Swatchのインストール(ログだけ)

yumリポジトリファイルを追加

vi /etc/yum.repos.d/dag.repo

[dag]
name=Dag RPM Repository for Fedora Core
baseurl=http://apt.sw.be/fedora/$releasever/en/$basearch/dag
gpgcheck=1
enabled=1

yumを使用してインストール

[root@fourth tmp]# yum install swatch
Setting up Install Process
Setting up Repos
dag                       100% |=========================| 1.1 kB    00:00
base                      100% |=========================| 1.1 kB    00:00
updates-released          100% |=========================|  951 B    00:00
Reading repository metadata in from local files
dag       : ################################################## 2860/2860
base      : ################################################## 2622/2622
updates-re: ################################################## 1020/1020
Resolving Dependencies
--> Populating transaction set with selected packages. Please wait.
---> Package swatch.noarch 0:3.1-1.1.fc3.rf set to be updated
--> Running transaction check
--> Processing Dependency: perl(Date::Calc) for package: swatch
--> Processing Dependency: perl(Time::HiRes) for package: swatch
--> Processing Dependency: perl(Date::Format) for package: swatch
--> Processing Dependency: perl(Date::Parse) for package: swatch
--> Processing Dependency: perl(Mail::Sendmail) for package: swatch
--> Processing Dependency: perl(File::Tail) for package: swatch
--> Restarting Dependency Resolution with new changes.
--> Populating transaction set with selected packages. Please wait.
---> Package perl-File-Tail.noarch 0:0.99.1-1.1.fc3.rf set to be updated
---> Package perl-Mail-Sendmail.noarch 0:0.79-1.1.fc3.rf set to be updated
---> Package perl-Time-HiRes.i386 0:1.55-3 set to be updated
---> Package perl-TimeDate.noarch 1:1.16-2 set to be updated
---> Package perl-Date-Calc.i386 0:5.3-9 set to be updated
--> Running transaction check
--> Processing Dependency: perl(Bit::Vector) for package: perl-Date-Calc
--> Restarting Dependency Resolution with new changes.
--> Populating transaction set with selected packages. Please wait.
---> Package perl-Bit-Vector.i386 0:6.3-3 set to be updated
--> Running transaction check

Dependencies Resolved
Transaction Listing:
  Install: swatch.noarch 0:3.1-1.1.fc3.rf - dag

Performing the following to resolve dependencies:
  Install: perl-Bit-Vector.i386 0:6.3-3 - base
  Install: perl-Date-Calc.i386 0:5.3-9 - base
  Install: perl-File-Tail.noarch 0:0.99.1-1.1.fc3.rf - dag
  Install: perl-Mail-Sendmail.noarch 0:0.79-1.1.fc3.rf - dag
  Install: perl-Time-HiRes.i386 0:1.55-3 - base
  Install: perl-TimeDate.noarch 1:1.16-2 - base
Total download size: 482 k
Is this ok [y/N]: y
Downloading Packages:
(1/4): perl-File-Tail-0.9 100% |=========================|  21 kB    00:00
(2/4): swatch-3.1-1.1.fc3 100% |=========================|  45 kB    00:00
(3/4): perl-Mail-Sendmail 100% |=========================|  23 kB    00:00
(4/4): perl-TimeDate-1.16 100% |=========================|  31 kB    00:08
Running Transaction Test
Finished Transaction Test
Transaction Test Succeeded
Running Transaction
Installing: perl-Time-HiRes 100 % done 1/7
Installing: perl-File-Tail 100 % done 2/7
Installing: perl-TimeDate 100 % done 3/7
Installing: perl-Mail-Sendmail 100 % done 4/7
Installing: perl-Date-Calc 100 % done 5/7
Installing: swatch 100 % done 6/7
Installing: perl-Bit-Vector 100 % done 7/7

Installed: swatch.noarch 0:3.1-1.1.fc3.rf
Dependency Installed: perl-Bit-Vector.i386 0:6.3-3 perl-Date-Calc.i386 0:5.3-9 perl-File-Tail.noarch 0:0.99.1-1.1.fc3.rf perl-Mail-Sendmail.noarch 0:0.79-1.1.fc3.rf perl-Time-HiRes.i386 0:1.55-3 perl-TimeDate.noarch 1:1.16-2
Complete!
[root@fourth tmp]# mkdir /etc/swatch
[root@fourth tmp]# vi /etc/swatch/.swatchrc
watchfor /Priority\: 2/
echo=normal
mail=user hoge@hoge.jp, subject=Snort Security Alert!