Sarg package for pfsense
-
Anyway I will try to clean install pfSense and Squid3 and SARG again later.
Try sarg just after you get squid up and running.
I'll check this squid3 first run error as soon as possible.
att,
Marcello CoutinhoHello Marcelloc
I will do and test it in this evening. I will make some screenshot also for some error.
Donny
-
Hello Marcelloc
I just clean install pfSense and basic configured. After that I have installed Squid3 last version.
In the Squid "general tab" I just only use some default setting. I enable "Enable logging and log rotate" and also changed the language to "en". So I click save.I got fatal error on Chrome web browser like this:
"Fatal error: Cannot use string offset as an array in /usr/local/pkg/squid.inc on line 1378"
and at this point I enter Chrome web browser again I got: "Error: No packege defined".
then I enter pfSense Lan IP and went back to Squid general tab but not things save (Enable logging and log rotate and language "en"). I saw on dashboard that Squid is not running and then
I tried to configure squid on general tab again and the click save but at this time I don't get any fatal error.I also checked at system log file and I saw some error like this:
php: /pkg_edit.php: The command '/usr/local/sbin/squid -k kill' returned exit code '1', the output was 'squid: ERROR: No running copy'
So you can see my screenshot.
I did not install SARG yet. Just only clean install pfsense and squid3Thank u
Donny
![Squid fatal error.png](/public/imported_attachments/1/Squid fatal error.png)
![Squid fatal error.png_thumb](/public/imported_attachments/1/Squid fatal error.png_thumb)
![Squid Error No package defined.png](/public/imported_attachments/1/Squid Error No package defined.png)
![Squid Error No package defined.png_thumb](/public/imported_attachments/1/Squid Error No package defined.png_thumb)
![Squid syslog file.png](/public/imported_attachments/1/Squid syslog file.png)
![Squid syslog file.png_thumb](/public/imported_attachments/1/Squid syslog file.png_thumb) -
Donny,
I've pushed a fix to this issue with no version change, on my tests it's working fine now.
wait 15 minutes, reinstall the package and try to configure it again.
att,
Marcello Coutinho -
Donny,
I've pushed a fix to this issue with no version change, on my tests it's working fine now.
wait 15 minutes, reinstall the package and try to configure it again.
att,
Marcello CoutinhoOk, I will try after 30 minutes.
-
I just clean install pfSense and basic configured. After that I have installed Squid3 last version. In the Squid "general tab" I just only use some default setting. I enable "Enable logging and log rotate" and also changed the language to "en". So I click save. I got fatal error on Chrome web browser like this: "Fatal error: Cannot use string offset as an array in /usr/local/pkg/squid.inc on line 1378" and at this point I enter Chrome web browser again I got: "Error: No packege defined". then I enter pfSense Lan IP and went back to Squid general tab but not things save (Enable logging and log rotate and language "en"). I saw on dashboard that Squid is not running and then I tried to configure squid on general tab again and the click save but at this time I don't get any fatal error. I also checked at system log file and I saw some error like this: php: /pkg_edit.php: The command '/usr/local/sbin/squid -k kill' returned exit code '1', the output was 'squid: ERROR: No running copy' So you can see my screenshot. I did not install SARG yet. Just only clean install pfsense and squid3
Hello Marcello,
I just tried it and I got the same fatal error and the same result that I explain before.
This is second time to clean install pfSense and Squid. I did not try to reinstall squid package because I want to be sure that squid work without error.
Now in Holland is almost 1 AM in the morning, I am going to bed now.
Donny
-
I'll try to reproduce this error.
Try to refresh the page with f5 and save again.
-
Hi marcelloc
looks like sarg can't handle large entries on file /var/squidGuard/log/block.log
I don't want erase the file /var/squidGuard/log/block.log, could u help me?
php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 27976, reading: 0.00%^MSARG: Records in file: 5000, reading: 17.87%^MSARG: Records in file: 10000, reading: 35.74%^MSARG: Records in file: 15000, reading: 53.62%^MSARG: Records in file: 20000, reading: 71.49%^MSARG: Records in file: 25000, reading: 89.36%^MSARG: Hour string too long in redirector log file /var/squidGuard/log/block.log SARG: Records in file: 27976, reading: 100.00%'
-
looks like sarg can't handle large entries on file /var/squidGuard/log/block.log
I don't want erase the file /var/squidGuard/log/block.log, could u help me?try to split this log or use sarg args to limit log search.
Hour string too long in redirector log file /var/squidGuard/log/block.log SARG: Records in file: 27976, reading: 100.00%'
I understand this error as some format error on log file/line not a too many records errors.
-
Thanks!
I've set the User_report_limit to 300 and rotate squidguard block log…
It's work for a while... than stopped sudenly again!
php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 86169, reading: 0.00%^MSARG: Records in file: 5000, reading: 5.80%^MSARG: Records in file: 10000, reading: 11.61%^MSARG: Records in file: 15000, reading: 17.41%^MSARG: Records in file: 20000, reading: 23.21%^MSARG: Records in file: 25000, reading: 29.01%^MSARG: Records in file: 30000, reading: 34.82%^MSARG: Records in file: 35000, reading: 40.62%^MSARG: Records in file: 40000, reading: 46.42%^MSARG: Records in file: 45000, reading: 52.22%^MSARG: Records in file: 50000, reading: 58.03%^MSARG: Records in file: 55000, reading: 63.83%^MSARG: Records in file: 60000, reading: 69.63%^MSARG: Records in file: 65000, reading: 75.43%^MSARG: Records in file: 70000, reading: 81.24%^MSARG: Records in file: 75000, reading: 87.04%^MSARG: Records in file: 80000, reading: 92.84%^MSARG: Records in file: 85000, reading: 98.64%^MSARG: Successful report generated on /usr/local/sarg-reports/29May2
-
i did conf like you,http://forum.pfsense.org/index.php/topic,47765.165.html
its ok now ,thank you for great jobhello marcelloc,i got this error while testing sarg with squid and squidguard,and can't see reports on view report tab
Error: Could not find report index file.
Check and save sarg settings and try to force sarg schedule.php: : The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 72216, reading: 0.00%^MSARG: Records in file: 5000, reading: 6.92%^MSARG: Records in file: 10000, reading: 13.85%^MSARG: Records in file: 15000, reading: 20.77%^MSARG: Records in file: 20000, reading: 27.69%^MSARG: Records in file: 25000, reading: 34.62%^MSARG: Records in file: 30000, reading: 41.54%^MSARG: Records in file: 35000, reading: 48.47%^MSARG: Records in file: 40000, reading: 55.39%^MSARG: Records in file: 45000, reading: 62.31%^MSARG: Records in file: 50000, reading: 69.24%^MSARG: Records in file: 55000, reading: 76.16%^MSARG: Records in file: 60000, reading: 83.08%^MSARG: Records in file: 65000, reading: 90.01%^MSARG: Records in file: 70000, reading: 96.93%^MSARG: Cannot delete /usr/local/sarg-reports/2012/06/12/debakim.html - No such file or directory SARG: Records in file: 72216, reading: 100.00%'
-
Is Sarg currently broken?
I am running Sarg on Squid2 logs, kept the default Report Options, selected all entries in Report to generate, and set up an hourly schedule.
After forcing the update, the View Report gives me:
Error: Could not find report index file.
Check and save sarg settings and try to force sarg schedule.{$dir}/{$url} in sarg_frame-php contains /usr/local/sarg-reports/index.html, which does not exist, but report files have been generated under /usr/local/sarg-reports/2012/07/26 which mirrors today's date.
Any suggestions what to do?
-
Is Sarg currently broken?
No, I have 6 working with latest version
{$dir}/{$url} in sarg_frame-php contains /usr/local/sarg-reports/index.html, which does not exist, but report files have been generated under /usr/local/sarg-reports/2012/07/26 which mirrors today's date.
Any suggestions what to do?
Did you selected "Generate the main index.html" option on gui?
I've attached a screenshot with my current setup.
-
Did you selected "Generate the main index.html" option on gui?
No, I didn't. Now that I did it, it is working.
Thanx.
-
Can somebody explain if I need to set up log rotation in the schedule or not? And how this works?
I have it set to default ( do nothing) in SAR and have my squid settings set to 186 days log rotation (aprox 6 months).
Do I need to use the log rotation of SARG as wel? What does it do exactly? Clean up my old logs?
-
Do I need to use the log rotation of SARG as wel?
No, just one log rotate is fine.
What does it do exactly? Clean up my old logs?
Rotate logs and keep last 10 rotated files.(access.log.0 access.log.1 access.log.2…)
att,
Marcello Coutinho -
Thanks for your reply.
Does it mean that it reads through the whole file everytime? So If I have it set to rotate in squid settings every 6 months will this cause it to be slow at generating the report?
-
Thanks for your reply.
Does it mean that it reads through the whole file everytime? So If I have it set to rotate in squid settings every 6 months will this cause it to be slow at generating the report?
Yes, you can use date arg in schedules, but sarg will read all file the same way looking for logs on that date range.
-
If I change the rotation to 1 month in squid settings? Will it "save" my old logs in SARG? So I can view the internet logs older than one month?
So.. if I set squid to rotate every 30 days, does SARG delete the old data? Or does it display the old logs (from the last months) even though they have been rotated? (renamed?)
-
If I change the rotation to 1 month in squid settings? Will it "save" my old logs in SARG? So I can view the internet logs older than one month?
yes
So.. if I set squid to rotate every 30 days, does SARG delete the old data? Or does it display the old logs (from the last months) even though they have been rotated? (renamed?)
no
-
Maybe a language barrier here.. but do you mean yes I can still view the older internet proxy logs (older than 30 days) in SARG even though I set it to rotate every 30 days in Squid?