Hello,

i'm trying to collect samples of messages sent to the ClamAV. I'm using VirusEvent feature with bash script which read data from ${CLAM_VIRUSEVENT_FILENAME}. Normally scanned with clamdscan there's value like 'fd[10]' or another file descriptor number, thus you can read the file from that descriptor. In case it is transferred trough the TCP protocol via INSTREAM command, the value is 'stream'.

Is there any chance to read that file from stream?

Thank you
Jan

Attachment: smime.p7s
Description: Elektronicky podpis S/MIME

_______________________________________________
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml

Reply via email to