This file is indexed.

/etc/epylog/weed_dist.cf is in epylog 1.0.7-2.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
##
# NOTE:
# Editing this file is not recommended. If you do, you might miss newer 
# revisions of this list in the future versions.
# See weed_local.cf for instructions on how to add or delete rules.
#

[pam]
\(pam_unix\).*: session closed for
\(pam_unix\).*: check pass;

[dhcpd]
dhcpd: DHCPREQUEST
dhcpd: DHCPACK
dhcpd: DHCPDISCOVER
dhcpd: DHCPOFFER
dhcpd: DHCPRELEASE
dhcpd: DHCPINFORM

[rpc]
rpc.mountd: authenticated mount request from
rpc.mountd: authenticated unmount request
rpc.statd.*: Version .* Starting
rpc.statd.*: Caught signal 15, un-registering and exiting

[automount]
automount.*: expired
automount.*: attempting to mount entry
automount.*: lookup\(file\): .* failed
automount.*: starting automounter
automount.*: using kernel protocol
automount.*: shutting down
automount.*: .* No such key in map

[crond]
CROND.*: \(mailman\) CMD \(/usr/bin/python
CROND.*: \(root\) CMD \(.*/sbin/rmmod -as\)
CROND.*: \(root\) CMD \(/usr/lib/sa/sa\d
CROND.*: \(root\) CMD \(run-parts
anacron.*: Updated timestamp for job

[bind]
named.*: lame server resolving
named.*: .* NS points to CNAME
named.*: Response from unexpected source
named.*: .* All possible A RR's lame
named.*: bad referral
named.*: Cleaned cache
named.*: USAGE
named.*: NSTATS
named.*: XSTATS
named.*: .* points to a CNAME
named.*: denied update from
named.*: .* Bogus LOOPBACK

[gnome]
gnome-name-server.*: input condition is:
gnome-name-server.*: name server starting
gnome-name-server.*: starting
gnome-name-server.*: name server was running
gconfd.*: Resolved address
gconfd.*: GConf server is not in use
gconfd.*: Exiting
gconfd.*: starting
gconfd.*: .* shutting down cleanly
gdm.*: Couldn't authenticate user
xscreensaver.*: FAILED LOGIN

[sshd]
sshd.*: Generating new .* key.
sshd.*: .* key generation complete
sshd.*: Connection closed
sshd.*: Could not reverse map address
sshd.*: Received disconnect from
sshd.*: error: Could not get shadow information for
sshd.*: Invalid user .* from

[xinetd]
xinetd.*: .* Transport endpoint is not connected
xinetd.*: EXIT:

[uw-imap]
imapd.*: AUTHENTICATE
imapd.*: Logout
imapd.*: Killed
imapd.*: imap.*service init
imapd.*: Command stream end of file
imapd.*: Autologout
imapd.*: Connection reset by peer
ipop3d.*: AUTHENTICATE
ipop3d.*: Logout
ipop3d.*: Killed
ipop3d.*: Autologout
ipop3d.*: pop3.*service init

[courier-imap]
imapd.*: Connection, ip=\[\S+\]
imapd.*: LOGOUT, user=\S+, ip=\[\S+\]
imapd.*: Disconnected, ip=\[\S+\]
imapd.*: DISCONNECTED, user=\S+, ip=\[\S+\]
imapd.*: LOGOUT, ip=\[\S+\]
pop3d.*: Connection, ip=\[\S+\]
pop3d.*: LOGOUT, user=\S+, ip=\[\S+\]
pop3d.*: Disconnected, ip=\[\S+\]
pop3d.*: DISCONNECTED, user=\S+, ip=\[\S+\]
pop3d.*: LOGOUT, ip=\[\S+\]

[postfix]
postfix/smtp\[\d+\]: connect to
postfix/smtp\[\d+\]: warning: no MX host
postfix/smtp\[\d+\]: warning: numeric domain name in resource data
postfix/smtp\[\d+\]: warning: host .* with my own hostname
postfix/smtpd.*: connect from
postfix/smtpd.*: disconnect from
postfix/smtpd.*: TLS connection established
postfix/smtpd.*: lost connection
postfix/cleanup
postfix/pickup

[sendmail]
sendmail\[.*:.*NOQUEUE: Null connection from
sendmail\[.*:.*timeout waiting for input

[qmail]
qmail:.* new msg
qmail:.* end msg
qmail:.* status:

[spamd]
spamd\[.*: info:
spamd\[.*: processing message
spamd\[.*: checking message
spamd\[.*: connection from
spamd\[.*: Creating default_prefs

[printer]
printer: ready to print
printer: status change
printer: printing
printer: peripheral low-power state

[pumpd]
pumpd.*: renewed lease for interface
pumpd.*: configured interface

[afpd]
afpd.*: ASIP session:
afpd.*: afp_flushfork:
afpd.*: .*B read,.*B written

[ntpd]
ntpd.*: kernel time discipline status change

[kernel]
kernel: application .* uses obsolete OSS audio interface
kernel: SELinux: initialized
kernel: device .* left promiscuous mode
kernel: .*: disabled promiscuous mode
usb-uhci.c: interrupt, status
PCI: Found IRQ
PCI: Sharing IRQ
PCI: Setting latency timer
kernel: agpgart: Found
kernel: agpgart: Putting

[misc]
modprobe: Can't locate module
logger: punching nameserver .* through the firewall
HORDE\[\S*\s*\[imp\] Logout
LOGIN ON tty.
dhclient: DHCPREQUEST
dhclient: DHCPACK
dhclient: DHCPDISCOVER
dhclient: bound to
dbus: avc: .* buckets used

[systemd]
systemd-logind\[\d+\]: Removed session \d+\.



## $Revision$ ##