Postfix 09 - pflogsumm
Postfix Mail Server Learning · Previous: EnGarde Secure Linux - installing a mail gateway
#########################
# pflogsumm #
#########################
# install pflogsumm
# -------------------------------
# apt-get install pflogsumm
# adjusting the rotation of the mail logs
# -------------------------------
# vi /etc/logrotate.conf
/var/log/mail.log {
missingok
daily
rotate 7
create
compress
start 0
}
# creating the script that sends the report
# -------------------------------
# vi /usr/local/sbin/postfix_report.sh
#!/bin/sh
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
gunzip /var/log/mail.log.0.gz
pflogsumm /var/log/mail.log.0 | formail -c -I"Subject: Mail Statistics" -I"From: pflogsumm@localhost" -I"To: postmaster@example.com" -I"Received: from www.example.com ([192.168.0.100])" | sendmail postmaster@example.com
gzip /var/log/mail.log.0
exit 0
# chmod 755 /usr/local/sbin/postfix_report.sh
# scheduling it in the crontab
# -------------------------------
0 7 * * * /usr/local/sbin/postfix_report.sh > /dev/null 2>&1Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2009. This section lists what has changed since and what to do instead today.
- pflogsumm itself: the tool is still packaged (Debian ships
pflogsumm) and still does what the article uses it for. - Unpacking and repacking the log: the script runs
gunzipandgzipon the rotated log around the report. That is not needed: pflogsumm reads standard input when no file is given, and-d yesterdayrestricts the report to yesterday's entries, so it can read the live log or azcatpipe, as below. - Faked headers with
formail: building the message withformail -I"Received: ..."adds a forgedReceived:line for no benefit. Pipe the report to a normal mail command with a subject, which is also what the pflogsumm manual page shows. - Where the log is: from Debian 12 on, rsyslog is not installed by default and the journal is the primary log, so
/var/log/mail.logexists only where rsyslog is installed. Debian's rsyslog also defaults to high-precision timestamps now, which the release notes flag as affecting log-reading programs; after an upgrade check that the report is not empty. - logrotate stanza:
start 0is what produces themail.log.0name the script depends on. Put such a stanza into its own file under/etc/logrotate.d/rather than intologrotate.conf, and make sure the distribution's own rule formail.logdoes not rotate the same file a second time.
$ # pflogsumm -d yesterday /var/log/mail.log | mail -s "Mail Statistics" postmaster@example.com $ # zcat /var/log/mail.log.0.gz | pflogsumm | mail -s "Mail Statistics" postmaster@example.com
Sources: