Re: /var/log/syslog is smaller than last time checked!
On Fri, 16 Sep 2011 17:12:26 +0300, Jari Fredriksson wrote:
> I just received this message from logcheck, on two machines (Debian), at
> the same minute. They do not share /var/log/ via NFS or anything.
>
> What might this be? Same minute!
>
> System Events
> =-=-=-=-=-=-=
> ***************
> *************** This could indicate tampering.
> *** WARNING ***: Log file /var/log/syslog is smaller than last time
> checked!
Hum... could it be because logrotate made its job and cutted the syslog
file while logcheck was analyzing it?
It could be just a pure casualty :-?
Greetings,
--
Camaleón
Reply to: