# logcheck mit Homebrew, apk, apt, Nix, zypper installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für logcheck in AI-Agent-Workflows.

## Installation

```sh
sudo av install brew:logcheck
```

Weitere Installationsbefehle:

### macOS

- Homebrew (100%):

```sh
brew install logcheck
```

  Evidenz: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add logcheck
```

  Evidenz: Alpine Linux edge package indexes: logcheck from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz

- Debian apt (92%):

```sh
sudo apt install logcheck
```

  Evidenz: Debian stable package indexes: logcheck from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- Nix (92%):

```sh
nix profile install nixpkgs#logcheck
```

  Evidenz: nixpkgs package indexes: pkgs/by-name/lo/logcheck/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- zypper (92%):

```sh
sudo zypper install logtail
```

  Evidenz: openSUSE Tumbleweed package metadata: logtail from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

## Paketfakten

- **Paketschlüssel:** brew:logcheck
- **Paketmanager:** Homebrew
- **Paketmanager-Seite:** <https://formulae.brew.sh/formula/logcheck>
- **Version:** 1.4.7
- **Quellzusammenfassung:** Mail anomalies in the system logfiles to the administrator
- **Homepage:** <https://packages.debian.org/sid/logcheck>
- **Upstream-Dokumentation:** <https://packages.debian.org/sid/logcheck>
- **Lizenz:** GPL-2.0-only
- **Quellarchiv:** <https://deb.debian.org/debian/pool/main/l/logcheck/logcheck_1.4.7.tar.xz>
- **Generiert:** 2026-08-04T22:13:35+00:00

## Executables

- logcheck (cli)
- logcheck-test (cli)
- logtail (cli)
- logtail2 (cli)
- logcheck (Alias)
- logcheck-test (Alias)
- logtail (Alias)
- logtail2 (Alias)

## Build-Abhängigkeiten

- gnu-sed

## Installationsverhalten

- Post-install-Hook: nicht definiert
- Bottle: verfügbar auf all

## Version und Aktualität

- Seite generiert: 2026-08-04
- Manager-Version: 1.4.7
- lokale Daten: OK
- Upstream-Repository: https://packages.debian.org/sid/logcheck
- Info: No package-manager update timestamp was available.
- Info: Release/tag comparison is only available for GitHub repositories.
## Projektgeschichte und Nutzung

logcheck is a Debian-oriented log monitoring tool that scans system logs for unexpected entries and emails reports to the administrator. It focuses on filtering routine messages out so security violations, attack alerts, and unusual system events stand out.

### Projektgeschichte

Debian's package page says logcheck was originally part of the Abacus Project security tools and was later rewritten. The Debian repository's change notes describe the Debian package becoming effectively Debian-native after a major overhaul around version 1.1.9.1 because Debian's version had diverged substantially from the old upstream 1.1.1 code.

The current Debian Salsa repository presents logcheck as the maintained source home for Debian packaging, with the project description centered on mailing summaries of log file entries to administrators via cron.

### Adoptionsgeschichte

logcheck's adoption is strongest in Debian-family systems, where its manpages, package page, and logcheck-database rules are first-class distribution artifacts. The supplied package metadata also records package availability in Homebrew, Alpine, Nix, openSUSE, Debian, and Ubuntu.

The package belongs to an older Unix administration style: periodic cron jobs, regex rule directories in /etc, and email to root or an administrator. That style remains useful on servers where a small local checker is preferable to a centralized log pipeline.

### Wie es verwendet wird

The logcheck command runs by default as an hourly cron job and after reboot. It filters messages at paranoid, server, or workstation levels, sorts reports into system events, security events, and attack alerts, and sends email only when messages survive the rules.

Administrators tune it through `/etc/logcheck/logcheck.conf`, monitored-file lists, and rule directories such as cracking.d, violations.d, violations.ignore.d, and ignore.d.*. The logcheck-database documentation emphasizes writing precise extended regular expressions and testing new rules with logcheck-test.

### Warum Paket-Nerds sich dafür interessieren

logcheck is a packaging-culture artifact: much of its value lives in distribution-maintained regex databases and package-specific rule files, not in a large binary. It is a useful example of Debian packaging acting as upstream stewardship for a security-administration workflow.

### Zeitleiste

- Pre-1.1.9.1: logcheck originates in the Abacus Project security tools and is later rewritten.
- 1.1.9.1: Debian change notes describe a major overhaul and larger config/rulefile changes.
- 2018: Debian Salsa project page records repository creation on May 13, 2018.
- Current: Debian manpages document hourly cron use, report levels, and /etc/logcheck configuration.

### Related projects

- logtail: used by logcheck workflows to process recent log messages.
- logcheck-database: the companion rules package that supplies regular-expression filters.

### Quellen

- <https://manpages.debian.org/testing/logcheck/logcheck.8.en.html>
- <https://packages.debian.org/sid/logcheck>
- <https://salsa.debian.org/debian/logcheck>
- <https://salsa.debian.org/debian/logcheck/-/raw/debian/sid/CHANGES>
- <https://salsa.debian.org/debian/logcheck/-/raw/debian/sid/docs/README.logcheck-database>


## Sicherheitshinweise

narrow executable package without higher-risk signals.

- **Geiger-Risiko:** grün / niedrig
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: /etc/logcheck/logcheck.conf, /etc/logcheck/*.d/*
## Details aus der Quelldatenbank

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** logcheck
- **Version Scheme:** 0
- **Revision:** 0
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** stable

## Andere Paketmanager-Einträge

- Debian apt - logcheck - 1.4.5+deb13u1: normalized package name match | Debian stable package indexes: logcheck from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | check the system log for unusual entries
- Debian apt - logcheck-database - 1.4.5+deb13u1: normalized package name match | Debian stable package indexes: logcheck-database from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | database of system log rules for logcheck
- Debian apt - logtail - 1.4.5+deb13u1: normalized package name match | Debian stable package indexes: logtail from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | Identify new lines added to the end of log files
- Nix - logcheck: normalized package name match | nixpkgs package indexes: pkgs/by-name/lo/logcheck/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - logcheck - 1.4.3: normalized package name match | Ubuntu 24.04 LTS package indexes: logcheck from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz | check the system log for unusual entries
- Ubuntu apt - logcheck-database - 1.4.3: normalized package name match | Ubuntu 24.04 LTS package indexes: logcheck-database from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz | database of system log rules for logcheck
- Ubuntu apt - logtail - 1.4.3: normalized package name match | Ubuntu 24.04 LTS package indexes: logtail from https://archive.ubuntu.com/ubuntu/dists/noble/main/binary-amd64/Packages.gz | Identify new lines added to the end of log files
- apk - logcheck - 1.4.7-r0: normalized package name match | Alpine Linux edge package indexes: logcheck from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Bash scripts used to monitor system log files for anomalies | https://packages.debian.org/source/sid/logcheck
- apk - logcheck-doc - 1.4.7-r0: normalized package name match | Alpine Linux edge package indexes: logcheck-doc from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Bash scripts used to monitor system log files for anomalies (documentation) | https://packages.debian.org/source/sid/logcheck
- apk - logtail - 3.22-r3: installed executable or alias match | Alpine Linux edge package indexes: logtail from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | Print new lines in log file since the last run (sf.net logtail-v3 ver) | https://logtail-v3.sourceforge.net/
- zypper - logtail - 0.2.4-21.9: installed executable or alias match | openSUSE Tumbleweed package metadata: logtail from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Helper application to analyze logfiles | http://sourceforge.net/projects/logdigest


## Verwandte Links

- [Terminal utility packages](https://pkg.so/de/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Networking and protocol packages](https://pkg.so/de/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/de/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [Productivity CLI packages](https://pkg.so/de/productivity-cli-packages/) - Matched curated productivity category metadata from av.db.
- [gnu-sed](https://pkg.so/de/brew/gnu-sed/) - Build dependency declared by Homebrew.
- [auditbeat](https://pkg.so/de/brew/auditbeat/) - Shares pkgdb curated category or tags: cli, monitoring, security.
- [threatdeck](https://pkg.so/de/brew/threatdeck/) - Shares pkgdb curated category or tags: cli, monitoring, security.
- [fail2ban](https://pkg.so/de/brew/fail2ban/) - Shares pkgdb curated category or tags: cli, log-analysis, security.
- [aide](https://pkg.so/de/brew/aide/) - Shares pkgdb curated category or tags: cli, monitoring, security.
- [gnutls](https://pkg.so/de/brew/gnutls/) - Shares pkgdb curated category or tags: cli, security.
- [krb5](https://pkg.so/de/brew/krb5/) - Shares pkgdb curated category or tags: cli, security.
- [nettle](https://pkg.so/de/brew/nettle/) - Shares pkgdb curated category or tags: cli, security.
- [libcap](https://pkg.so/de/brew/libcap/) - Shares pkgdb curated category or tags: cli, security.

## Combined YAML source

View the package source record on GitHub. [combined/logcheck.yml](https://github.com/mxcl/pkgdb/blob/main/combined/logcheck.yml)


## Quellen

- pkg.so package database
- Geiger risk classifier
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
