{"id":14336,"date":"2025-12-30T10:41:56","date_gmt":"2025-12-30T05:11:56","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=14336"},"modified":"2026-09-07T11:13:25","modified_gmt":"2026-09-07T05:43:25","slug":"how-to-monitor-secure-clamav-on-linux-server","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/how-to-monitor-secure-clamav-on-linux-server\/","title":{"rendered":"How to Monitor &amp; Secure ClamAV on Linux Server &#8211; Full Guide"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>To monitor and secure ClamAV on a Linux server<\/strong>, keep virus signatures updated (freshclam), enable real-time on-access scanning, schedule regular full scans, harden clamd\/freshclam configs, centralize logs and alerts, quarantine detections, and test with EICAR. Use systemd services and timers for reliability, plus syslog\/SIEM integration for visibility and compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ClamAV is a proven, open-source antivirus engine for Linux. In this guide, you\u2019ll learn how to monitor and secure ClamAV on Linux server environments using safe defaults, real-time scanning, scheduled jobs, alerting, and hardening. The steps are beginner-friendly yet production-ready, based on years of hosting and security operations experience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-is-clamav-and-why-monitoring-matters\"><strong>What is ClamAV and Why Monitoring Matters<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ClamAV provides malware detection for files, archives, email, and web content. Installing it is only half the job\u2014continuous <a href=\"https:\/\/www.youstable.com\/blog\/zabbix-top-alternatives\/\">monitoring and secure configuration are what keep servers<\/a> safe in the real world. Attackers target uploads, temporary directories, web roots, and email spools; without updates, alerting, and on-access scanning, threats can slip by unnoticed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"core-components-youll-use\"><strong>Core Components You\u2019ll Use<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>clamd:<\/strong> Multithreaded scanning daemon used for speed and concurrent scans.<\/li>\n\n\n\n<li><strong>clamscan\/clamdscan: <\/strong>On-demand scanners (clamdscan talks to clamd).<\/li>\n\n\n\n<li><strong>freshclam:<\/strong> Automatic signature updater.<\/li>\n\n\n\n<li><strong>clamonacc:<\/strong> On-access (real-time) scanner using Linux fanotify.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"prerequisites-and-quick-checks\"><strong>Prerequisites and Quick Checks<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.youstable.com\/blog\/install-iptables-on-linux\/\">Linux server<\/a> with systemd (Ubuntu\/Debian, AlmaLinux\/RHEL, Rocky, etc.).<\/li>\n\n\n\n<li>Root\/sudo access.<\/li>\n\n\n\n<li>Outbound HTTPS\/DNS allowed for signature updates.<\/li>\n\n\n\n<li>Basic mail\/sendmail or alerting path (optional, for notifications).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Check versions to ensure you\u2019re on a supported build with fanotify support:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>clamscan --version\nclamd --version\nfreshclam --version\nclamonacc --version<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"install-and-update-clamav-properly\"><strong>Install and Update ClamAV Properly<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ubuntu-debian\"><strong>Ubuntu\/Debian<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt <a href=\"https:\/\/www.youstable.com\/blog\/install-clamav-on-linux\/\">install -y clamav<\/a> clamav-daemon clamav-freshclam\nsudo systemctl enable --now clamav-freshclam\nsudo systemctl enable --now clamav-daemon\n\n# Initial database update (if needed)\nsudo systemctl stop clamav-freshclam\nsudo freshclam\nsudo systemctl start clamav-freshclam<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"rhel-almalinux-rocky\"><strong>RHEL\/AlmaLinux\/Rocky<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo dnf install -y epel-release\nsudo dnf install -y clamav clamav-update clamav-server-systemd clamav-scanner-systemd\nsudo sed -i 's\/^Example\/#Example\/' \/etc\/clamd.d\/scan.conf\nsudo sed -i 's\/^Example\/#Example\/' \/etc\/freshclam.conf\nsudo systemctl enable --now freshclam\nsudo systemctl enable --now clamd@scan<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Tip: Always verify freshclam runs automatically and the database is current. Out-of-date signatures are the #1 failure mode we see in incident response.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"secure-clamav-configuration-clamd-conf-and-freshclam-conf\"><strong>Secure ClamAV Configuration (clamd.conf and freshclam.conf)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"essential-clamd-conf-settings\"><strong>Essential clamd.conf Settings<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Debian\/Ubuntu, edit \/etc\/clamav\/clamd.conf. On RHEL-like, edit \/etc\/clamd.d\/scan.conf. Below are safe, production-oriented defaults (adjust paths to your distro):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Run as unprivileged user\nUser clamav\nAllowSupplementaryGroups yes\n\n# Use a local socket, restrict permissions\nLocalSocket \/run\/clamav\/clamd.ctl\nLocalSocketMode 660\n\n# Logging\nLogFile \/var\/log\/clamav\/clamd.log\nLogTime yes\nLogRotate yes\nLogSyslog yes\n\n# Detection features\nScanPE yes\nScanELF yes\nDetectPUA no           # set to yes if you can manage potential false positives\nHeuristicScanPrecedence yes\nBytecode yes\n\n# Resource limits (tune for your server)\nMaxFileSize 200M\nMaxScanSize 300M\nMaxRecursion 16\nMaxThreads 4           # increase on larger CPUs\nReadTimeout 300\nStreamMaxLength 300M\n\n# Exclusions (avoid scanning pseudo\/virtual FS)\nExcludePath ^\/proc\/\nExcludePath ^\/sys\/\nExcludePath ^\/dev\/\nExcludePath ^\/run\/\nExcludePath ^\/var\/lib\/docker\/overlay2\/   # tune for containers if applicable\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"secure-freshclam-conf-settings\"><strong>Secure freshclam.conf Settings<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Debian\/Ubuntu: \/etc\/clamav\/freshclam.conf. On RHEL-like: \/etc\/freshclam.conf. Recommended:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Log updates\nUpdateLogFile \/var\/log\/clamav\/freshclam.log\nLogTime yes\n\n# Official mirror (CDN-aware)\nDatabaseMirror database.clamav.net\n\n# Check up to 12 times\/day (balanced)\nChecks 12\n\n# Optional: use a proxy if egress is restricted\n# HTTPProxyServer proxy.example.com\n# HTTPProxyPort 3128\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If you must expose clamd over TCP (for remote scanners), bind only to localhost or a management network and firewall strictly:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># clamd.conf\nTCPSocket 3310\nTCPAddr 127.0.0.1\n# then use firewalls\/VPNs if exposed beyond localhost<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"enable-real-time-on-access-scanning-with-clamonacc\"><strong>Enable Real-Time (On-Access) Scanning with clamonacc<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On-access scanning blocks or detects malware the moment it\u2019s created or modified. clamonacc uses Linux fanotify; ensure your kernel supports it (modern distros do).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"start-clamonacc-via-systemd\"><strong>Start clamonacc via systemd<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Debian\/Ubuntu typically provide a clamonacc service. Adjust paths for your server (scan the directories where files arrive\u2014web roots, user homes, uploads):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Example: monitor \/var\/www and \/home\nsudo systemctl enable --now clamav-clamonacc\n\n# Or run manually to test:\nsudo clamonacc --fdpass \n  --log=\/var\/log\/clamav\/onaccess.log \n  --include=\/var\/www \n  --include=\/home \n  --exclude-dir=\/proc \n  --exclude-dir=\/sys \n  --exclude-dir=\/dev<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">On RHEL-like systems, you can create a dedicated unit to run clamonacc with your include\/exclude set.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/systemd\/system\/clamonacc.service\n&#91;Unit]\nDescription=ClamAV On-Access Scanner\nAfter=clamd@scan.service\n\n&#91;Service]\nType=simple\nUser=root\nExecStart=\/usr\/bin\/clamonacc --fdpass --log=\/var\/log\/clamav\/onaccess.log \n  --include=\/var\/www --include=\/home --exclude-dir=\/proc --exclude-dir=\/sys --exclude-dir=\/dev\nRestart=always\n\n&#91;Install]\nWantedBy=multi-user.target\n\n# Enable it\nsudo systemctl daemon-reload\nsudo systemctl enable --now clamonacc<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Keep your include list focused to limit overhead. For high-traffic sites, start with upload directories and expand as needed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"schedule-regular-full-scans-systemd-timers-or-cron\"><strong>Schedule Regular Full Scans (systemd timers or cron)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even with on-access scanning, perform scheduled deep scans to catch dormant files and verify exclusions aren\u2019t hiding risks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-systemd-timer-recommended\"><strong>Create a systemd Timer (recommended)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># \/usr\/local\/sbin\/clamav-scan.sh\n#!\/usr\/bin\/env bash\nset -euo pipefail\nLOG=\"\/var\/log\/clamav\/scan-$(date +%F).log\"\nmkdir -p \/var\/log\/clamav\n\/usr\/bin\/clamdscan -m -i --fdpass --log=\"$LOG\" \/var\/www \/home \/srv || true\ngrep -q \"FOUND\" \"$LOG\" &amp;&amp; mail -s \"ClamAV Malware Found on $(hostname)\" root &lt; \"$LOG\" || true\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo chmod +x \/usr\/local\/sbin\/clamav-scan.sh\n\n# \/etc\/systemd\/system\/clamav-scan.service\n&#91;Unit]\nDescription=Nightly ClamAV Scan\n\n&#91;Service]\nType=oneshot\nExecStart=\/usr\/local\/sbin\/clamav-scan.sh<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/systemd\/system\/clamav-scan.timer\n&#91;Unit]\nDescription=Run ClamAV scan nightly\n\n&#91;Timer]\nOnCalendar=02:30\nPersistent=true\n\n&#91;Install]\nWantedBy=timers.target\n\n# Enable the timer\nsudo systemctl daemon-reload\nsudo systemctl enable --now clamav-scan.timer<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"cron-alternative\"><strong>Cron Alternative<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo bash -c 'cat &gt;\/etc\/cron.daily\/clamav-scan &lt;&lt;\"EOF\"\n#!\/usr\/bin\/env bash\n\/usr\/bin\/clamdscan -m -i --fdpass --log=\/var\/log\/clamav\/cron-scan.log \/var\/www \/home \/srv || true\ngrep -q \"FOUND\" \/var\/log\/clamav\/cron-scan.log &amp;&amp; mail -s \"ClamAV Malware Found on $(hostname)\" root &lt; \/var\/log\/clamav\/cron-scan.log || true\nEOF\nchmod +x \/etc\/cron.daily\/clamav-scan'<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"quarantine-actions-and-exclusions\"><strong>Quarantine, Actions, and Exclusions<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-safe-quarantine\"><strong>Create a Safe Quarantine<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo mkdir -p \/var\/quarantine\nsudo chown clamav:clamav \/var\/quarantine\nsudo chmod 750 \/var\/quarantine\n\n# Example: move infected files during scans\nclamdscan -m --move=\/var\/quarantine \/var\/www<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can also hook a VirusEvent to trigger a response script per detection (notify, isolate, delete after backup verification):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># in clamd.conf\nVirusEvent \/usr\/local\/bin\/clamav-incident.sh --file=%f --malware=%v<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Be conservative with deletions; quarantining first is safer. Always exclude ephemeral paths (\/proc, \/sys, \/run) and large immutables (VM images, backup archives) unless you\u2019ve planned the performance impact.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"monitoring-and-alerts-you-can-trust\"><strong>Monitoring and Alerts You Can Trust<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"watch-logs-and-service-health\"><strong>Watch Logs and Service Health<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Service status\nsystemctl status clamav-daemon clamav-freshclam 2&gt;\/dev\/null || true\nsystemctl status clamd@scan freshclam 2&gt;\/dev\/null || true\n\n# Recent logs (systemd)\njournalctl -u clamav-daemon -u clamav-freshclam -u clamonacc --since \"1 hour ago\"\njournalctl -u clamd@scan -u freshclam --since \"1 hour ago\"\n\n# Find detections\ngrep -R \"FOUND\" \/var\/log\/clamav\/ 2&gt;\/dev\/null<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"email-and-syslog-alerts\"><strong>Email and Syslog Alerts<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable LogSyslog in clamd.conf and forward syslog\/journal to your SIEM. For simple email alerts, pipe log excerpts to mailx as shown in the systemd\/cron examples.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"prometheus-nagios-integration\"><strong>Prometheus\/Nagios Integration<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nagios\/Icinga: use a plugin to verify freshclam age and clamd health.<\/li>\n\n\n\n<li>Prometheus: expose log-derived metrics (detections, database age) via node_exporter\u2019s textfile collector or a community clamav_exporter.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"test-detection-with-eicar\"><strong>Test Detection with EICAR<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>curl -fsSL -o \/tmp\/eicar.com.txt https:\/\/secure.eicar.org\/eicar.com.txt\nclamscan \/tmp\/eicar.com.txt\n# Expect: EICAR test file FOUND<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If on-access is enabled for \/tmp, simply writing the file should trigger a detection logged in onaccess.log or clamd.log.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"performance-tuning-and-best-practices\"><strong>Performance Tuning and Best Practices<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use clamdscan (daemon) for speed; avoid clamscan in production.<\/li>\n\n\n\n<li>Tune MaxThreads to CPU cores (start with 2\u20134, test under load).<\/li>\n\n\n\n<li>Scan during off-peak hours; prioritize high-risk paths (\/var\/www, uploads, homes).<\/li>\n\n\n\n<li>Right-size MaxScanSize\/MaxFileSize to avoid thrashing on multi-GB artifacts.<\/li>\n\n\n\n<li>Cache-friendly: exclude container layers, VM images, and backup mounts from on-access; scan them in scheduled jobs instead.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"advanced-hardening\"><strong>Advanced Hardening<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"user-mac-policies-and-sockets\"><strong>User, MAC Policies, and Sockets<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Run clamd as the clamav user (default). Avoid root unless required for fdpass.<\/li>\n\n\n\n<li>Keep LocalSocket permissions restrictive (660) and group-owned by a service group that needs access.<\/li>\n\n\n\n<li>Enable and tune SELinux\/AppArmor profiles to confine clamd and clamonacc.<\/li>\n\n\n\n<li>If using TCP, bind to 127.0.0.1 or a management subnet; enforce firewalls and no public exposure.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"optional-community-signatures\"><strong>Optional: Community Signatures<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can enhance detection using reputable third-party signatures (e.g., Sanesecurity, SecuriteInfo). Validate sources, automate updates cautiously, and track false positives. Test in staging before rolling out to production.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"email-and-web-stack-integration\"><strong>Email and Web Stack Integration<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Mail servers: integrate clamav-milter with Postfix\/Sendmail to scan inbound mail.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.youstable.com\/blog\/install-apache-web-server-in-linux\/\">Web servers:<\/a> scan uploads at the application layer, and let clamonacc cover file writes at the OS layer.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"troubleshooting-common-issues\"><strong>Troubleshooting Common Issues<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"freshclam-fails-or-is-throttled\"><strong>freshclam Fails or Is Throttled<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Check connectivity and DNS: dig database.clamav.net.<\/li>\n\n\n\n<li>Reduce Checks if you\u2019re hitting rate limits.<\/li>\n\n\n\n<li>If behind a proxy, set HTTPProxy in freshclam.conf.<\/li>\n\n\n\n<li>Review \/var\/log\/clamav\/freshclam.log for specific errors.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"on-access-errors-fanotify\"><strong>On-Access Errors (fanotify)<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensure clamd is running before clamonacc.<\/li>\n\n\n\n<li>Run clamonacc with &#8211;fdpass when needed so it can pass file descriptors to clamd.<\/li>\n\n\n\n<li>Exclude network filesystems or special mounts that don\u2019t support fanotify.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"false-positives\"><strong>False Positives<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm with VirusTotal or multiple scanners.<\/li>\n\n\n\n<li>Temporarily exclude specific paths or hashes while you report upstream.<\/li>\n\n\n\n<li>Keep PUA disabled unless you can review alerts quickly.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs-monitor-and-secure-clamav-on-linux-server\"><strong>FAQs: Monitor and Secure ClamAV on Linux Server<\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765954702086\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-often-should-i-update-clamav-signaturesu003c-strongu003e\">u003cstrongu003eHow often should I update ClamAV signatures?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Set freshclam to check 6\u201312 times per day. This balances bandwidth and freshness. In high-risk environments, tighten to hourly checks. Always verify that freshclam is enabled at boot and logs updates successfully.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765954709373\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003eis-on-access-scanning-required-if-i-run-daily-scansu003c-strongu003e\">u003cstrongu003eIs on-access scanning required if I run daily scans?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, for most internet-facing servers. On-access scanning catches threats immediately\u2014before they\u2019re executed or served. Scheduled scans are still important to catch dormant files and verify exclusions.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765954725681\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ewhat-should-i-scan-to-reduce-load-on-busy-serversu003c-strongu003e\">u003cstrongu003eWhat should I scan to reduce load on busy servers?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Prioritize web roots, upload directories, email spools, and user homes. Exclude virtual filesystems and large immutable artifacts. Use on-access for high-risk paths and nightly deep scans for the rest.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765954736774\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003e-how-do-i-get-alerted-when-clamav-finds-malwareu003c-strongu003e\">u003cstrongu003e How do I get alerted when ClamAV finds malware?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Parse \u201cFOUND\u201d lines from clamd\/freshclam logs and send email via mailx, or forward logs to your SIEM\/Syslog and create rules. The sample systemd timer script in this guide demonstrates a simple email alert.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765954749724\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ecan-i-use-third-party-signatures-safelyu003c-strongu003e\">u003cstrongu003eCan I use third-party signatures safely?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, from reputable providers like Sanesecurity or SecuriteInfo. Test in staging first, monitor for false positives, and document your update process. Keep official databases enabled as your baseline.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">By combining timely updates, on-access scanning, scheduled deep scans, robust logging, and alerting, you can confidently <a href=\"https:\/\/www.youstable.com\/blog\/how-to-monitor-secure-git-on-linux\/\">monitor and secure ClamAV on Linux server<\/a> workloads. Adopt the configuration snippets above, test with EICAR, and iterate on exclusions and performance settings for your environment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To monitor and secure ClamAV on a Linux server, keep virus signatures updated (freshclam), enable real-time on-access scanning, schedule regular [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":16660,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":132,"footnotes":""},"categories":[350,2262],"tags":[],"class_list":["post-14336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-kb-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=14336"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14336\/revisions"}],"predecessor-version":[{"id":23335,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14336\/revisions\/23335"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/16660"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=14336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=14336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=14336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}