Hello,
I'm running csf+lfd and tracking for authentication failures but, exim looks like it's not keeping all authentication failures in /var/log/maillog. I see a lot of login failures in exim's mainlog file but none of them recorded to maillog. That makes lfd to fail to recognize login failures.
1. Why exim doesn't write login failure logs into maillog?
2. Should I change lfd to track exim mainlog?
I'm running csf+lfd and tracking for authentication failures but, exim looks like it's not keeping all authentication failures in /var/log/maillog. I see a lot of login failures in exim's mainlog file but none of them recorded to maillog. That makes lfd to fail to recognize login failures.
1. Why exim doesn't write login failure logs into maillog?
2. Should I change lfd to track exim mainlog?