Compare commits

...
Sign in to create a new pull request.

1 commit

Author SHA1 Message Date
Stefan Schulze Frielinghaus
db9091db68 Initial EPEL 10 build 2026-02-12 21:08:21 +01:00
8 changed files with 136 additions and 0 deletions

1
.gitignore vendored Normal file
View file

@ -0,0 +1 @@
/sec-2.9.4.tar.gz

12
conf.README Normal file
View file

@ -0,0 +1,12 @@
This is the SEC configuration directory. Because SEC usage varies so widely
from user to user, this package is configured by default to not run.
The commented-out default settings in /etc/sysconfig/sec will load any file in
this directory with a .sec suffix. You can find several example rules at
https://github.com/simple-evcorr/rulesets
and install the ones you want here (taking into account that the examples are
generic and some of them may need to be tweaked to work with your setup). You
should also read the SEC man page so you have at least a basic understanding of
the SEC configuration commands.

8
sec.logrotate Normal file
View file

@ -0,0 +1,8 @@
/var/log/sec {
missingok
notifempty
sharedscripts
postrotate
[ ! -f /run/sec.pid ] || kill -USR2 `cat /run/sec.pid`
endscript
}

12
sec.service Normal file
View file

@ -0,0 +1,12 @@
[Unit]
Description=Simple Event Correlator script to filter log file entries
After=syslog.target
[Service]
Type=forking
PIDFile=/run/sec.pid
ExecStart=/usr/bin/sec --detach --pid=/run/sec.pid $OPTIONS
EnvironmentFile=/etc/sysconfig/sec
[Install]
WantedBy=multi-user.target

71
sec.spec Normal file
View file

@ -0,0 +1,71 @@
Name: sec
Version: 2.9.4
Release: 1%{?dist}
Summary: Simple Event Correlator script to filter log file entries
License: GPLv2+
URL: https://simple-evcorr.github.io/
Source0: https://github.com/simple-evcorr/sec/releases/download/%{version}/sec-%{version}.tar.gz
Source1: sec.service
Source2: sec@.service
Source3: sec.logrotate
Source4: sec.sysconfig
Source5: conf.README
BuildArch: noarch
BuildRequires: perl-generators
BuildRequires: systemd
Requires: logrotate
Requires(post): systemd
Requires(preun): systemd
Requires(postun): systemd
%description
SEC is a simple event correlation tool that reads lines from files, named
pipes, or standard input, and matches the lines with regular expressions,
Perl subroutines, and other patterns for recognizing input events.
Events are then correlated according to the rules in configuration files,
producing output events by executing user-specified shell commands, by
writing messages to pipes or files, etc.
%prep
%setup -q
%build
%install
# Install SEC and its associated files
install -D -m 0755 -p sec %{buildroot}%{_bindir}/sec
install -D -m 0644 -p sec.man %{buildroot}%{_mandir}/man1/sec.1
install -D -m 0644 -p %{SOURCE1} %{buildroot}%{_unitdir}/sec.service
install -D -m 0644 -p %{SOURCE2} %{buildroot}%{_unitdir}/sec@.service
install -D -m 0644 -p %{SOURCE3} %{buildroot}%{_sysconfdir}/logrotate.d/sec
install -D -m 0644 -p %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/sec
install -D -m 0644 -p %{SOURCE5} %{buildroot}%{_sysconfdir}/%{name}/README
# Remove executable bits because these files get packed as docs
chmod 0644 contrib/convert.pl contrib/swatch2sec.pl
%post
%systemd_post sec.service
%preun
%systemd_preun sec.service
%postun
%systemd_postun_with_restart sec.service
%files
%doc ChangeLog COPYING README contrib/convert.pl contrib/itostream.c contrib/swatch2sec.pl
%config(noreplace) %{_sysconfdir}/%{name}
%config(noreplace) %{_sysconfdir}/logrotate.d/sec
%config(noreplace) %{_sysconfdir}/sysconfig/sec
%{_bindir}/sec
%{_mandir}/man1/sec.1*
%{_unitdir}/sec.service
%{_unitdir}/sec@.service
%changelog
* Thu Feb 12 2026 Stefan Schulze Frielinghaus <stefansf@fedoraproject.org> - 2.9.4-1
- Initial EPEL 10 build

19
sec.sysconfig Normal file
View file

@ -0,0 +1,19 @@
# Command line options for SEC
OPTIONS="--conf=/etc/sec/*.sec --input=/var/log/messages --log=/var/log/sec --intevents"
# This is an example config if multiple instances of SEC should be started.
# These settings should be used together with the systemd service file
# sec@.service
# which allows to run multiple sec instances.
#
#
# Below you find an example configuration of two instances named FOO and BAR.
# The instances can be started via the commands
# systemctl start sec@FOO and systemctl start sec@BAR
# For further configuration options, consult the systemd file:
# /lib/systemd/system/sec@.service
#OPTIONS_FOO="--conf=/etc/sec/FOO/*.sec --input=/var/log/secure --log=/var/log/sec-FOO --intevents"
#OPTIONS_BAR="--conf=/etc/sec/BAR/*.sec --input=/var/log/maillog --log=/var/log/sec-BAR --intevents"

12
sec@.service Normal file
View file

@ -0,0 +1,12 @@
[Unit]
Description=Simple Event Correlator (instance %I)
After=syslog.target
[Service]
Type=forking
PIDFile=/run/sec-%I.pid
ExecStart=/usr/bin/sec --detach --pid=/run/sec-%I.pid $OPTIONS_%I
EnvironmentFile=/etc/sysconfig/sec
[Install]
WantedBy=multi-user.target

View file

@ -0,0 +1 @@
SHA512 (sec-2.9.4.tar.gz) = e049ea61e52420faddc2ad3373d9ec65cc6187d59e89537d919eb0342688e494c3d9db334347dbaf9a42260930c99756d46ed3f9f015a38bd95f6959ded047d9