<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog.conf in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629254#M817110</link>
    <description>What in the world is /var/adm/all directory anyway ? Have never seen or heard about this one at all.</description>
    <pubDate>Mon, 19 Sep 2005 12:07:45 GMT</pubDate>
    <dc:creator>Mel Burslan</dc:creator>
    <dc:date>2005-09-19T12:07:45Z</dc:date>
    <item>
      <title>Syslog.conf</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629252#M817108</link>
      <description>I am aksed by an audit to turn on the following logs. Can someone explain to me why some of these are and how to turn them on? Some like the local's, I have not heard of and found on HP's website. Do we really need these turned on?&lt;BR /&gt; &lt;BR /&gt;a. /var/adm/all/kern.log&lt;BR /&gt;&lt;BR /&gt;b. /var/adm/all/user.log&lt;BR /&gt;&lt;BR /&gt;c. /var/adm/all/mail.log&lt;BR /&gt;&lt;BR /&gt;d. /var/adm/all/daemon.log&lt;BR /&gt;&lt;BR /&gt;e. /var/adm/all/auth.log&lt;BR /&gt;&lt;BR /&gt;f. /var/adm/all/syslog.log&lt;BR /&gt;&lt;BR /&gt;g. /var/adm/all/lpr.log&lt;BR /&gt;&lt;BR /&gt;h. /var/adm/all/news.log&lt;BR /&gt;&lt;BR /&gt;i. /var/adm/all/uucp.log&lt;BR /&gt;&lt;BR /&gt;j. /var/adm/all/cron.log&lt;BR /&gt;&lt;BR /&gt;k. /var/adm/all/local0.log&lt;BR /&gt;&lt;BR /&gt;l. /var/adm/all/local1.log&lt;BR /&gt;&lt;BR /&gt;m. /var/adm/all/local2.log&lt;BR /&gt;&lt;BR /&gt;n. /var/adm/all/local3.log&lt;BR /&gt;&lt;BR /&gt;o. /var/adm/all/local4.log&lt;BR /&gt;&lt;BR /&gt;p. /var/adm/all/local5.log&lt;BR /&gt;&lt;BR /&gt;q. /var/adm/all/local6.log&lt;BR /&gt;&lt;BR /&gt;r. /var/adm/all/local7.log&lt;BR /&gt;&lt;BR /&gt;s. /etc/utmp&lt;BR /&gt;&lt;BR /&gt;t. /etc/security/lastlog&lt;BR /&gt;&lt;BR /&gt;u. /var/adm/wtmp&lt;BR /&gt;&lt;BR /&gt;v. /var/adm/messages&lt;BR /&gt;&lt;BR /&gt;w. /var/adm/syslog&lt;BR /&gt;&lt;BR /&gt;x. /var/adm/acct &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 19 Sep 2005 11:51:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629252#M817108</guid>
      <dc:creator>Global Server Operation</dc:creator>
      <dc:date>2005-09-19T11:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629253#M817109</link>
      <description>There is no /var/adm/all directory on HP-UX.  It sounds like the auditor is trying to use a generic Unix document and apply it specifically to HP-UX.  That ain't gonna work!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 19 Sep 2005 11:58:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629253#M817109</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2005-09-19T11:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629254#M817110</link>
      <description>What in the world is /var/adm/all directory anyway ? Have never seen or heard about this one at all.</description>
      <pubDate>Mon, 19 Sep 2005 12:07:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629254#M817110</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2005-09-19T12:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629255#M817111</link>
      <description>This is a very likely a generic list from the auditor without a translation for HP-UX (or AIX or Solaris or Linux, etc 'cause they're all different) mixed in with a bunch of customized files. Let's start with the standard HP-UX files in /var/adm:&lt;BR /&gt;&lt;BR /&gt;syslog is called /var/adm/syslog/syslog.log&lt;BR /&gt;(I would leave it there even though you can change it's name and location--other HP-UX professionals will have to go searching otherwise)&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;/var/adm/acct is NOT a file, it is a directory and only used with accounting turned on (not common)&lt;BR /&gt; &lt;BR /&gt;/etc/security/lastlog is not a standard HP-UX file. The last and lastb commands read the special binary files wtmp and btmp in /var/adm. These files can also be decoded with fwtmp.&lt;BR /&gt; &lt;BR /&gt;messages is often renamed to dmesg.log but you have to enable it yourself using cron, something like this:&lt;BR /&gt; &lt;BR /&gt;00,10,20,30,40,50 * * * * dmesg - &amp;gt;&amp;gt; /var/adm/messages&lt;BR /&gt; &lt;BR /&gt;kern user mail daemon syslog lpr news uucp local0 local1 local2 local3 lcoal4 local5 local6 local7:&lt;BR /&gt;are known as syslog facilities and normally, these are all logged into the syslog file. But with (extensive) changes to /etc/syslogd.conf, you can have syslogd split each facility into the different files shown above.&lt;BR /&gt; &lt;BR /&gt;You can tell the auditors that all these facilities are enabled and hand them the /etc/syslog.conf file as proof.</description>
      <pubDate>Mon, 19 Sep 2005 12:18:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629255#M817111</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2005-09-19T12:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629256#M817112</link>
      <description>Thanks to all.  This has really helped me a lot.  I will assign points.&lt;BR /&gt;</description>
      <pubDate>Mon, 19 Sep 2005 12:37:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf/m-p/3629256#M817112</guid>
      <dc:creator>Global Server Operation</dc:creator>
      <dc:date>2005-09-19T12:37:12Z</dc:date>
    </item>
  </channel>
</rss>

