<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog is not logging events in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5826433#M53926</link>
    <description>&lt;P&gt;/proc/kmesg doesn't produce any message, when a filesystem (/boot) runs full.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2012 11:22:43 GMT</pubDate>
    <dc:creator>Ralf Seefeldt</dc:creator>
    <dc:date>2012-10-08T11:22:43Z</dc:date>
    <item>
      <title>syslog is not logging events</title>
      <link>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5826331#M53925</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;I have a customer running a bunch of LINUX server (Oracle with RedHat Kernel 2.6.18-194.3.1.0.1.el5 ).&lt;BR /&gt;My problem is, that the syslog files are nearly empty.&lt;BR /&gt;One example (with a logrotate every week) is:&lt;/P&gt;&lt;P&gt;=========&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; # cat /var/log/messages.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sep 30 04:02:02 &amp;lt;hostname&amp;gt; syslogd 1.4.1: restart.&lt;BR /&gt;=========&lt;BR /&gt;That's all&lt;BR /&gt;&lt;BR /&gt;no auditd logs.&lt;BR /&gt;Today, we had a full local filesystem. There are no messages about this in the messages.&lt;BR /&gt;&lt;BR /&gt;The syslog configuration seems OK to me. syslogd and klogd are running.&lt;BR /&gt;&lt;BR /&gt;Where can I adjust the config for syslog to log as expected (vx_nospace, kernel, auditd, ...)?&lt;BR /&gt;&lt;BR /&gt;My config is:&lt;BR /&gt;&lt;BR /&gt;=============================&lt;BR /&gt;cat syslog.conf&lt;BR /&gt;# Log all kernel messages to the console.&lt;BR /&gt;# Logging much else clutters up the screen.&lt;BR /&gt;#kern.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /dev/console&lt;BR /&gt;&lt;BR /&gt;# Log anything (except mail) of level info or higher.&lt;BR /&gt;# Don't log private authentication messages!&lt;BR /&gt;*.info;mail.none;authpriv.none;cron.none&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/messages&lt;BR /&gt;&lt;BR /&gt;# The authpriv file has restricted access.&lt;BR /&gt;authpriv.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/secure&lt;BR /&gt;&lt;BR /&gt;# Log all the mail messages in one place.&lt;BR /&gt;mail.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -/var/log/maillog&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# Log cron stuff&lt;BR /&gt;cron.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/cron&lt;BR /&gt;&lt;BR /&gt;# Everybody gets emergency messages&lt;BR /&gt;*.emerg&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&lt;BR /&gt;&lt;BR /&gt;# Save news errors of level crit and higher in a special file.&lt;BR /&gt;uucp,news.crit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/spooler&lt;BR /&gt;&lt;BR /&gt;# Save boot messages also to boot.log&lt;BR /&gt;local7.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /var/log/boot.log&lt;BR /&gt;&lt;BR /&gt;==================&lt;BR /&gt;cat&amp;nbsp; /etc/sysconfig/syslog&lt;BR /&gt;# Options to syslogd&lt;BR /&gt;# -m 0 disables 'MARK' messages.&lt;BR /&gt;# -r enables logging from remote machines&lt;BR /&gt;# -x disables DNS lookups on messages recieved with -r&lt;BR /&gt;# See syslogd(8) for more details&lt;BR /&gt;SYSLOGD_OPTIONS="-m 0"&lt;BR /&gt;# Options to klogd&lt;BR /&gt;# -2 prints all kernel oops messages twice; once for klogd to decode, and&lt;BR /&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; once for processing with 'ksymoops'&lt;BR /&gt;# -x disables all klogd processing of oops messages entirely&lt;BR /&gt;# See klogd(8) for more details&lt;BR /&gt;KLOGD_OPTIONS="-x"&lt;BR /&gt;#&lt;BR /&gt;SYSLOG_UMASK=077&lt;BR /&gt;# set this to a umask value to use for all log files as in umask(1).&lt;BR /&gt;# By default, all permissions are removed for "group" and "other".&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;=========================&lt;BR /&gt;ps -ef | grep log&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8482 12522&amp;nbsp; 0 11:17 pts/1&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 grep log&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9857&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; 0 11:06 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 syslogd -m 0&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9862&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; 0 11:06 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 klogd -x&lt;BR /&gt;...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;Ralf&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 09:39:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5826331#M53925</guid>
      <dc:creator>Ralf Seefeldt</dc:creator>
      <dc:date>2012-10-08T09:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not logging events</title>
      <link>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5826433#M53926</link>
      <description>&lt;P&gt;/proc/kmesg doesn't produce any message, when a filesystem (/boot) runs full.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 11:22:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5826433#M53926</guid>
      <dc:creator>Ralf Seefeldt</dc:creator>
      <dc:date>2012-10-08T11:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not logging events</title>
      <link>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5828895#M53927</link>
      <description>&lt;P&gt;I figured out, that there is really no way to get historical informationen about filled up fielsystems. It is simply not tracked by LINUX.&lt;/P&gt;&lt;P&gt;Tools like logwatch would do the job, but with the restriction, that they do not run permanently and provide only a discrete view of the filesystems.&lt;/P&gt;&lt;P&gt;If one likes to figure out, whether or not some unknown application fills up a filesystem every night at 2:23 am for only 20 seconds, then LINUX by itself can not give the answer. Only the applications logfile or an additional daemon could do this job.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 09:51:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/syslog-is-not-logging-events/m-p/5828895#M53927</guid>
      <dc:creator>Ralf Seefeldt</dc:creator>
      <dc:date>2012-10-10T09:51:20Z</dc:date>
    </item>
  </channel>
</rss>

