On Thu, 14 Mar 2024 11:25:52 -0700 cono...@panix.com (John Conover) wrote: > Email from logcheck(1) contains: > > E: File could not be read: /var/log/syslog > E: File could not be read: /var/log/auth.log > > which do not exist in bookworm 12.5. > > The offending file: > > /etc/logcheck/logcheck.logfiles.d/syslog.logfiles > > contains both filenames.
Interesting. My logcheck instance works just fine, andmakes no such complaints. However, my /etc/logcheck/logcheck.logfiles.d/syslog.logfiles has them commented out. root@issola:~# cat /etc/logcheck/logcheck.logfiles.d/syslog.logfiles ## Log entries in the logs listed below will be checked by logcheck # The default is to check standard syslog files # created by rsyslog or other syslog daemons # (If your system does not use a syslog daemon you # can comment these lines out) # /var/log/syslog # /var/log/auth.log root@issola:~# So you might do the same. -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/