr/local/jails/containers/dl/usr/local/*/logs
[logs.access]
paths = /usr/local/jails/containers/ingress/var/log/nginx/access.log
[action.default]
cmd = echo -e "---------\nMatched $RULE_ID in $FILE at line $LINE, context:\n\n$CONTEXT\n" >> /tmp/pylogsentinel.daily
[rule.error_std]
description = Error-like conditions
pattern = /(error|fatal|exception|killed)/i
logs = standard
[rule.error_arr]
description = Arr software error
pattern = /(\|error\|)/i
logs = arr
[rule.access]
description = HTTP code >=500 in access log
pattern = /HTTP\/[0-9].[0-9]" 5[0-9][0-9]/
logs = access
|