Sorry, I wasn't clear enough on that: I need to see the processing of a
message (Experiencing the problem) inside the debug log. The one you attached
stops after rsyslogd init, but before any message is processed.

Rainer

> -----Original Message-----
> From: [email protected] [mailto:rsyslog-
> [email protected]] On Behalf Of Ayelet Regev
> Sent: Wednesday, August 10, 2011 6:15 PM
> To: rsyslog-users
> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10
> 
> Hi,
> 
> For now im only testing local ruleset.
> 
> im sending local4.debug event and i want it to log in
> /var/log/central/traceall , but all my events are sent to
> /var/adm/messages.
> 
> smu15a:/ ROOT > logger -p "local4.debug" "RSYSLOG test"
> 
> smu15a:/ ROOT > tail -1 /var/adm/messages
> 2011-08-10T19:12:10+03:00 smu15a root: [ID 702911 local4.debug] RSYSLOG
> test
> 
> smu15a:/ ROOT > tail -10 /var/log/central/traceall
> 
> smu15a:/ ROOT > more /etc/rsyslog-client.conf | grep -v ^#
> 
> $ModLoad imtcp
> $ModLoad imudp
> $ModLoad imsolaris
> 
> $RuleSet local
> user,daemon,uucp,cron,mark.notice               /var/adm/messages
> *.emerg;mail.none                               *
> kern.debug                                      /var/adm/messages
> auth.debug              /var/log/central/auth.debug
> mail.emerg                      /var/log/central/MIPSlog
> local0.debug                    /var/log/central/local0.debug
> local4.debug                    /var/log/central/traceall
> local6.debug
> /var/cti/logs/SDT/SDT_Audit_Information.log
> $DefaultRuleset local
> $RuleSet remote
> local0.debug                    @remoteserver:50514
> $InputTCPServerRun 50514
> $UDPServerRun 514
> $UDPServerRun 1514
> 
> On Wed, Aug 10, 2011 at 6:51 PM, Rainer Gerhards
> <[email protected]>wrote:
> 
> > Can you provide a debug log that contains an occurence of this
> problem?
> > This
> > helps us understand what happens.
> >
> > Rainer
> >
> > > -----Original Message-----
> > > From: [email protected] [mailto:rsyslog-
> > > [email protected]] On Behalf Of Ayelet Regev
> > > Sent: Wednesday, August 10, 2011 10:00 AM
> > > To: [email protected]
> > > Subject: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10
> > >
> > > ** <[email protected]>
> > >
> > > Hi All,
> > >
> > > Im testing rsyslog 4.7.2 on Solaris 10.
> > >
> > > You may see below  my syslog-client.conf file.
> > >
> > > Im running the rsyslog with these parameters and I have validated
> > > config
> > > file.:
> > > (I had to comment imklog module loading and listener commands to
> make
> > > it
> > > work without errors.)
> > > My biggest problem at the moment is that all events are written to
> > > /tmp/kuku
> > > no matter their severity...
> > > Im executing "logger -p "mail.emerg" "test"" and its written into
> > > /tmp/kuku
> > > and not to the correct file.
> > >
> > > Your help is more then apprichiated....
> > >
> > > smu15a:/ ROOT > /usr/local/sbin/rsyslogd -c4 -f /etc/rsyslog-
> > > client.conf
> > >
> > >
> > > smu15a:/ ROOT > /usr/local/sbin/rsyslogd -c4 -f /etc/rsyslog-
> > > client.conf -N4
> > > rsyslogd: version 4.7.2, config validation run (level 4), master
> config
> > > /etc/rsyslog-client.conf
> > > rsyslogd: End of config validation run. Bye
> > >
> > >
> > >
> > > # Modules
> > >
> > > $ModLoad imtcp
> > > $ModLoad imudp
> > > #$ModLoad imuxsock
> > > $ModLoad imsolaris
> > > #$ModLoad imklog
> > >
> > > # Templates
> > > # log every host in its own directory
> > > #$template
> > >
> RemoteHost,"/var/syslog/hosts/%HOSTNAME%/%$YEAR%/%$MONTH%/%$DAY%/syslog
> > > .log"
> > > ### Rulesets
> > > # Local Logging
> > > $RuleSet local
> > > ###user,daemon,uucp,cron,mark.notice            /var/adm/messages
> > > user.notice             /tmp/kuku
> > > ###kern.debug                                   /var/adm/messages
> > > ###*.emerg;mail.none                            *
> > > #Central logging events
> > > #Security logs
> > > auth,authpriv.debug             /var/log/central/auth.debug
> > > #MIPS applicaation logs
> > > mail.emerg                      /var/log/central/MIPSlog
> > > #Comverse applications events (other than MIPS)
> > > local0.debug                    /var/log/central/local0.debug
> > > #Strore local4 events in /var/log/central/traceall
> > > local4.debug                    /var/log/central/traceall
> > > local6.debug
> > > /var/cti/logs/SDT/SDT_Audit_Information.log
> > > # use the local RuleSet as default if not specified otherwise
> > > $DefaultRuleset local
> > > # Remote Logging
> > > $RuleSet remote
> > > *.crit                  @localhost:666
> > > # Send messages we receive to Gremlin
> > > ### Listeners
> > > # bind ruleset to tcp listener
> > > ###$InputTCPServerBindRuleset remote
> > > # and activate it:
> > > $InputTCPServerRun 50514
> > > ###$InputUDPServerBindRuleset remote
> > > $UDPServerRun 514
> > > $UDPServerRun 1514
> > >
> > >
> > > Ayelet Regev-Dabah
> > > System Software Platform TL
> > > *Comverse
> > > *Office: +972 3 6459362
> > > *[email protected]* <[email protected]>
> > > *www.comverse.com* <http://www.comverse.com/>
> > >
> > >
> > >
> > >  *  ________________________________  *
> > > "This e-mail message may contain confidential, commercial or
> privileged
> > > information that constitutes proprietary information of Comverse
> > > Technology
> > > or its subsidiaries. If you are not the intended recipient of this
> > > message,
> > > you are hereby notified that any review, use or distribution of
> this
> > > information is absolutely prohibited and we request that you delete
> all
> > > copies and contact us by e-mailing to: [email protected]. Thank
> > > You."
> > > _______________________________________________
> > > rsyslog mailing list
> > > http://lists.adiscon.net/mailman/listinfo/rsyslog
> > > http://www.rsyslog.com
> > _______________________________________________
> > rsyslog mailing list
> > http://lists.adiscon.net/mailman/listinfo/rsyslog
> > http://www.rsyslog.com
> >
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com

Reply via email to