KS-Soft. Network Management Solutions
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister    ProfileProfile    Log inLog in 

[HowTo] check text (log) file for growth?

 
Post new topic   Reply to topic    KS-Soft Forum Index -> Configuration, Maintenance, Troubleshooting
View previous topic :: View next topic  
Author Message
rasc



Joined: 11 Oct 2009
Posts: 95

PostPosted: Wed Mar 09, 2011 3:58 am    Post subject: [HowTo] check text (log) file for growth? Reply with quote

Hi all,

hope one of you got an idea how to solve DOS attacks against our mail server (using HostMon)*.
I liked to watch the log file and if it grows for more than X [lines | kB] per time get alarmed.


How would I achieve that in HM?

Thanks, Rasc



*The issue is: Every other week any 'malicious person' tries to spy out usernames/passwords of local POP3 accounts.
After enough attacks the server crashes.

Unfortunately the log (plain text log file) is pretty bad/unusable. A typical login looks like
Connection from 1.2.3.4, Wed Mar 09 10:17:06 2011
User Fred, (2) 0 messages, 0 bytes
0 sec. elapsed, connection closed Wed Mar 09 10:17:06 2011
and a typical attack like this:
Connection from 178.239.83.1, Wed Mar 09 10:15:17 2011
1 sec. elapsed, connection closed Wed Mar 09 10:15:18 2011
Back to top
View user's profile Send private message
KS-Soft Europe



Joined: 16 May 2006
Posts: 2832

PostPosted: Wed Mar 09, 2011 8:18 am    Post subject: [HowTo] check text (log) file for growth? Reply with quote

You may setup "Folder/File Size" test and Action with "Advanced mode" and expression like:
Code:
('%SuggestedReply%'-'%SuggestedLastReply%') > '3 Kb'


Please check the manual or visit our web site for more information at:
Advanced action: http://www.ks-soft.net/hostmon.eng/mframe.htm#actions.htm#advancedaction
Folder/File Size test: http://www.ks-soft.net/hostmon.eng/mframe.htm#tests.htm#dirsize
Back to top
View user's profile Send private message Send e-mail Visit poster's website
rasc



Joined: 11 Oct 2009
Posts: 95

PostPosted: Wed Mar 09, 2011 11:27 am    Post subject: Reply with quote

Thank you very much for your suggestion. Works like a charm!
Back to top
View user's profile Send private message
rasc



Joined: 11 Oct 2009
Posts: 95

PostPosted: Wed Mar 09, 2011 9:23 pm    Post subject: Reply with quote

...really works like a charm!
Had to get up tonight at 02:40 am and 4:10 am because POP3 and IMAP were attacked. But that's much better than 30min server downtime

Thanks again!
Back to top
View user's profile Send private message
KS-Soft



Joined: 03 Apr 2002
Posts: 12795
Location: USA

PostPosted: Thu Mar 10, 2011 10:39 am    Post subject: Reply with quote

You are welcome

Regards
Alex
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    KS-Soft Forum Index -> Configuration, Maintenance, Troubleshooting All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

KS-Soft Forum Index