Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/CISOfy/lynis.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTopi Miettinen <toiwoton@gmail.com>2020-03-19 22:25:50 +0300
committerTopi Miettinen <toiwoton@gmail.com>2020-03-19 22:25:50 +0300
commit6de9c31cf54c9be5fd7524fc5fcdfa42994a45f6 (patch)
tree39764af568d2dc13fedafd65b1b27d15f19cf258 /plugins
parent6d9ebe41365aaf51e41ca4bd322b93a6104e7322 (diff)
Fix journalctl output parsing for recent journalctls
Process output from journalctl (v245) like: "Archived and active journals take up xxx.xM in the file system." Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
Diffstat (limited to 'plugins')
-rw-r--r--plugins/plugin_systemd_phase12
1 files changed, 1 insertions, 1 deletions
diff --git a/plugins/plugin_systemd_phase1 b/plugins/plugin_systemd_phase1
index 9d424915..0c73f45d 100644
--- a/plugins/plugin_systemd_phase1
+++ b/plugins/plugin_systemd_phase1
@@ -176,7 +176,7 @@
if [ ! "${JOURNALCTLBINARY}" = "" -a ${SYSTEMD_RUNNING} -eq 1 ]; then PREQS_MET="YES"; else PREQS_MET="NO"; fi
Register --test-no PLGN-3816 --preqs-met ${PREQS_MET} --weight L --network NO --description "Query journal for boot related information" --progress
if [ ${SKIPTEST} -eq 0 ]; then
- FIND=`${JOURNALCTLBINARY} --disk-usage | awk '{ if ($1=="Journals") { print $4 }}'`
+ FIND=`${JOURNALCTLBINARY} --disk-usage | awk '{ if ($1=="Journals") { print $4 } else if ($1=="Archived") { print $7 }}'`
Report "journal_disk_size=${FIND}"
LogText "Result: journals are ${FIND} in size"
fi