Performance Spamassassin

Performance Spamassassin - réseaux et sécurité - Linux et OS Alternatifs

Marsh Posté le 12-09-2007 à 11:29:04    

Hello tous,
 
Suite au crash de mon serveur spamassassin ( http://forum.hardware.fr/forum2.ph [...] w=0&nojs=0 ) j'ai décidé de tout réinstaller proprement.
 
J'ai donc réinstallé le dernier Debian Etch sur ma machine.
installé la version de spamassassin "fourni" avec: la 3.1.7 donc.
 
J'ai configuré tout ce qu'il me fallait sans pb: bayes ... network tests etc...
 
mon architecture fait que mon serveur spam n'est pas relais SMTP, mon relais SMTP lui transmet les simplement les mails pour analyse !
 
tout fonctionne SAUF que depuis ce changement le scan time est anormalement long : entre 5 et 10s !
 
Sachant que mon relais smtp à un timeout de 5s (NON MODIFIABLE) je me retrouve avec aucun mail analysé. Dans les log de spamassassin tout va bien, seulement il scanne le mail en 6, 7 voir 8s donc mon relais n'attend pas sa réponse.
 
J'ai tout essayé:
-desactivé bayes
-desactiver les network test
-supprimer toutes mes règles
-augmenter la priorité des processus spamd ...
 
je n'arrive pas à descendre en dessous des 5s :( :(
 
Est ce que vous auriez des idées?
(surtout qu'avant il crash ca marchait très bien avec la même machine j'avais des temps d'analyse entre 1 et 4 secondes)
 
help


Message édité par Pims le 12-09-2007 à 11:29:32

---------------
Life is like a box of chocolate you never know what you gonna get.
Reply

Marsh Posté le 12-09-2007 à 11:29:04   

Reply

Marsh Posté le 12-09-2007 à 11:37:28    

5 secondes en timeout cela me parait tres court  :??:  
 
si tu ne peux pas le modifier, tu vas avoir du mal a bosser avec SA. (la marge de manoeuvre est etroite)
 
 
mais d'un autre coté 5 secondes de temps de traitement avec SA c'est beaucoup si tu dis que c'est le cas meme en ayant desactivé les regles.
 
lance un spamassassin -D --lint en console (avec le user avec lequel SA fonctionne) et montre la sortie.
 
peut etre un pb DNS, ou une erreur qqueconque qui ralentit le traitement.
 
de meme la version 3.1.7 est obsolete, peut etre qu'une maj est a envisager


Message édité par toniotonio le 12-09-2007 à 11:38:23

---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 11:53:34    

Merci pour ta réponse :)
 
Jusqu'a maintenant avec la même machine et la version 3.1.3 je n'avait aucun pb, et mes temps étaient inférieur à 5s 95% du temps.
 
sinon effectivement avec mon utilisateur "spam" il n'arrive pas à ouvrir correctement la base bayes:
 
bayes: tie-ing to DB file R/O /home/spam/.spamassassin/bayes_* R/O: tie failed: aucun fichier ou repertoire de ce type

Reply

Marsh Posté le 12-09-2007 à 11:55:13    

il faut que tu fixes ca car il pert quelques secondes sur cette erreur
 
je te conseille d'ailleurs de placer la base bayes dans une base mysql.


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 11:57:48    

oui, je suis entrain de regarder ca, les droits semblent correct pourtant...

Reply

Marsh Posté le 12-09-2007 à 11:58:47    

fait voir le lint complet aussi


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 12:12:51    

Code :
  1. spam@debian3:~$ spamassassin -D --lint
  2. [5049] dbg: logger: adding facilities: all
  3. [5049] dbg: logger: logging level is DBG
  4. [5049] dbg: generic: SpamAssassin version 3.1.7-deb
  5. [5049] dbg: config: score set 0 chosen.
  6. [5049] dbg: util: running in taint mode? yes
  7. [5049] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH
  8. [5049] dbg: util: PATH included '/usr/local/bin', keeping
  9. [5049] dbg: util: PATH included '/usr/bin', keeping
  10. [5049] dbg: util: PATH included '/bin', keeping
  11. [5049] dbg: util: PATH included '/usr/bin/X11', keeping
  12. [5049] dbg: util: PATH included '/usr/games', keeping
  13. [5049] dbg: util: final PATH set to: /usr/local/bin:/usr/bin:/bin:/usr/bin/X11:/usr/games
  14. [5049] dbg: message: ---- MIME PARSER START ----
  15. [5049] dbg: message: main message type: text/plain
  16. [5049] dbg: message: parsing normal part
  17. [5049] dbg: message: added part, type: text/plain
  18. [5049] dbg: message: ---- MIME PARSER END ----
  19. [5049] dbg: dns: is Net::DNS::Resolver available? yes
  20. [5049] dbg: dns: Net::DNS version: 0.59
  21. [5049] dbg: diag: perl platform: 5.008008 linux
  22. [5049] dbg: diag: module installed: Digest::SHA1, version 2.11
  23. [5049] dbg: diag: module installed: HTML::Parser, version 3.55
  24. [5049] dbg: diag: module installed: MIME::Base64, version 3.07
  25. [5049] dbg: diag: module installed: DB_File, version 1.814
  26. [5049] dbg: diag: module installed: Net::DNS, version 0.59
  27. [5049] dbg: diag: module installed: Net::SMTP, version 2.29
  28. [5049] dbg: diag: module not installed: Mail::SPF::Query ('require' failed)
  29. [5049] dbg: diag: module not installed: IP::Country::Fast ('require' failed)
  30. [5049] dbg: diag: module installed: Razor2::Client::Agent, version 2.81
  31. [5049] dbg: diag: module not installed: Net::Ident ('require' failed)
  32. [5049] dbg: diag: module not installed: IO::Socket::INET6 ('require' failed)
  33. [5049] dbg: diag: module not installed: IO::Socket::SSL ('require' failed)
  34. [5049] dbg: diag: module installed: Time::HiRes, version 1.86
  35. [5049] dbg: diag: module not installed: DBI ('require' failed)
  36. [5049] dbg: diag: module installed: Getopt::Long, version 2.35
  37. [5049] dbg: diag: module installed: LWP::UserAgent, version 2.033
  38. [5049] dbg: diag: module installed: HTTP::Date, version 1.47
  39. [5049] dbg: diag: module installed: Archive::Tar, version 1.30
  40. [5049] dbg: diag: module installed: IO::Zlib, version 1.04
  41. [5049] dbg: ignore: using a test message to lint rules
  42. [5049] dbg: config: using "/etc/spamassassin" for site rules pre files
  43. [5049] dbg: config: read file /etc/spamassassin/init.pre
  44. [5049] dbg: config: read file /etc/spamassassin/v310.pre
  45. [5049] dbg: config: read file /etc/spamassassin/v312.pre
  46. [5049] dbg: config: using "/usr/share/spamassassin" for sys rules pre files
  47. [5049] dbg: config: using "/usr/share/spamassassin" for default rules dir
  48. [5049] dbg: config: read file /usr/share/spamassassin/10_misc.cf
  49. [5049] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf
  50. [5049] dbg: config: read file /usr/share/spamassassin/20_anti_ratware.cf
  51. [5049] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf
  52. [5049] dbg: config: read file /usr/share/spamassassin/20_compensate.cf
  53. [5049] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf
  54. [5049] dbg: config: read file /usr/share/spamassassin/20_drugs.cf
  55. [5049] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf
  56. [5049] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf
  57. [5049] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf
  58. [5049] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf
  59. [5049] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf
  60. [5049] dbg: config: read file /usr/share/spamassassin/20_phrases.cf
  61. [5049] dbg: config: read file /usr/share/spamassassin/20_porn.cf
  62. [5049] dbg: config: read file /usr/share/spamassassin/20_ratware.cf
  63. [5049] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf
  64. [5049] dbg: config: read file /usr/share/spamassassin/23_bayes.cf
  65. [5049] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf
  66. [5049] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf
  67. [5049] dbg: config: read file /usr/share/spamassassin/25_body_tests_es.cf
  68. [5049] dbg: config: read file /usr/share/spamassassin/25_body_tests_pl.cf
  69. [5049] dbg: config: read file /usr/share/spamassassin/25_dcc.cf
  70. [5049] dbg: config: read file /usr/share/spamassassin/25_dkim.cf
  71. [5049] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf
  72. [5049] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf
  73. [5049] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf
  74. [5049] dbg: config: read file /usr/share/spamassassin/25_razor2.cf
  75. [5049] dbg: config: read file /usr/share/spamassassin/25_replace.cf
  76. [5049] dbg: config: read file /usr/share/spamassassin/25_spf.cf
  77. [5049] dbg: config: read file /usr/share/spamassassin/25_textcat.cf
  78. [5049] dbg: config: read file /usr/share/spamassassin/25_uribl.cf
  79. [5049] dbg: config: read file /usr/share/spamassassin/30_text_de.cf
  80. [5049] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf
  81. [5049] dbg: config: read file /usr/share/spamassassin/30_text_it.cf
  82. [5049] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf
  83. [5049] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf
  84. [5049] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf
  85. [5049] dbg: config: read file /usr/share/spamassassin/50_scores.cf
  86. [5049] dbg: config: read file /usr/share/spamassassin/60_awl.cf
  87. [5049] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf
  88. [5049] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf
  89. [5049] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf
  90. [5049] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf
  91. [5049] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf
  92. [5049] dbg: config: read file /usr/share/spamassassin/65_debian.cf
  93. [5049] dbg: config: using "/etc/spamassassin" for site rules dir
  94. [5049] dbg: config: read file /etc/spamassassin/local.cf
  95. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC
  96. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x83414bc)
  97. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC
  98. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::Hashcash=HASH(0x92f9ecc)
  99. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC
  100. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::SPF=HASH(0x931d054)
  101. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC
  102. [5049] dbg: pyzor: local tests only, disabling Pyzor
  103. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::Pyzor=HASH(0x93229a0)[5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC
  104. [5049] dbg: razor2: local tests only, skipping Razor
  105. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::Razor2=HASH(0x92ff064)
  106. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC
  107. [5049] dbg: reporter: local tests only, disabling SpamCop
  108. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::SpamCop=HASH(0x930192c)
  109. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC
  110. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::AWL=HASH(0x938d51c)
  111. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC
  112. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0x939b970)
  113. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC
  114. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::WhiteListSubject=HASH(0x93a7e70)
  115. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC
  116. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::MIMEHeader=HASH(0x93a8b54)
  117. [5049] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC
  118. [5049] dbg: plugin: registered Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x93ae308)
  119. [5049] dbg: config: adding redirector regex: /^http:\/\/chkpt\.zdnet\.com\/chkpt\/\w+\/(.*)$/i
  120. [5049] dbg: config: adding redirector regex: /^http:\/\/www(?:\d+)?\.nate\.com\/r\/\w+\/(.*)$/i
  121. [5049] dbg: config: adding redirector regex: /^http:\/\/.+\.gov\/(?:.*\/)?externalLink\.jhtml\?.*url=(.*?)(?:&.*)?$/i
  122. [5049] dbg: config: adding redirector regex: /^http:\/\/redir\.internet\.com\/.+?\/.+?\/(.*)$/i
  123. [5049] dbg: config: adding redirector regex: /^http:\/\/(?:.*?\.)?adtech\.de\/.*(?:;|\|)link=(.*?)(?:;|$)/i
  124. [5049] dbg: config: adding redirector regex: m'^http.*?/redirect\.php\?.*(?<=[?&])goto=(.*?)(?:$|[&#])'i
  125. [5049] dbg: config: adding redirector regex: m'^https?:/*(?:[^/]+\.)?emf\d\.com/r\.cfm.*?&r=(.*)'i
  126. [5049] dbg: config: adding redirector regex: m'/(?:index.php)?\?.*(?<=[?&])URL=(.*?)(?:$|[&#])'i
  127. [5049] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/url\?.*?(?<=[?&])q=(.*?)(?:$|[&#])'i
  128. [5049] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])site:(.*?)(?:$|%20|[\s+&#])'i
  129. [5049] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])(?:"|%22)(.*?)(?:$|%22|["\s+&#])'i
  130. [5049] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/translate\?.*?(?<=[?&])u=(.*?)(?:$|[&#])'i
  131. [5049] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x93ae308) implements 'finish_parsing_end'
  132. [5049] dbg: replacetags: replacing tags
  133. [5049] dbg: replacetags: done replacing tags
  134. [5049] dbg: bayes: tie-ing to DB file R/O /home/spam/.spamassassin/bayes_toks
  135. [5049] dbg: bayes: tie-ing to DB file R/O /home/spam/.spamassassin/bayes_seen
  136. [5049] dbg: bayes: found bayes db version 3
  137. [5049] dbg: bayes: DB journal sync: last sync: 1189585521
  138. [5049] dbg: config: score set 2 chosen.
  139. [5049] dbg: message: ---- MIME PARSER START ----
  140. [5049] dbg: message: main message type: text/plain
  141. [5049] dbg: message: parsing normal part
  142. [5049] dbg: message: added part, type: text/plain
  143. [5049] dbg: message: ---- MIME PARSER END ----
  144. [5049] dbg: dns: is DNS available? 0
  145. [5049] dbg: metadata: X-Spam-Relays-Trusted:
  146. [5049] dbg: metadata: X-Spam-Relays-Untrusted:
  147. [5049] dbg: metadata: X-Spam-Relays-Internal:
  148. [5049] dbg: metadata: X-Spam-Relays-External:
  149. [5049] dbg: message: no encoding detected
  150. [5049] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x83414bc) implements 'parsed_metadata'
  151. [5049] dbg: rules: local tests only, ignoring RBL eval
  152. [5049] dbg: check: running tests for priority: 0
  153. [5049] dbg: rules: running header regexp tests; score so far=0
  154. [5049] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<"
  155. [5049] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1189591446@lint_rules>
  156. [5049] dbg: rules: "
  157. [5049] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@lint_rules>"
  158. [5049] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1189591446"
  159. [5049] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org
  160. [5049] dbg: eval: all '*To' addrs:
  161. [5049] dbg: rules: ran eval rule NO_RELAYS ======> got hit
  162. [5049] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit
  163. [5049] dbg: rules: running body-text per-line regexp tests; score so far=-0.001
  164. [5049] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I"
  165. [5049] dbg: uri: running uri tests; score so far=-0.001
  166. [5049] dbg: bayes: DB journal sync: last sync: 1189585521
  167. [5049] dbg: bayes: corpus size: nspam = 3500, nham = 289
  168. [5049] dbg: bayes: score = 0.639943740030148
  169. [5049] dbg: bayes: DB journal sync: last sync: 1189585521
  170. [5049] dbg: bayes: untie-ing
  171. [5049] dbg: bayes: untie-ing db_toks
  172. [5049] dbg: bayes: untie-ing db_seen
  173. [5049] dbg: rules: ran eval rule BAYES_60 ======> got hit
  174. [5049] dbg: rules: running raw-body-text per-line regexp tests; score so far=0.999
  175. [5049] dbg: rules: running full-text regexp tests; score so far=0.999
  176. [5049] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x83414bc) implements 'check_tick'
  177. [5049] dbg: check: running tests for priority: 500
  178. [5049] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x83414bc) implements 'check_post_dnsbl'
  179. [5049] dbg: rules: running meta tests; score so far=0.999
  180. [5049] info: rules: meta test DIGEST_MULTIPLE has undefined dependency 'DCC_CHECK'
  181. [5049] dbg: rules: running header regexp tests; score so far=3.156
  182. [5049] dbg: rules: running body-text per-line regexp tests; score so far=3.156
  183. [5049] dbg: uri: running uri tests; score so far=3.156
  184. [5049] dbg: rules: running raw-body-text per-line regexp tests; score so far=3.156
  185. [5049] dbg: rules: running full-text regexp tests; score so far=3.156
  186. [5049] dbg: check: running tests for priority: 1000
  187. [5049] dbg: rules: running meta tests; score so far=3.156
  188. [5049] dbg: rules: running header regexp tests; score so far=3.156
  189. [5049] dbg: rules: running body-text per-line regexp tests; score so far=3.156
  190. [5049] dbg: uri: running uri tests; score so far=3.156
  191. [5049] dbg: rules: running raw-body-text per-line regexp tests; score so far=3.156
  192. [5049] dbg: rules: running full-text regexp tests; score so far=3.156
  193. [5049] dbg: check: is spam? score=3.156 required=6
  194. [5049] dbg: check: tests=BAYES_60,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS,TO_CC_NONE
  195. [5049] dbg: check: subtests=__HAS_MSGID,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__NONEMPTY_BODY,__SANE_MSGID,__UNUSABLE_MSGID

Reply

Marsh Posté le 12-09-2007 à 12:17:45    

Voilà ce que j'avais comme stats avant:
 
sam aoû 25 08:00:01 CEST 2007
 ***** Antispam stats J-1 *****  
SpamAssassin statistics for entire logfile
----------------------------------------------------------------------
 
Total messages:                Ham:       Spam:      % Spam:    
----------------------------------------------------------------------
2584                           436        2148       83.13%
 
Average spam score            : 22.59/6.00
Average ham score             : 0.34/6.00
 
Username:                      Total:  Ham:    Spam:   % Spam:
----------------------------------------------------------------------
(unknown)                      2584    436     2148    83.13%
 
Username:                      Avg. ham score:      Avg. spam score:    
----------------------------------------------------------------------
(unknown)                      0.34/6.00            22.59/6.00          
 
    *****# Script de stats complementaires du filtrage antispam #*****
Nombre de mails dans les logs de filtrage antispam : 18243
Temps moyen de filtrage par mail (log global) : 2.82194814449377843556
Temps moyen de filtrage pour aujourd'hui : 2.62761904761904761904

 
----- Stats des regles antispam -----
Erreur de date : 12%  (330)
Systeme Razor : 0%  (0)
Regles URI : 0%  (1)
Regles SARE : 0%  (0)
Regles DRUGS : 6%  (162)
 
----- Filtrage DNS et sur infos IP -----
Filtrage XBL : 16%  (431)
Filtrage NJABL : 14%  (379)
Fitrage SORBS : 27%  (707)
Regles Dynamic IP 1 : 27%  (701)
Regles Dynamic IP 2 : 9%  (252)
 
     *****--   FIN du script  --*****


Message édité par Pims le 12-09-2007 à 12:18:39
Reply

Marsh Posté le 12-09-2007 à 12:36:09    

ton pb de bayes est reglé semble t il ?
 
est ce que cela ameliore les temps de reponses ?
 
 
-ta base bayes et son journal ont quelle taille ?
-utilise tu spamd ou bien amavisd ?  
-tu as un cache DNS sur ta becane ?
-Pyzor et DCC sont til actifs dans les plugins ?
- fais voir ton local.cf et les *.pre
 
essaye de migrer vers la derniere version de SA et d'activer les compilations des rules.


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 14:03:38    

merci :)
 
Oui pour bayes ca a l'air d'aller, les droits sur les fichiers étaient bons mais pas sur le répertoire.
 
-la base bayes fait 5mo environ
-j'utilise spamd
-non pas de cache DNS
-non pas de pyzor et DCC (tu me conseilles de les mettre?)
 
Je viens de migrer vers la version 3.2.1
 
Voilà mon fichier local.cf
 
# This is the right place to customize your installation of SpamAssassin.
#
# See 'perldoc Mail::SpamAssassin::Conf' for details of what can be
# tweaked.
#
# Only a small subset of options are listed below
#
###########################################################################
 
#   Add *****SPAM***** to the Subject header of spam e-mails
#
rewrite_header Subject *****SPAM*****
 
 
#   Save spam messages as a message/rfc822 MIME attachment instead of
#   modifying the original message (0: off, 2: use text/plain instead)
#
# report_safe 1
 
 
#   Set which networks or hosts are considered 'trusted' by your mail
#   server (i.e. not spammers)
#
trusted_networks 120.0.100.150
 
 
#   Set file-locking method (flock is not safe over NFS, but is faster)
#
# lock_method flock
 
 
#   Set the threshold at which a message is considered spam (default: 5.0)
#
required_score 6.0
 
skip_rbl_checks 1
#   Use Bayesian classifier (default: 1)
#
use_bayes 1
bayes_path /home/spam/.spamassassin/bayes
bayes_file_mode 0666
bayes_use_hapaxes 1
#   Bayesian classifier auto-learning (default: 1)
#
bayes_auto_learn 1
 
 
use_razor2 1
razor_config /usr/share/spamassassin/.razor/razor-agent.conf
razor_timeout 3
 
rbl_timeout 3
dns_available yes
#check_mx_attempts 1
 
#   Set headers which may provide inappropriate cues to the Bayesian
#   classifier
#
bayes_ignore_header X-Bogosity
bayes_ignore_header X-Spam-Flag
bayes_ignore_header X-Spam-Status

Reply

Marsh Posté le 12-09-2007 à 14:03:38   

Reply

Marsh Posté le 12-09-2007 à 14:13:33    

il faut verifier dans tes fichiers *.pre les plugins activés, en particulier razor2 qui par defaut est desactivé (a verifier)
de meme desactive le dans ton local.cf:  use_razor2 0.
 
DCC et pyzor ne doivent pas etre activé car il ajoute un temps de latence non negligeable
 
 
tu devrait utiliser un cache dns.
 
verifie bien que spamd est utilisé et non spamassassin directment.
 
 
comment as tu update SA ?


Message édité par toniotonio le 12-09-2007 à 14:14:23

---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 14:20:08    

Oui pour désactiver razor en faisant un  
use_razor2 1
c'est bon.
 
Avant il était activer pourtant...
 
J'ai update SA avec un apt-get sur backports.org


Message édité par Pims le 12-09-2007 à 14:21:51
Reply

Marsh Posté le 12-09-2007 à 14:22:04    

que donne les temps de reponses maintenant ?


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 14:24:11    

c'est pareil :( tjrs plus de 5s

Reply

Marsh Posté le 12-09-2007 à 14:28:47    

desactive bayes et le awl  pour comparer les tps de reponse:  
 
use_bayes 0
use_auto_whitelist 0
 
 
puis relances spamd
 
PS: es tu bien certain que c'est spamd qui est appelé a chaque fois ?  pas d'acces direct par le binaire spamassassin ?
Comment est appelé SA dans ta boucle (postfix ?)


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 14:31:31    

Oui dans le fichier /etc/default/spamassassin
j'ai bien la ligne
ENABLED=1
 
Je vais essayer de desactiver bayes et AWL
 
Sinon je n'ai pas de postfix qui tourne dessus, mon relais SMTP soumet le mail directement à mon serveur spamassassin vie le port 783.

Reply

Marsh Posté le 12-09-2007 à 14:35:04    

C'est pareil en désactivant tout, 5.9s lors de mon dernier mail analysé... il y a vraiment un problème qqpart :(

Reply

Marsh Posté le 12-09-2007 à 14:36:16    

Sinon ma machine ne semble pas être saturée:
 
ram utilisée: 160Mo sur 1024
CPU tourne autour de 5 à 20%


Message édité par Pims le 12-09-2007 à 14:36:26
Reply

Marsh Posté le 12-09-2007 à 14:49:38    

peut etre les dns, mais tes RBL sont desactivés donc les requetes sont plutot limités...
ou bien un pb reseau...
 
essaye de voir les connections effectuées lors du traitement.


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 15:28:55    

serait ce du à la debian etch?

Reply

Marsh Posté le 12-09-2007 à 15:47:01    

il n'y a pas de pb a ma connaissance.
j'utilise des etch avec des SA sans soucis.
 
verifie bien le reseau, et les connections lors du traitement dans SA. (avec iptraf par exemple)
 
teste une requete dns en console pour voir le temps de reponse


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 16:11:29    

Bon, j'ai finalement trouvé un autre moyen: passer le timeout de mon relais smtp à 10s !
 
Cela dit ca ne me dit pas pourquoi suite à ce changement de version j'ai doublé mon temps de traitement :(

Reply

Marsh Posté le 12-09-2007 à 16:13:42    

c'est une bonne chose
mais comme tu dis il y aun pb qque part
 
essaie ce que j'ai ecrit plus haut et active le debug de spamd pour bien checker ce qu'il fait a la reception d'un mail (-D dans le init.d)


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 16:17:02    

j'ai lancé un sa-compil sans vraiment comprendre ce que je faisais, ca change quoi?
 
Sinon je vais activer le debug oui.

Reply

Marsh Posté le 12-09-2007 à 16:23:08    

cela compile les rules qui sont prévues pour, pour accelerer sensiblement le traitement
 
c'est une bonne chose a faire
 
n'oublie pas de decommenter loadplugin Mail::SpamAssassin::Plugin::Rule2XSBody  dans le v320.pre


Message édité par toniotonio le 12-09-2007 à 16:23:37

---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 16:23:35    

en activant le debug je vois ça de bizarre donc mon mail.log:
 
spamd[26744]: prefork: sysread(8) not ready, wait max 300s
 
ça me semble suspect ! non?

Reply

Marsh Posté le 12-09-2007 à 16:27:57    

tu as bcp de mail en parallele qui arrive sur SA ?


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 16:28:49    

non, que ça qui arrive sur cette machine. qq mail par minutes je dirais...


Message édité par Pims le 12-09-2007 à 16:31:33
Reply

Marsh Posté le 12-09-2007 à 16:32:42    

c'est pas forcement suspect...
d'autre messages bizarres dans le debug ?


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 12-09-2007 à 16:39:23    

ça n'a pas l'air...
 

Reply

Marsh Posté le 12-09-2007 à 16:59:02    

Je vais continuer mes recherches, en tout cas merci beaucoup pour ton aide précieux :jap:
 
Pour le moment ca semble marcher avec mes 10s de timeout...  
je trouve ce debian bien plus lent... pour récuperer les mails de spam par exemple... je me demande si le DD n'aurait pas un pb physique.

Reply

Marsh Posté le 12-09-2007 à 18:18:12    

les perfs sont à chié, y a rien à y faire, ça bouffe trop de CPU. Tu te retrouve toujours sur des temps de traitement de l'ordre de la seconde ...

Reply

Marsh Posté le 13-09-2007 à 08:37:07    

Oui si tu veux, seulement ca n'explique pas pourquoi avec le même matériel je suis passé d'un temps moyen de 2.5s à 7.5s...

Reply

Marsh Posté le 13-09-2007 à 10:14:00    

Autre question: est ce que ca vaut le coup d'augmenter un peu la priorité des processus spamd?

Reply

Marsh Posté le 13-09-2007 à 10:20:17    

pour ce que tu disais que tu recois comme volume de mail, ce n'est pas cela le pb.
 
a moins que le serveru ne soit assigné a d'autres taches.
 
il faudrait que tu verifies ce que je disais plus haut lors du traitement sur le reseau, ainsi que la charge cpu a ce moment.
 
quelles sont les caracteristiques de la machine ?
le temps de traitement est il superieur a 5 secondes avec tous les emails, meme par exemple ce ne contenant qu'une ligne de texte brut ?


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 13-09-2007 à 11:05:39    

La machine n'est pas un foudre de guerre.
 
P4 2.4Ghz
1Go de Ram
 
Elle ne fait rien d'autre.
 
La charge CPU monte entre 20 et 60% à chaque mail reçu.
Le traffic réseau passe à qq ko/s au moment des transferts.
180Mo de Ram sont utilisés
 
Sinon oui TOUTES les analyses dépassent les 5s.
 
Voilà mes stats depuis hier:
 
jeudi 13 septembre 2007, 09:03:01 (UTC+0200)
 ***** Antispam stats J-1 *****  
SpamAssassin statistics for entire logfile
----------------------------------------------------------------------
 
Total messages:                Ham:       Spam:      % Spam:    
----------------------------------------------------------------------
1456                           566        890        61.13%
 
Average spam score            : 19.11/6.00
Average ham score             : 1.25/6.00
 
Username:                      Total:  Ham:    Spam:   % Spam:
----------------------------------------------------------------------
(unknown)                      1456    566     890     61.13%
 
Username:                      Avg. ham score:      Avg. spam score:    
----------------------------------------------------------------------
(unknown)                      1.25/6.00            19.11/6.00          
 
    *****# Script de stats complementaires du filtrage antispam #*****
Nombre de mails dans les logs de filtrage antispam : 1579
Temps moyen de filtrage par mail (log global) : 6.61405953134895503483
Temps moyen de filtrage pour aujourd'hui : 6.11300813008130081300
 
----- Stats des regles antispam -----
Erreur de date : 16%  (237)
Systeme Razor : 41%  (605)
Regles URI : 0%  (1)
Regles SARE : 0%  (0)
Regles DRUGS : 12%  (182)
 
----- Filtrage DNS et sur infos IP -----
Filtrage XBL : 1%  (26)
Filtrage NJABL : 2%  (34)
Fitrage SORBS : 1%  (28)
Regles Dynamic IP 1 : 13%  (200)
Regles Dynamic IP 2 : 6%  (96)


Message édité par Pims le 13-09-2007 à 11:06:10
Reply

Marsh Posté le 13-09-2007 à 11:09:50    

que donne un top lors du traitement ?
 
de meme essaye d'utiliser  iptraf pour voir les connections lors du traitement. essaie de reperer des requetes DNS.
 
la machine est largement assez puissante pour traiter un mail simple en moins de 2 secondes.
 
et poste le debug de spamd sur le traitement d'un message


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le 13-09-2007 à 11:42:31    

Je vois bien des requetes DNS à distination d'un de mes serveurs internes dans le IP traf.
 
Sinon voilà le traitement d'un message en 6s:
 
Sep 13 11:27:16 localhost spamd[7053]: spamd: connection from 120.0.100.150 [120.0.100.150] at port 44841  
Sep 13 11:27:16 localhost spamd[7053]: spamd: running as uid 1000  
Sep 13 11:27:16 localhost spamd[7053]: message: main message type: multipart/alternative  
Sep 13 11:27:16 localhost spamd[7053]: spamd: processing message <534546071@prod-mail.cabestan.com> for (unknown):1000  
Sep 13 11:27:16 localhost spamd[7053]: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually  
Sep 13 11:27:16 localhost spamd[7053]: received-header: parsed as [ ip=213.41.75.84 rdns= helo=prod-mail.cabestan.com by=arkoon.maboite.fr ident= envfrom= intl=0 id=smtpdGXAiWD auth= msa=0 ]  
Sep 13 11:27:16 localhost spamd[7053]: received-header: do not trust any hosts from here on  
Sep 13 11:27:16 localhost spamd[7053]: received-header: relay 213.41.75.84 trusted? no internal? no msa? no  
Sep 13 11:27:16 localhost spamd[7053]: metadata: X-Spam-Relays-Trusted:  
Sep 13 11:27:16 localhost spamd[7053]: metadata: X-Spam-Relays-Untrusted: [ ip=213.41.75.84 rdns= helo=prod-mail.cabestan.com by=arkoon.maboite.fr ident= envfrom= intl=0 id=smtpdGXAiWD auth= msa=0 ]  
Sep 13 11:27:16 localhost spamd[7053]: metadata: X-Spam-Relays-Internal:  
Sep 13 11:27:16 localhost spamd[7053]: metadata: X-Spam-Relays-External: [ ip=213.41.75.84 rdns= helo=prod-mail.cabestan.com by=arkoon.maboite.fr ident= envfrom= intl=0 id=smtpdGXAiWD auth= msa=0 ]  
Sep 13 11:27:16 localhost spamd[7053]: message: ---- MIME PARSER START ----  
Sep 13 11:27:16 localhost spamd[7053]: message: parsing multipart, got boundary: ----=_Boundary__13092007_111345  
Sep 13 11:27:16 localhost spamd[7053]: message: found part of type text/plain, boundary: ----=_Boundary__13092007_111345  
Sep 13 11:27:16 localhost spamd[7053]: message: added part, type: text/plain  
Sep 13 11:27:16 localhost spamd[7053]: message: found part of type text/html, boundary: ----=_Boundary__13092007_111345  
Sep 13 11:27:16 localhost spamd[7053]: message: added part, type: text/html  
Sep 13 11:27:16 localhost spamd[7053]: message: parsing normal part  
Sep 13 11:27:16 localhost spamd[7053]: message: parsing normal part  
Sep 13 11:27:16 localhost spamd[7053]: message: ---- MIME PARSER END ----  
Sep 13 11:27:16 localhost spamd[7053]: message: decoding quoted-printable  
Sep 13 11:27:16 localhost spamd[7053]: message: decoding quoted-printable  
Sep 13 11:27:16 localhost spamd[7053]: uridnsbl: domains to query: cabestan.com  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_GREY lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_SECUREWHOIS lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_MYPRIVREG lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_NETSOLPR lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_AITPRIV lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_FINEXE lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_CONTACTPRIV lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_BLACK lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_REGISTER4LESS lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_NETID lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_DYNADOT lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_OB_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_DMNBYPROXY lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_MONIKER_PRIV lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_PRIVDOMAIN lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_DREAMPRIV lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_RED lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_SC_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_AB_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_WHOISGUARD lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_PRIVPROT lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_NAMEKING lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_PH_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_DOMPRIVCORP lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_PRIVACYPOST lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_RHS_DOB lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_DOMESCROW lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_WHOISPROT lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_JP_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_REGTEK lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_SAFENAMES lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_WS_SURBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_NOMINET lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_REGISTERFLY lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: WHOIS_UNLISTED lookup start  
Sep 13 11:27:16 localhost spamd[7053]: dns: URIBL_SBL lookup start  
Sep 13 11:27:16 localhost spamd[7053]: check: running tests for priority: -1000  
Sep 13 11:27:16 localhost spamd[7053]: rules: running head tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: eval: all '*From' addrs: peter.wildhorn@ipwgroup.eu  
Sep 13 11:27:16 localhost spamd[7053]: eval: all '*To' addrs: jacques.michaux@maboite.fr  
Sep 13 11:27:16 localhost spamd[7053]: rules: running body tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running uri tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running rawbody tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running full tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running meta tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: check: running tests for priority: -950  
Sep 13 11:27:16 localhost spamd[7053]: rules: running head tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running body tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running uri tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running rawbody tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running full tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running meta tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: check: running tests for priority: -900  
Sep 13 11:27:16 localhost spamd[7053]: rules: running head tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running body tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running uri tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running rawbody tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running full tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running meta tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: check: running tests for priority: -400  
Sep 13 11:27:16 localhost spamd[7053]: rules: running head tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running body tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running uri tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: bayes: tie-ing to DB file R/O /home/spam/.spamassassin/bayes_toks  
Sep 13 11:27:16 localhost spamd[7053]: bayes: tie-ing to DB file R/O /home/spam/.spamassassin/bayes_seen  
Sep 13 11:27:16 localhost spamd[7053]: bayes: found bayes db version 3  
Sep 13 11:27:16 localhost spamd[7053]: bayes: DB journal sync: last sync: 1189675146  
Sep 13 11:27:16 localhost spamd[7053]: bayes: corpus size: nspam = 9471, nham = 298  
Sep 13 11:27:16 localhost spamd[7053]: bayes: score = 0.500000000112844  
Sep 13 11:27:16 localhost spamd[7053]: bayes: DB journal sync: last sync: 1189675146  
Sep 13 11:27:16 localhost spamd[7053]: bayes: DB expiry: tokens in DB: 133903, Expiry max size: 150000, Oldest atime: 1178565756, Newest atime: 1189675383, Last expire: 1189621407, Current time: 1189675636  
Sep 13 11:27:16 localhost spamd[7053]: bayes: untie-ing  
Sep 13 11:27:16 localhost spamd[7053]: rules: running rawbody tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running full tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running meta tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: check: running tests for priority: 0  
Sep 13 11:27:16 localhost spamd[7053]: rules: running head tests; score so far=0  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __CTYPE_MULTIPART_ALT ======> got hit: "multipart/alternative"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __CTYPE_HAS_BOUNDARY ======> got hit: "boundary"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __CT ======> got hit: "m"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule RDNS_NONE ======> got hit: "[ ip=213.41.75.84 rdns= "  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __LAST_UNTRUSTED_RELAY_NO_AUTH ======> got hit: "[ ip=213.41.75.84 rdns= helo=prod-mail.cabestan.com by=arkoon.maboite.fr ident= envfrom= intl=0 id=smtpdGXAiWD auth= "  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __DOS_SINGLE_EXT_RELAY ======> got hit: "[ ip=213.41.75.84 rdns= helo=prod-mail.cabestan.com by=arkoon.maboite.fr ident= envfrom= intl=0 id=smtpdGXAiWD auth= msa=0 ]"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __MISSING_REF ======> got hit: "UNSET"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __NAKED_TO ======> got hit: "jacques.michaux@maboite.fr"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __MIME_VERSION ======> got hit: "1"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __HAS_RCVD ======> got hit: "f"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __DOS_RCVD_THU ======> got hit: " Thu, "  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __TOCC_EXISTS ======> got hit: "j"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@prod-mail.cabestan.com>"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __MSOE_MID_WRONG_CASE ======> got hit: "  
Sep 13 11:27:16 localhost spamd[7053]: rules: Message-Id: "  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __HAS_MSGID ======> got hit: "<"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __SANE_MSGID ======> got hit: "<60pt8g$ftp1kn@ironport-1.cabestan-local.com>  
Sep 13 11:27:16 localhost spamd[7053]: rules: "  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran header rule __HAS_SUBJECT ======> got hit: "A"  
Sep 13 11:27:16 localhost spamd[7053]: spf: checking to see if the message has a Received-SPF header that we can use  
Sep 13 11:27:16 localhost spamd[7053]: spf: already checked for Received-SPF headers, proceeding with DNS based checks  
Sep 13 11:27:16 localhost last message repeated 3 times
Sep 13 11:27:16 localhost spamd[7053]: spf: cannot get Envelope-From, cannot use SPF  
Sep 13 11:27:16 localhost spamd[7053]: spf: def_spf_whitelist_from: could not find useable envelope sender  
Sep 13 11:27:16 localhost spamd[7053]: spf: already checked for Received-SPF headers, proceeding with DNS based checks  
Sep 13 11:27:16 localhost last message repeated 2 times
Sep 13 11:27:16 localhost spamd[7053]: spf: spf_whitelist_from: could not find useable envelope sender  
Sep 13 11:27:16 localhost spamd[7053]: rules: running body tests; score so far=0.1  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran body rule __MBA ======> got hit: "MBA"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran body rule __DOS_BODY_MON ======> got hit: "mon"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran body rule __HAS_ANY_EMAIL ======> got hit: "n@ipwgroup.e"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran body rule __FB_MBA ======> got hit: "MBA"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran body rule __NONEMPTY_BODY ======> got hit: "A"  
Sep 13 11:27:16 localhost spamd[7053]: rules: running uri tests; score so far=0.1  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran uri rule __DOS_HAS_ANY_URI ======> got hit: "h"  
Sep 13 11:27:16 localhost spamd[7053]: https_http_mismatch: anchors 9  
Sep 13 11:27:16 localhost spamd[7053]: eval: stock info total: 0  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __TAG_EXISTS_BODY ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: eval: text words: 203, html words: 30  
Sep 13 11:27:16 localhost spamd[7053]: eval: madiff: left: 15, orig: 30, max-difference: 50.00%  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule MPART_ALT_DIFF_COUNT ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule HTML_IMAGE_RATIO_02 ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __MIME_HTML ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __HTML_TITLE_SUBJ_DIFF ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule HTML_MESSAGE ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __TAG_EXISTS_HTML ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: relay UNKNOWN(213.41.75.84), doesn't match any whitelist  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule BAYES_50 ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __TVD_MIME_ATT_TP ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __HTML_LINK_IMAGE ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __TAG_EXISTS_HEAD ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __TAG_EXISTS_META ======> got hit (1)  
Sep 13 11:27:16 localhost spamd[7053]: rules: running rawbody tests; score so far=1.595  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran rawbody rule __TVD_BODY ======> got hit: "GROU"  
Sep 13 11:27:16 localhost spamd[7053]: rules: ran eval rule __MIME_QP ======> got hit (2)  
Sep 13 11:27:16 localhost spamd[7053]: rules: running full tests; score so far=1.595  
Sep 13 11:27:16 localhost spamd[7053]: info: entering helper-app run mode  
Sep 13 11:27:17 localhost spamd[7053]: info: leaving helper-app run mode  
Sep 13 11:27:17 localhost spamd[7053]: razor2: part=0 engine=4 contested=0 confidence=0  
Sep 13 11:27:17 localhost spamd[7053]: razor2: part=1 engine=4 contested=1 confidence=0  
Sep 13 11:27:17 localhost spamd[7053]: razor2: part=1 engine=8 contested=0 confidence=0  
Sep 13 11:27:17 localhost spamd[7053]: razor2: results: spam? 0  
Sep 13 11:27:17 localhost spamd[7053]: razor2: results: engine 8, highest cf score: 0  
Sep 13 11:27:17 localhost spamd[7053]: razor2: results: engine 4, highest cf score: 0  
Sep 13 11:27:17 localhost spamd[7053]: pyzor: pyzor is not available: no pyzor executable found  
Sep 13 11:27:17 localhost spamd[7053]: pyzor: no pyzor found, disabling Pyzor  
Sep 13 11:27:17 localhost spamd[7053]: rules: running meta tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: check: running tests for priority: 500  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (multi.uribl.com.:cabestan.com)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-DNSBL=3 URI-NS=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (multi.surbl.org.:cabestan.com)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-DNSBL=2 URI-NS=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 2  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-DNSBL=2 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (dob.sibl.support-intelligence.net:cabestan.com)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-A=2 URI-DNSBL=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (bl.open-whois.org.:cabestan.com)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-A=2 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 1  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-A=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 1  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-DNSBL=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (sbl.spamhaus.org.:70.75.41.213)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: URI-DNSBL=1 at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: async: select found 1 socks ready  
Sep 13 11:27:17 localhost spamd[7053]: uridnsbl: query for cabestan.com took 1 seconds to look up (sbl.spamhaus.org.:71.75.41.213)  
Sep 13 11:27:17 localhost spamd[7053]: async: queries completed: 1 started: 0  
Sep 13 11:27:17 localhost spamd[7053]: async: queries active: at Thu Sep 13 11:27:17 2007  
Sep 13 11:27:17 localhost spamd[7053]: dns: success for 4 of 5 queries  
Sep 13 11:27:17 localhost spamd[7053]: rules: running head tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: rules: running body tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: rules: running uri tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: rules: running rawbody tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: rules: running full tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: rules: running meta tests; score so far=1.595  
Sep 13 11:27:17 localhost spamd[7053]: check: running tests for priority: 1000  
Sep 13 11:27:17 localhost spamd[7053]: rules: running head tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: config: using "/home/spam/.spamassassin" for user state dir  
Sep 13 11:27:17 localhost spamd[7053]: locker: safe_lock: created /home/spam/.spamassassin/auto-whitelist.lock.debian3.maboite.fr.7053  
Sep 13 11:27:17 localhost spamd[7053]: locker: safe_lock: trying to get lock on /home/spam/.spamassassin/auto-whitelist with 0 retries  
Sep 13 11:27:17 localhost spamd[7053]: locker: safe_lock: link to /home/spam/.spamassassin/auto-whitelist.lock: link ok  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: tie-ing to DB file of type DB_File R/W in /home/spam/.spamassassin/auto-whitelist  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: db-based peter.wildhorn@ipwgroup.eu|ip=213.41 scores 0/0  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: db-based peter.wildhorn@ipwgroup.eu|ip=none scores 0/0  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: AWL active, pre-score: 2.812, autolearn score: 2.812, mean: undef, IP: 213.41.75.84  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: add_score: new count: 1, new totscore: 2.812  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: DB addr list: untie-ing and unlocking  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: DB addr list: file locked, breaking lock  
Sep 13 11:27:17 localhost spamd[7053]: locker: safe_unlock: unlink /home/spam/.spamassassin/auto-whitelist.lock  
Sep 13 11:27:17 localhost spamd[7053]: auto-whitelist: post auto-whitelist score: 2.812  
Sep 13 11:27:17 localhost spamd[7053]: rules: running body tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: rules: running uri tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: rules: running rawbody tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: rules: running full tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: rules: running meta tests; score so far=2.812  
Sep 13 11:27:17 localhost spamd[7053]: learn: auto-learn: currently using scoreset 3, recomputing score based on scoreset 1  
Sep 13 11:27:17 localhost spamd[7053]: learn: auto-learn: message score: 2.812, computed score for autolearn: 3.338  
Sep 13 11:27:17 localhost spamd[7053]: learn: auto-learn? ham=0.1, spam=12, body-points=3.338, head-points=3.338, learned-points=0.001  
Sep 13 11:27:17 localhost spamd[7053]: learn: auto-learn? no: inside auto-learn thresholds, not considered ham or spam  
Sep 13 11:27:17 localhost spamd[7053]: check: is spam? score=2.812 required=6  
Sep 13 11:27:17 localhost spamd[7053]: check: tests=BAYES_50,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_TITLE_SUBJ_DIFF,MPART_ALT_DIFF_COUNT,RDNS_NONE  
Sep 13 11:27:17 localhost spamd[7053]: check: subtests=__CT,__CTYPE_HAS_BOUNDARY,__CTYPE_MULTIPART_ALT,__DOS_BODY_MON,__DOS_HAS_ANY_URI,__DOS_RCVD_THU,__DOS_REF_2_WK_DAYS,__DOS_SINGLE_EXT_RELAY,__FB_MBA,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_MSGID,__HAS_RCVD,__HAS_SUBJECT,__HTML_LINK_IMAGE,__HTML_TITLE_SUBJ_DIFF,__LAST_UNTRUSTED_RELAY_NO_AUTH,__MBA,__MIME_HTML,__MIME_QP,__MIME_VERSION,__MISSING_REF,__MSGID_OK_HOST,__MSOE_MID_WRONG_CASE,__NAKED_TO,__NONEMPTY_BODY,__SANE_MSGID,__TAG_EXISTS_BODY,__TAG_EXISTS_HEAD,__TAG_EXISTS_HTML,__TAG_EXISTS_META,__TOCC_EXISTS,__TVD_BODY,__TVD_MIME_ATT_TP  
Sep 13 11:27:17 localhost spamd[7053]: spamd: clean message (2.8/6.0) for (unknown):1000 in 6.0 seconds, 9169 bytes.  
Sep 13 11:27:17 localhost spamd[7053]: spamd: result: . 2 - BAYES_50,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_TITLE_SUBJ_DIFF,MPART_ALT_DIFF_COUNT,RDNS_NONE scantime=6.0,size=9169,user=(unknown),uid=1000,required_score=6.0,rhost=120.0.100.150,raddr=120.0.100.150,rport=44841,mid=<534546071@prod-mail.cabestan.com>,bayes=0.500000,autolearn=no  
Sep 13 11:27:17 localhost spamd[7053]: config: copying current conf from backup  
Sep 13 11:27:17 localhost spamd[7052]: prefork: child 7053: entering state 1  
Sep 13 11:27:17 localhost spamd[7053]: prefork: periodic ping from spamd parent  
Sep 13 11:27:17 localhost spamd[7052]: prefork: new lowest idle kid: 7053  
Sep 13 11:27:17 localhost spamd[7053]: prefork: sysread(8) not ready, wait max 300 secs  
Sep 13 11:27:17 localhost spamd[7052]: prefork: child reports idle  
Sep 13 11:27:17 localhost spamd[7052]: prefork: child states: IB


Message édité par Pims le 13-09-2007 à 12:25:39
Reply

Marsh Posté le 13-09-2007 à 11:44:24    

Il y a qqch de très bizarre:
 
D'après les heures dans les traces le message semble avoir été traité en 3 secondes mais il indique 6s
 
En tout cas dans les faits c'est bien 6s car si j'ai un timeout de 5s sur mon relais smtp ca ne passe pas.

Reply

Marsh Posté le 13-09-2007 à 11:53:03    

installe un cache dns sur ta becane en local et refait le test


---------------
Messagerie dédiée, Relais Mail Antispam/Antivirus, Infogérance 24/7: http://www.eole-its.com
Reply

Marsh Posté le    

Reply

Sujets relatifs:

Leave a Replay

Make sure you enter the(*)required information where indicate.HTML code is not allowed