Page 1 of 1

Unable to whitelist Varnish from LFD Suspicious File Alert

Posted: 27 Nov 2023, 09:30
by geekytone
Hello,

Currently, I get a ton of emails like this:
lfd on [hostname]: Suspicious File Alert
Time: Mon Nov 27 10:17:20 2023 +0100
File: /tmp/xxxxxxxx.o
Reason: Linux Binary
Owner: varnish:varnish (xxx:xxx)
Action: No action taken
These files are created by Varnish when it compiles the VCL for reloading.

However, I already whitelisted the "varnish" user from /etc/csf/csf.fignore like this:
user:varnish
But it still send emails. Is there a bug in LFD or did I made something wrong?