• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Resolved No logrotate for fail2ban.log

SabineW

Basic Pleskian
Hi to all,
on my server (Plesk Onyx v17.0.17 on Ubuntu 14.04.5 LTS) the fail2ban.log is quite large (more than 8 GB) and it seems, that the logrotate dosn't work correctly.
With the command
logrotate -d -f /etc/logrotate.d/fail2ban
I got this errormessage
error: skipping "/var/log/fail2ban.log" because parent directory has insecure permissions (It's world writable or writable by group which is not "root") Set "su" directive in config file to tell logrotate which user/group should be used for rotation.
but the "su" directive is set in my config file
# use the syslog group by default, since this is the owning group
# of /var/log/syslog.
su root syslog
And here is the information about the rights of the logfile:
-rw------- 1 root root 8,8G Dez 30 11:23 fail2ban.log

Are this enough Information to help?
(Sorry for my bad english.)
 
... because parent directory has insecure permissions (It's world writable or writable by group which is not "root") ...
--> Check the permissions and owner of the parent directory, not of the log file. I think /var/log ought to be 755 and root:root.
 
Hi Peter,
thank you for your help. I have changed the permissions and the group of the /var/log-directory and now the logrotate works fine.
Best regards
Sabine
 
Back
Top