On Thu, 12 Apr 2012 12:13:14 +0200, Tilman Schmidt t.schmidt@phoenixsoftware.de said:
T> The most frequent reason for a lot of unmatched entries showing up is T> that the corresponding logwatch script is out of date wrt the program T> whose log is being watched. Program maintainers tend to change the T> wording of messages on a whim, and the logwatch scripts need to be T> updated to keep up with them. So yes, there is a constant need to update T> logwatch, specifically its scripts.
I found the "checksyslog" setup easier to understand and modify. http://www.hcst.net/~vogelke/src/logfiles/ has some examples.