<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=LOGCHECK_-_Documentation</id>
	<title>LOGCHECK - Documentation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=LOGCHECK_-_Documentation"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=LOGCHECK_-_Documentation&amp;action=history"/>
	<updated>2026-05-02T18:38:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=LOGCHECK_-_Documentation&amp;diff=893&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=LOGCHECK_-_Documentation&amp;diff=893&amp;oldid=prev"/>
		<updated>2026-01-17T07:07:07Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 07:07, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Command Usage ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Command Usage ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=LOGCHECK_-_Documentation&amp;diff=508&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Command Usage == To use `logcheck`, the following basic syntax is applied:   &lt;nowiki&gt; logcheck [options]&lt;/nowiki&gt;  Where `[options]` can vary based on the user’s preferences and the log files to be checked.  == Main Options ==  *  &lt;nowiki&gt;-s&lt;/nowiki&gt;,  &lt;nowiki&gt;--sendmail&lt;/nowiki&gt;: This option sends the output via email to a specified recipient. *  &lt;nowiki&gt;-c&lt;/nowiki&gt;,  &lt;nowiki&gt;--config&lt;/nowiki&gt; &lt;path&gt;: Specifies a custom configuration file instead...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=LOGCHECK_-_Documentation&amp;diff=508&amp;oldid=prev"/>
		<updated>2025-12-14T08:40:17Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Command Usage == To use `logcheck`, the following basic syntax is applied:   &amp;lt;nowiki&amp;gt; logcheck [options]&amp;lt;/nowiki&amp;gt;  Where `[options]` can vary based on the user’s preferences and the log files to be checked.  == Main Options ==  *  &amp;lt;nowiki&amp;gt;-s&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--sendmail&amp;lt;/nowiki&amp;gt;: This option sends the output via email to a specified recipient. *  &amp;lt;nowiki&amp;gt;-c&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--config&amp;lt;/nowiki&amp;gt; &amp;lt;path&amp;gt;: Specifies a custom configuration file instead...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Command Usage ==&lt;br /&gt;
To use `logcheck`, the following basic syntax is applied:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
logcheck [options]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Where `[options]` can vary based on the user’s preferences and the log files to be checked.&lt;br /&gt;
&lt;br /&gt;
== Main Options ==&lt;br /&gt;
&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-s&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--sendmail&amp;lt;/nowiki&amp;gt;: This option sends the output via email to a specified recipient.&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-c&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--config&amp;lt;/nowiki&amp;gt; &amp;lt;path&amp;gt;: Specifies a custom configuration file instead of the default one.&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-f&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--filter&amp;lt;/nowiki&amp;gt; &amp;lt;filter_name&amp;gt;: Uses a specific filter for parsing logs.&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-t&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--test&amp;lt;/nowiki&amp;gt;: Runs the logcheck program in test mode without sending any emails or making any changes.&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-i&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--ignore&amp;lt;/nowiki&amp;gt; &amp;lt;filename&amp;gt;: Ignores the logs in the specified file.&lt;br /&gt;
*  &amp;lt;nowiki&amp;gt;-h&amp;lt;/nowiki&amp;gt;,  &amp;lt;nowiki&amp;gt;--help&amp;lt;/nowiki&amp;gt;: Displays a help message with available options.&lt;br /&gt;
&lt;br /&gt;
== Configuration File ==&lt;br /&gt;
&lt;br /&gt;
The main configuration file for `logcheck` is located at `/etc/logcheck/logcheck.conf`. This file controls the general behavior and filtering rules that `logcheck` applies to logs. Key options in this file include:&lt;br /&gt;
&lt;br /&gt;
* **MAILTO**: Defines the email address to which log summaries will be sent.&lt;br /&gt;
* **LOGCHECK_RE**: Sets the regular expression filters used to detect suspicious activity.&lt;br /&gt;
* **LOGCHECK\_FILTER**: Specifies a default filter to apply to the log files.&lt;br /&gt;
&lt;br /&gt;
An example of a basic configuration entry in `/etc/logcheck/logcheck.conf`:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
# Define recipient email address for logcheck alerts&lt;br /&gt;
MAILTO=&amp;quot;admin@example.com&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Set the filter type to &amp;quot;security&amp;quot;&lt;br /&gt;
LOGCHECK_FILTER=&amp;quot;security&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Filtering Logs ==&lt;br /&gt;
&lt;br /&gt;
`logcheck` uses regular expressions (regex) to filter through log files. The tool has predefined filters (e.g., for security, system, and authentication logs) but can also be customized with user-defined filters. Some common filters include:&lt;br /&gt;
&lt;br /&gt;
* **Security**: Focuses on logs related to potential security breaches.&lt;br /&gt;
* **System**: Filters standard system events and errors.&lt;br /&gt;
* **Applications**: Targets logs from applications such as Apache or MySQL.&lt;br /&gt;
&lt;br /&gt;
You can specify a custom filter by using the `-f` option when running `logcheck`.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
logcheck -f security&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command checks the logs against the security filter.&lt;br /&gt;
&lt;br /&gt;
== Running Logcheck Automatically ==&lt;br /&gt;
&lt;br /&gt;
To have `logcheck` run automatically on a schedule, you can use `cron`. A typical cron job configuration to run `logcheck` every day at midnight would look like this:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
0 0 * * * /usr/sbin/logcheck&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will execute `logcheck` daily and send the output to the configured email address.&lt;br /&gt;
&lt;br /&gt;
== Example: Basic Logcheck Execution ==&lt;br /&gt;
&lt;br /&gt;
Here is a basic example of running `logcheck`:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
logcheck -t&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will test the configuration and show what actions would be taken without actually sending any email.&lt;br /&gt;
&lt;br /&gt;
== Example: Running Logcheck with Custom Filter ==&lt;br /&gt;
&lt;br /&gt;
If you have a custom filter file, you can specify it using the `-f` flag:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
logcheck -f /path/to/custom_filter&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will apply the custom filter to your logs instead of the default one.&lt;br /&gt;
&lt;br /&gt;
== Logs and Output ==&lt;br /&gt;
&lt;br /&gt;
When `logcheck` runs, it reviews the relevant log files (e.g., `/var/log/messages`, `/var/log/secure`, etc.) for any events that match its filtering rules. If any such events are found, a summary report is generated. By default, this report is emailed to the address specified in the configuration file.&lt;br /&gt;
&lt;br /&gt;
The output is typically categorized into levels, such as:&lt;br /&gt;
&lt;br /&gt;
* **Informational**: General information on system activities.&lt;br /&gt;
* **Warning**: Warnings about non-critical issues.&lt;br /&gt;
* **Critical**: Critical system or security issues that require attention.&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* [Logcheck Official Documentation](https://man7.org/linux/man-pages/man8/logcheck.8.html)&lt;br /&gt;
* [Logcheck GitHub Repository](https://github.com/logcheck/logcheck)&lt;br /&gt;
* [Debian Package for Logcheck](https://packages.debian.org/stable/admin/logcheck)&lt;br /&gt;
* [Logcheck Configuration Guide](https://www.serverwatch.com/tutorials/logcheck-configuring-and-using/)&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>