[Esd-l] statistitc for procmail sanitizer

John D. Hardin jhardin at impsec.org
Fri Mar 26 06:05:58 PST 2004

On Fri, 26 Mar 2004, [iso-8859-2] Mgr Marcela Donihova wrote:

> I'm looking for  statistics of procmail sanitizer?
> Exist that aplication?

Kind of. It's very lightweight.

If you define $SECURITY_MSGID_LOG to a file, then the sanitizer will
write the Message-ID of trapped messages to that file. You can do a
periodic "wc -l" on that file to see how many messages were trapped.

I have a little script that lets me tie this into MRTG so I get a
graph of quarantines over time. I suppose if you wanted to do more
statistical analysis you could do something like point
$SECURITY_MSGID_LOG at a named pipe and have the pipe reader log time
and so forth.

More complex analysis should probably just process the quarantine
folder directly.

What sort of statistics are you looking for?

