Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Sarg package for pfsense

    Scheduled Pinned Locked Moved pfSense Packages
    467 Posts 99 Posters 563.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DonnyD
      Donny
      last edited by

      Donny, did you tried to save config after package update?
      
      the code has the correct folder but maybe the default config file of sarg 2.3.2 has /var/log/squid/access.log
      

      Hallo Marcelloc

      First, I have clean install Squid3 and configured, then I click save and I got squid proxy error fatal the line 1378 or 1387 (I am not sure which number) on Chrome web browser and I also not sure which file name "Squid.conf" or "Squid_reverse.inf")
      Second, I have clean install SARG last version and configured in General tab, User tab and  Schedule tab, then save. When I click update button at Real time report, no real time report appear at all.
      I also try to reboot pfsense many time after config Squid3 and SARG but the Real time report still not appear.
      Anyway I will try to clean install pfSense and Squid3 and SARG again later.

      Thank you
      Donny

      1 Reply Last reply Reply Quote 0
      • marcellocM
        marcelloc
        last edited by

        @Donny:

        Anyway I will try to clean install pfSense and Squid3 and SARG again later.

        Try sarg just after you get squid up and running.

        I'll check this squid3 first run error as soon as possible.

        att,
        Marcello Coutinho

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • DonnyD
          Donny
          last edited by

          @marcelloc:

          @Donny:

          Anyway I will try to clean install pfSense and Squid3 and SARG again later.

          Try sarg just after you get squid up and running.

          I'll check this squid3 first run error as soon as possible.

          att,
          Marcello Coutinho

          Hello Marcelloc

          I will do and test it in this evening. I will make some screenshot also for some error.

          Donny

          1 Reply Last reply Reply Quote 0
          • DonnyD
            Donny
            last edited by

            Hello Marcelloc

            I just clean install pfSense and basic configured. After that I have installed Squid3 last version.
            In the Squid "general tab" I just only use some default setting. I enable "Enable logging and log rotate" and also changed the language to "en". So I click save.

            I got fatal error on Chrome web browser like this:

            "Fatal error: Cannot use string offset as an array in /usr/local/pkg/squid.inc on line 1378"

            and at this point I enter Chrome web browser again I got: "Error: No packege defined".

            then I enter pfSense Lan IP and went back to Squid general tab but not things save (Enable logging and log rotate and language "en"). I saw on dashboard that Squid is not running  and then
            I tried to configure squid on general tab again and the click save but at this time I don't get any fatal error.

            I also checked at system log file and I saw some error like this:

            php: /pkg_edit.php: The command '/usr/local/sbin/squid -k kill' returned exit code '1', the output was 'squid: ERROR: No running copy'

            So you can see my screenshot.
            I did not install SARG yet. Just only clean install pfsense and squid3

            Thank u

            Donny

            ![Squid fatal error.png](/public/imported_attachments/1/Squid fatal error.png)
            ![Squid fatal error.png_thumb](/public/imported_attachments/1/Squid fatal error.png_thumb)
            ![Squid Error No package defined.png](/public/imported_attachments/1/Squid Error No package defined.png)
            ![Squid Error No package defined.png_thumb](/public/imported_attachments/1/Squid Error No package defined.png_thumb)
            ![Squid syslog file.png](/public/imported_attachments/1/Squid syslog file.png)
            ![Squid syslog file.png_thumb](/public/imported_attachments/1/Squid syslog file.png_thumb)

            1 Reply Last reply Reply Quote 0
            • marcellocM
              marcelloc
              last edited by

              Donny,

              I've pushed a fix to this issue with no version change, on my tests it's working fine now.

              wait 15 minutes, reinstall the package and try to configure it again.

              att,
              Marcello Coutinho

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • DonnyD
                Donny
                last edited by

                @marcelloc:

                Donny,

                I've pushed a fix to this issue with no version change, on my tests it's working fine now.

                wait 15 minutes, reinstall the package and try to configure it again.

                att,
                Marcello Coutinho

                Ok, I will try after 30 minutes.

                1 Reply Last reply Reply Quote 0
                • DonnyD
                  Donny
                  last edited by

                  I just clean install pfSense and basic configured. After that I have installed Squid3 last version. 
                  In the Squid "general tab" I just only use some default setting. I enable "Enable logging and log rotate" and also changed the language to "en". So I click save.
                  
                  I got fatal error on Chrome web browser like this:
                  
                  "Fatal error: Cannot use string offset as an array in /usr/local/pkg/squid.inc on line 1378"
                  
                  and at this point I enter Chrome web browser again I got: "Error: No packege defined".
                  
                  then I enter pfSense Lan IP and went back to Squid general tab but not things save (Enable logging and log rotate and language "en"). I saw on dashboard that Squid is not running  and then 
                  I tried to configure squid on general tab again and the click save but at this time I don't get any fatal error.
                  
                  I also checked at system log file and I saw some error like this:
                  
                  php: /pkg_edit.php: The command '/usr/local/sbin/squid -k kill' returned exit code '1', the output was 'squid: ERROR: No running copy'
                  
                  So you can see my screenshot.
                  I did not install SARG yet. Just only clean install pfsense and squid3
                  

                  Hello Marcello,

                  I just tried it and I got the same fatal error and the same result that I explain before.

                  This is second time to clean install pfSense and Squid. I did not try to reinstall squid package because I want to be sure that squid work without error.

                  Now in Holland is almost 1 AM in the morning, I am going to bed now.

                  Donny

                  1 Reply Last reply Reply Quote 0
                  • marcellocM
                    marcelloc
                    last edited by

                    I'll try to reproduce this error.

                    Try to refresh the page with f5 and save again.

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • K
                      klamath
                      last edited by

                      Hi marcelloc

                      looks like sarg can't handle large entries on file /var/squidGuard/log/block.log

                      I don't want erase the file /var/squidGuard/log/block.log, could u help me?

                      php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 27976, reading: 0.00%^MSARG: Records in file: 5000, reading: 17.87%^MSARG: Records in file: 10000, reading: 35.74%^MSARG: Records in file: 15000, reading: 53.62%^MSARG: Records in file: 20000, reading: 71.49%^MSARG: Records in file: 25000, reading: 89.36%^MSARG: Hour string too long in redirector log file /var/squidGuard/log/block.log SARG: Records in file: 27976, reading: 100.00%'

                      HP ProLiant MicroServer N40L - 2GB - 250G HD - 3 NIC Intel PRO/1000 MT Gigabit PCI
                      pfSense 2.0.1-RELEASE (amd64)

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        @klamath:

                        looks like sarg can't handle large entries on file /var/squidGuard/log/block.log
                        I don't want erase the file /var/squidGuard/log/block.log, could u help me?

                        try to split this log or use sarg args to limit log search.

                        @klamath:

                        Hour string too long in redirector log file /var/squidGuard/log/block.log SARG: Records in file: 27976, reading: 100.00%'

                        I understand this error as some format error on log file/line not a too many records errors.

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • K
                          klamath
                          last edited by

                          Thanks!

                          I've set the User_report_limit to 300 and rotate squidguard block log…

                          It's work for a while... than stopped sudenly again!

                          php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 86169, reading: 0.00%^MSARG: Records in file: 5000, reading: 5.80%^MSARG: Records in file: 10000, reading: 11.61%^MSARG: Records in file: 15000, reading: 17.41%^MSARG: Records in file: 20000, reading: 23.21%^MSARG: Records in file: 25000, reading: 29.01%^MSARG: Records in file: 30000, reading: 34.82%^MSARG: Records in file: 35000, reading: 40.62%^MSARG: Records in file: 40000, reading: 46.42%^MSARG: Records in file: 45000, reading: 52.22%^MSARG: Records in file: 50000, reading: 58.03%^MSARG: Records in file: 55000, reading: 63.83%^MSARG: Records in file: 60000, reading: 69.63%^MSARG: Records in file: 65000, reading: 75.43%^MSARG: Records in file: 70000, reading: 81.24%^MSARG: Records in file: 75000, reading: 87.04%^MSARG: Records in file: 80000, reading: 92.84%^MSARG: Records in file: 85000, reading: 98.64%^MSARG: Successful report generated on /usr/local/sarg-reports/29May2

                          HP ProLiant MicroServer N40L - 2GB - 250G HD - 3 NIC Intel PRO/1000 MT Gigabit PCI
                          pfSense 2.0.1-RELEASE (amd64)

                          1 Reply Last reply Reply Quote 0
                          • E
                            expert_az
                            last edited by

                            i did conf like you,http://forum.pfsense.org/index.php/topic,47765.165.html
                            its ok now ,thank you for great job

                            hello marcelloc,i got this error while testing sarg with  squid and squidguard,and can't see reports on view report tab

                            Error: Could not find report index file.
                            Check and save sarg settings and try to force sarg schedule.

                            php: : The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 72216, reading: 0.00%^MSARG: Records in file: 5000, reading: 6.92%^MSARG: Records in file: 10000, reading: 13.85%^MSARG: Records in file: 15000, reading: 20.77%^MSARG: Records in file: 20000, reading: 27.69%^MSARG: Records in file: 25000, reading: 34.62%^MSARG: Records in file: 30000, reading: 41.54%^MSARG: Records in file: 35000, reading: 48.47%^MSARG: Records in file: 40000, reading: 55.39%^MSARG: Records in file: 45000, reading: 62.31%^MSARG: Records in file: 50000, reading: 69.24%^MSARG: Records in file: 55000, reading: 76.16%^MSARG: Records in file: 60000, reading: 83.08%^MSARG: Records in file: 65000, reading: 90.01%^MSARG: Records in file: 70000, reading: 96.93%^MSARG: Cannot delete /usr/local/sarg-reports/2012/06/12/debakim.html - No such file or directory SARG: Records in file: 72216, reading: 100.00%'

                            1 Reply Last reply Reply Quote 0
                            • F
                              Fesoj
                              last edited by

                              Is Sarg currently broken?

                              I am running Sarg on Squid2 logs, kept the default Report Options, selected all entries in Report to generate, and set up an hourly schedule.

                              After forcing the update, the View Report gives me:

                              Error: Could not find report index file.
                              Check and save sarg settings and try to force sarg schedule.

                              {$dir}/{$url} in sarg_frame-php contains /usr/local/sarg-reports/index.html, which does not exist, but report files have been generated under /usr/local/sarg-reports/2012/07/26 which mirrors today's date.

                              Any suggestions what to do?

                              1 Reply Last reply Reply Quote 0
                              • marcellocM
                                marcelloc
                                last edited by

                                @Fesoj:

                                Is Sarg currently broken?

                                No, I have 6 working with latest version

                                @Fesoj:

                                {$dir}/{$url} in sarg_frame-php contains /usr/local/sarg-reports/index.html, which does not exist, but report files have been generated under /usr/local/sarg-reports/2012/07/26 which mirrors today's date.

                                Any suggestions what to do?

                                Did you selected "Generate the main index.html" option on gui?

                                I've attached a screenshot with my current setup.

                                sarg_general.png
                                sarg_general.png_thumb

                                Treinamentos de Elite: http://sys-squad.com

                                Help a community developer! ;D

                                1 Reply Last reply Reply Quote 0
                                • F
                                  Fesoj
                                  last edited by

                                  Did you selected "Generate the main index.html" option on gui?

                                  No, I didn't. Now that I did it, it is working.

                                  Thanx.

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    AudiAddict
                                    last edited by

                                    Can somebody explain if I need to set up log rotation in the schedule or not? And how this works?

                                    I have it set to default ( do nothing) in SAR and have my squid settings set to 186 days log rotation (aprox 6 months).

                                    Do I need to use the log rotation of SARG as wel? What does it do exactly? Clean up my old logs?

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      @AudiAddict:

                                      Do I need to use the log rotation of SARG as wel?

                                      No, just one log rotate is fine.

                                      @AudiAddict:

                                      What does it do exactly? Clean up my old logs?

                                      Rotate logs and keep last 10 rotated files.(access.log.0 access.log.1 access.log.2…)

                                      att,
                                      Marcello Coutinho

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • A
                                        AudiAddict
                                        last edited by

                                        Thanks for your reply.

                                        Does it mean that it reads through the whole file everytime? So If I have it set to rotate in squid settings every 6 months will this cause it to be slow at generating the report?

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          @AudiAddict:

                                          Thanks for your reply.

                                          Does it mean that it reads through the whole file everytime? So If I have it set to rotate in squid settings every 6 months will this cause it to be slow at generating the report?

                                          Yes, you can use date arg in schedules, but sarg will read all file the same way looking for logs on that date range.

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • A
                                            AudiAddict
                                            last edited by

                                            If I change the rotation to 1 month in squid settings? Will it "save" my old logs in SARG? So I can view the internet logs older than one month?

                                            So.. if I set squid to rotate every 30 days, does SARG delete the old data? Or does it display the old logs (from the last months) even though they have been rotated? (renamed?)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.