Bug#693292: apache2.2-bin: False positives with mod_log_forensic and check_forensic
Package: apache2.2-bin
Version: 2.2.16-6+squeeze8
Severity: normal
Since update 2.2.16-6+squeeze8 check_forensic reports much more failed
requests than before. Most of them are false positives. I think, this is
caused by mod_log_forensic, throwing in some additional '-' from
time to time.
For instance:
Check_forensic reports:
#check_forensic /var/log/apache2/forensic.log
+20773:50a49a18:8063|GET RequestDetailsRemoved
[...]
If I check this with grep I get:
#grep '20773:50a49a18:8063' /var/log/apache2/forensic.log
+20773:50a49a18:8063|GET RequestDetailsRemoved
--20773:50a49a18:8063
-- System Information:
Debian Release: 6.0.6
APT prefers stable
APT policy: (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/4 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/dash
Versions of packages apache2.2-bin depends on:
ii libapr1 1.4.2-6+squeeze4 The Apache Portable Runtime Librar
ii libaprutil1 1.3.9+dfsg-5 The Apache Portable Runtime Utilit
ii libaprutil1-dbd-sqlite 1.3.9+dfsg-5 The Apache Portable Runtime Utilit
ii libaprutil1-ldap 1.3.9+dfsg-5 The Apache Portable Runtime Utilit
ii libc6 2.11.3-4 Embedded GNU C Library: Shared lib
ii libcap2 1:2.19-3 support for getting/setting POSIX.
ii libldap-2.4-2 2.4.23-7.2 OpenLDAP libraries
ii libpcre3 8.02-1.1 Perl 5 Compatible Regular Expressi
ii libssl0.9.8 0.9.8o-4squeeze13 SSL shared libraries
ii zlib1g 1:1.2.3.4.dfsg-3 compression library - runtime
apache2.2-bin recommends no packages.
apache2.2-bin suggests no packages.
-- no debconf information
Reply to: