intercept_fs
| Value | Named Filter |
|---|
Named filter for intercept FS driver settings.
Updated:
Revision: d0c46ac
Note: This is pre-release documentation.
Please access https://doc.dovecotpro.com/latest/ for documentation on released versions.
Driver name: fs
intercept_buffer_max_size isn't currently supported.FS driver writes intercepted sessions to a Dovecot Filesystems. The file begins with intercept_fs_header_line followed by the protocol traffic in Dovecot rawlog file format. For example:
rip=127.0.0.1 service=imap user=8b80216185b851ce9b2c7f6c4a53e16a
1732198510.211817 O: 1.1 OK [CAPABILITY IMAP4rev1 ...] Logged in
1732198510.211843 I: 1.2 APPEND "inbox" "22-Feb-2008 17:06:23 +0200" {87+}
...
1732198510.211846 O: 1.2 OK [APPENDUID 1732198510 1] Append completed (0.003 + 0.000 + 0.002 secs).
1732198510.211848 I: 1.3 select INBOX
...The following Settings Variables are supported by intercept_fs_* settings:
| Variable | Description |
|---|---|
| `user` | user@domain |
| `crypted_user` | user@domain encrypted via intercept_crypted_user |
| `protocol` | imap/pop3/lmtp |
| `local_ip` | local IP |
| `remote_ip` | remote IP |
| `local_port` | local port |
| `remote_port` | remote port |
| `home` | user's home directory |
| `session` | session ID |
intercept_fs| Value | Named Filter |
|---|
Named filter for intercept FS driver settings.
intercept_fs_header_line| Default | [None] |
|---|---|
| Value | string |
Add a header to the log.
See variables for supported variable substitutions.
intercept_fs_rotate_at_midnight| Default | no |
|---|---|
| Value | boolean |
Rotate the log at midnight (server's local timezone).
intercept_fs_rotate_interval| Default | 5min |
|---|---|
| Value | time |
Flush log and create a new one this often.
intercept_fs_rotate_size| Default | [None] |
|---|---|
| Value | size |
Rotate the log when it reaches this size.
If 0, never rotate.
intercept fs {
fs posix {
prefix = /tmp/intercept/%{crypted_user}/%{protocol}-
}
# Add a header to the log
header_line = rip=%{remote_ip} protocol=%{protocol} crypted_user=%{crypted_user}
# Flush log and create a new one every this often
rotate_interval = 5min
# Rotate the log at midnight (server's local timezone)
rotate_at_midnight = yes
}
intercept_debug = yesIntercepted sessions can be written to object storage using Dictmap. This replaces the fs posix filter in the example above. All fs filters inside the same block form a single chain, so fs posix can't be combined with fs dictmap.
This example reuses the mails dict and the user_other_objects Cassandra table from the obox configuration, see @fs_dictmap_defaults = cassandra and Cassandra Keyspace/Tables. The intercepted session files are mapped to object IDs with dict keys shared/dictmap/<fs_dictmap_dict_prefix><file name>. The only default dict map that matches these keys is shared/dictmap/$user/other/$object_name, so fs_dictmap_dict_prefix must be in <user>/other/ format. Using %{crypted_user} there keeps the plaintext username out of Cassandra.
See S3 Compatible Storage for configuring the fs s3 settings.
intercept fs {
fs dictmap {
# Store the objects with path <storage_objectid_prefix><object ID>
storage_objectid_prefix = intercept/%{crypted_user}/
# Must match the shared/dictmap/$user/other/$object_name dict map
dict_prefix = %{crypted_user}/other/
}
# Use the same dict as obox
dict proxy {
name = mails
socket_path = dict-async
}
# Object storage, configured with the fs_s3_* settings
fs s3 {
}
header_line = rip=%{remote_ip} protocol=%{protocol} crypted_user=%{crypted_user}
rotate_interval = 5min
rotate_at_midnight = yes
}