Once or every time?
Ralf
only while scanning. I added a dedicated process service to check if and how long, … the log4j-scan runs
…on Linux & Windows
Hallo,
can you post your config for this check?
It means that the CPU Load rises every time the check runs?
Any ideas how to reduced the load?
Ralf
you can check the overhead of the plugin, by running the scanner manually (with the same options as the plugin) and compare the load.
Thanks
I will check this tomorrow.
Ralf
Hi all,
Just found out yesterday, that this plugin doesn’t work on agents running on systemd. It work after I installed xinetd and changed the listening port.
I am pretty sure there is still a problem with systemd. The investigation with Tribe is still ongoing. Therefore I have temporarily switched back to xinetd.
CentOS for example has a too old systemd version (if I remember correctly).
There are some more threads about systemd and centos7.
Ralf
First of all thanks for the feddback and the ![]()
![]()
![]()
![]()
on the Exchange ![]()
If understand you correctly the agent ie working with systemd but not the plugin?
Sorry… I am little bit confused about agent and plugin.
What I am trying to say is; on a target host (CentOS running systemd) other checks output (CPU, memory, disk, etc.) are readable during service discovery, but there is no output from CVE-2021_44228-log4j.
When I try to restart xinetd service, I realized that port 6556 used by systemd. So I decide to change the xinetd port and re-scan the service, then CVE-2021_44228-log4j is there.
I think Doc’s reply is the answer for this 
so this was not realy an issue with the CVE-2021_44228-log4j plugin, nothing to fix on my side I guess ![]()
We found out that CentOS ships a very old version of systemd. This is buggy.
Time for a change to Debian… 
Hallo,
scanintervall (for excample) 86000 in the bakery is the one and only option to configure how often the scan runs?
Ralf
if you use the bakery → yes
There is a public KB article from Tribe about this.
https://kb.checkmk.com/pages/viewpage.action?pageId=17476598
Don’t start these debates here ![]()

12345678901234567890
Hallo,
time for the next step.
The CVE scanner show me 9000 different hits in our network (177 Hosts in then moment).
Most systems are used by developers.
My question:
How did you evaluate the scan results and what are your next steps?
Ralf
- search for CVE services
- filter for “not-OK”
- sort in some way
- hand over this info to their manager
- run

Hallo,
anyone here using the exclude features?
My questions:
is it possible to define a part of a path?
c:\dir1\subdir2\subdir3\project01
should be find using \subdir2\
We have tons of directories ist a dot.
c:\dir1\subdir2.namewithdot\project01
should be found using
Is this possible and what would be the correct syntax?
Thanks
Ralf
.namewithdot