AppleFileServer stops making Access Log Entries

This is the second time this has happened:
My file server, running Lion Server to serve up (among other things) OD to 20 clients, stops recording Login and Logout events to the AppleFileServiceAccess.log. Users can still connect; nothing else seems to have stopped working.
The only clue that I have found in the system.log is the entry below. I didn't look the last time it stopped logging access, so I can't say for sure if this is common. What did fix it (as usual) was rebooting the server or toggling the AFP server.
Mar  2 19:47:38 artx AppleFileServer[392]: RootHolder: user not authenticated with f_uid: <0>, f_gid: <1>
The last time the AppleFileServiceAccess.log file was touched was Mar  2 19:39, so I'm going to make the assumption that the above entry is what killed the logging.
Has anybody else experienced this, or had similar experiences?
Also worthy of note: this has only happened after I had done a complete, fresh Lion rebuild of the server. Previously, the server had been upgraded to Lion Server in gradual steps from Tiger Server and the logging never broke like this. The only differences in the setup after the rebuild are the inclusion of a self-signed SSL and the use

I get a parsing error adding that line in 9.2.3:
[07/23/2010 13:39:07] WebLogic Server 9.2 MP3  Mon Mar 10 08:28:41 EDT 2008 1096261 >
[07/23/2010 13:39:09] <Jul 23, 2010 1:39:09 PM EDT> <Error> <Management> <BEA-141244> <Schema validation errors while parsing
C:\bea923\weblogic92\config\WebCTDomain\config\config.xml - Expected elements 'log-time-in-gmt@ log-milli-
seconds@' instead of 'buffer-size-kb@' here in element web-server-
[07/23/2010 13:39:09] <Jul 23, 2010 1:39:09 PM EDT> <Critical> <WebLogicServer> <BEA-000362> <Server failed. Reason: [Management:141245]Schema
Validation Error in C:\bea923\weblogic92\config\WebCTDomain\config\config.xml see log for details. Schema validation can be disabled by starting the server with
the command line option: -Dweblogic.configuration.schemaValidationEnabled=false>
[07/23/2010 13:39:09] <Jul 23, 2010 1:39:09 PM EDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FAILED>
[07/23/2010 13:39:09] <Jul 23, 2010 1:39:09 PM EDT> <Error> <WebLogicServer> <BEA-000383> <A critical service failed. The server will shut itself down>
[07/23/2010 13:39:09] <Jul 23, 2010 1:39:09 PM EDT> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FORCE_SHUTTING_DOWN> Oh well.
Edited by: user9199914 on Jul 23, 2010 11:30 AM
Edited by: user9199914 on Jul 23, 2010 11:31 AM

Similar Messages

  • Does access log entry contains VLV  results in high etime?

    Hello all,
    I found following events in access log, Is it resulting in etime > 10 milli sec(recomended).? Do we need to avoid VLV involved searches, if yes how can we resist the client to do so. Please help me.
    [08/Oct/2012:09:22:31 +0000] conn=15860523 op=2 msgId=168 - SRCH base="ou=groups,dc=xxx,dc=com" scope=2 filter="(&(objectClass=groupofuniquenames)(uniqueMember=uid=xxxx,ou=people,dc=xxx,dc=com))" attrs="cn cn mail objectClass dn name objectsid"
    [08/Oct/2012:09:22:32 +0000] conn=15860523 op=2 msgId=168 - SORT cn (31)
    [08/Oct/2012:09:22:32 +0000] conn=15860523 op=2 msgId=168 - VLV 0:21474899:0:0 1:31 (0)
    [08/Oct/2012:09:22:33 +0000] conn=15860523 op=2 msgId=168 - RESULT err=0 tag=101 nentries=27 etime=1.514740* notes=U
    Thank in advance.

    Well first you have to see whether the client is authenticating as Directory Manager. If that's the case you can't prevent it from using the control, you have to make it use a different login.
    I don't currently have an installation of DSEE to check this on, but you should be able to find the VLV "feature" object somewhere under cn=config, either by searching against the suffix live, or by grepping in dse.ldif. The SORT control oids are 1.2.840.113556.1.4.*
    I usually had to work with this in the opposite context, where a non-privileged account was trying to use the control but did not have permission to. So in that case we would add an ACI under there to give the user access to the feature. In this case, you would do the opposite.
    The VLV index option is not practical. Since the filter must be part of the index definition, you would need an individual index for every user that would be queried like this.
    When I look at the nentries (27) and the response time (1 sec) I wonder if this is that big a deal. Requesting the server to SORT the results might be worth waiting a second for it, though I agree it a bit long to wait. The usual policy is not to worry about little SORT queries like this.
    I wonder if this is caused by general slowness in your service. Are other queries slow at the time this kind of response time is happening? Are these SORT type queries always slow or only sometimes? What is the CPU utilization like on the system? The SORT should really just be using a bit of extra CPU.

  • How do I get my ipod to stop making me log into my account?

    My new ipod has been asking me to log in to my apple account. When I do, using the correct passwrod, as it tells me when my password is incorrect, the ipod immediately asks me to do it again. I can't do anything on the thing. Why is it doing this and how do I stop it?

    What account is it asking to be logged into?
    Just what are you doing?
    iTunes/App Store?
    - Reset the iOS device. Nothing will be lost      
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Then try again
    Reset the password:
    How do I change or recover a forgotten Apple ID Password?
    If you've forgotten your Apple ID Password or want to change it, go to My Apple ID and follow the instructions. SeeChanging your Apple ID password if you'd like more information.
    - Backup and then restore from backup. See:                                               
    iOS: Back up and restore your iOS device with iCloud or iTunes
    - Restore to factory settings/new iOS device.                       

  • WMI stops returning event log entries

    A little bit of a strange issues with Server 2008. We've been trying to implement cisco CDA for a customer which uses wmi to read the security log on a DC and then matches the users up with the devices that are connecting to the network. Every week or so
    the CDA would stop receiving mappings from 2 out of 3 domain controllers. Once the wmi service is restarted on the DC the events start going through again.
    I've been able to replicate the behaviour using a script:
    strComputer = "dc-001.domain.local"
    Set objWMIService = GetObject("winmgmts:{(Security)}\\" & _
    strComputer & "\root\cimv2")
    Set colMonitoredEvents = objWMIService.ExecNotificationQuery _    
    ("Select * from __InstanceCreationEvent Where " _
    & "TargetInstance ISA 'Win32_NTLogEvent' " _
    & "and TargetInstance.EventCode=4768")
    Do While True
    Set objLatestEvent = colMonitoredEvents.NextEvent()
    Wscript.Echo objLatestEvent.TargetInstance.User
    Wscript.Echo objLatestEvent.TargetInstance.TimeWritten
    wscript.Echo objLatestEvent.TargetInstance.Message
    This hotfix seems to match what I'm seeing as there
    are no errors ...just no events returned back. Unfortunately installing the hotfix made no difference at all.
    It's also worth noting I can run different wmi queries while the one above isn't working so wmi service is up and running.
    Has anyone else come across this, or have I missed another patch somewhere?

    Hi Kacenka,
    On current situation, please use
    WMI Diagnosis Tool to ascertain the current state of the WMI service. For more details, please refer to the following article.
    WMIDiag 2.1 is here!
    Meanwhile, please post the above script in the
    Official Scripting Guys Forum, then confirm if it can help you to achieve that target correctly.
    If any more detail, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

  • .sh file usage log entries multiplied

    Hi all,
    I have a very strange problem: In order to find out what parts of a big application being used,
    I have added the following line as the first executable line in every .sh file:
    /application/sh_log $0
    The file sh_log looks like this:
    now=$(date +"%Y_%m_%d")
    if [ -f $filename ];                 # Does logfile exist?
       echo  $(basename $1)";"$(date +"%Y%m%d%H%M%S")";" >> $filename   # Logfile exists, append log record
       touch $filename          # Logfile did not exist, create it
       chmod 7777 $filename     # Make it writeable
       echo  $(basename $1)";"$(date +"%Y%m%d%H%M%S")";" >> $filename   # Ans append log record
    The application calls it's .sh files in a number of ways, but all of them originating from crontab.
    What confuses me is that log entries often appear in tuples, that is, when the application's
    .sh file is calling the file making the log entry, supposedly to make a single log entry, I'm still
    getting 2, 3 or even more log entries with the same time-stamp (resolution: 1 sec).
    I don't understand this and would appreciate if some guru here could give me a clou.

    I would log also PIDs together with script name: "/application/sh_log $0 $$". Then you could see whether the application script or sh_log is really called more times (different PIDs).
    Also consider to use chmod 0777 instead of 7777. So, e.g.:
    now=$(date +"%Y_%m_%d")
    [ ! -f $filename ] && touch $filename && chmod 0777 $filename
    #Format:  my_PID;script_name;script_PID;timestamp;
    echo  $$";"$(basename $1)";"$2";"$(date +"%Y%m%d%H%M%S")";" >> $filename

  • Access Log format for Sun One Web Server 6.0 SP6

    Is it possible to add the Process Id to the access log? If so, what is the proper format for the access log entry in magnus.conf. We would like to be able to see which process each request used, just like in the error log.

    User agent and referer information can be logged. Refer to following docs(see under Table 7-1):

  • Access Logging in OC4J

    I can get the various websites like the default-web-site to output access log information but they never have userid info in them, only "- -" even users are logged in. No userids appear in OHS access logs either. Apps frontended by SiteMinder have both REMOTE_USER and SMSESSION populated but no userid makes it into the access logs. Any ideas?

    I'd never done it, but it does look like you can specify a format for the access-log entries:
    The format string looks like it supports a field called $user, which may give you what you want.
    As a test, using OC4J, I just set mine up as follows in default-web-site.xml:
    <web-app application="ascontrol" name="ascontrol" load-on-startup="true" root="/em" ohs-routing="false" access-log="true"/>
    <access-log path="../log/default-web-access.log" format="$ip - $user '$request' $status $size"/>
    I then started OC4J, accessed the ascontrol application and logged in as the oc4jadmin user.
    In the access log, the following entries were produced that clearly lists the user I logged in as: - - - [ - - 'GET /em/console/ias/oc4j/home HTTP/1.1' 200 9654 - 'oc4jadmin' 'POST /em/j_security_check HTTP/1.1' 302 207 - 'oc4jadmin' 'GET /em/console/postLogon HTTP/1.1' 200 4731 - 'oc4jadmin' 'POST /em/console/postLogon HTTP/1.1' 302 180 - 'oc4jadmin' 'GET /em/console/ HTTP/1.1' 302 156 - 'oc4jadmin' 'GET /em/ HTTP/1.1' 200 185 - 'oc4jadmin' 'GET /em/console/ias/oc4j/home HTTP/1.1' 200 21610 - 'oc4jadmin' 'GET /em/cabo/images/cache/cghee.gif HTTP/1.1' 200 76 - 'oc4jadmin' 'GET /em/cabo/images/cache/cghes.gif HTTP/1.1' 200 109 - 'oc4jadmin' 'GET /em/cabo/images/cache/cstlu.gif HTTP/1.1' 200 43 - 'oc4jadmin' 'GET /em/cabo/images/cache/en/bRestOXOP.gif HTTP/1.1' 200 460 - 'oc4jadmin' 'GET /em/cabo/images/cache/en/bStopDwKu.gif HTTP/1.1' 200 426 - 'oc4jadmin' 'GET /em/cabo/images/cache/cstru.gif HTTP/1.1' 200 44 - 'oc4jadmin' 'GET /em/cabo/images/cache/cstll.gif HTTP/1.1' 200 44 - 'oc4jadmin' 'GET /em/cabo/images/cache/cghec.gif HTTP/1.1' 200 93 - 'oc4jadmin' 'GET /em/cabo/images/cache/cstrl.gif HTTP/1.1' 200 43 - 'oc4jadmin' 'GET /em/images/trafficGreen.gif HTTP/1.1' 200 1213 - 'oc4jadmin' 'GET /em/dynamicImage/emSDK/chart/EmChartBean?beanId=D659A5D6B83129E7F46647BB382F045B.gif HTTP/1.1' 200 3359

  • LIBTUX_CAT:1278 errors and access log entires

    On our development database, we're observing the LIBTUX_CAT 1278 warnings quite often. Each of these entries are accompanied by an lines in the access log of the same day.
    Question is:
    What do the access log entries mean? How are the two entries in the two files (the ULOG and access.ddmmyy files) related?
    125419.usplsoplhdimf03!?proc.13754.1.-2: 09-03-2010: Tuxedo Version, 64-bit
    125419.usplsoplhdimf03!?proc.13754.1.-2: LIBTUX_CAT:1278: ERROR: Cannot join application - permission denied
    $ grep 13754 *
    access.090310:125408.usplsoplhdimf03!?proc.13754.1.0: total client (17), logon with AUTH: NATIVE cltname (tpsysadm) usrname (OB4D2_SVR) success
    access.090310:125419.usplsoplhdimf03!?proc.13754.1.0: total client (17), logoff with AUTH: NATIVE cltname (tpsysadm) usrname (OB4D2_SVR) success

    I can't say for sure what is happening here, but my guess is that process 13754 may be calling tpterm() on some and then continuing to call other ATMI APIs.
    Most Tuxedo client APIs perform an implicit tpinit((TPINIT *)NULL) if called by an application which has not previously called tpinit(). Since this implicit tpinit does not include any authorization information, it can only succeed in an application with no authorization.
    The evidence is that your application performed a successful tpinit() (logon) at 12:54:08. The access log indicates that authorization was used. At 12:54:19 the application performed tpterm() (logoff). During the same second another tpinit() was unsuccessful. Most likely this was an implicit tpinit((TPINIT *)NULL) done by some other call such as tpcall(), tpconnect(), tpacall(), or another ATMI function.
    In order to further debug the problem, you may want to
    export TMTRACE=*:ulog:dye
    in the client which is failing. This will cause a record of all ATMI calls to be written to the userlog.

  • You can't use The following message is stopping me access my disk utility.  'this version of the application "Disk Utility" with this version of OS X.'  not only that my Mac pro keeps dropping my internet connection and logs on to BT Open.

    After installing Yosmite, The following message is stopping me accessing my disk utility.  'You can't use this version of the application “Disk Utility” with this version of OS X.' you have “Disk Utility” 12.1.1. 
    not only that my Mac pro keeps dropping my internet connection and logs on to BT Open.

    For whatever reason you don't have the Yosemite version of Disk Utility which is 13. I suggest you reinstall Yosemite.
    Reinstalling OS X Without Erasing the Drive
    Boot to the Recovery HD: Restart the computer and after the chime press and hold down the COMMAND and R keys until the menu screen appears. Alternatively, restart the computer and after the chime press and hold down the OPTION key until the boot manager screen appears. Select the Recovery HD and click on the downward pointing arrow button.
    Repair the Hard Drive and Permissions: Upon startup select Disk Utility from the main menu. Repair the Hard Drive and Permissions as follows.
    When the recovery menu appears select Disk Utility. After DU loads select your hard drive entry (mfgr.'s ID and drive size) from the the left side list.  In the DU status area you will see an entry for the S.M.A.R.T. status of the hard drive.  If it does not say "Verified" then the hard drive is failing or failed. (SMART status is not reported on external Firewire or USB drives.) If the drive is "Verified" then select your OS X volume from the list on the left (sub-entry below the drive entry,) click on the First Aid tab, then click on the Repair Disk button. If DU reports any errors that have been fixed, then re-run Repair Disk until no errors are reported. If no errors are reported click on the Repair Permissions button. Wait until the operation completes, then quit DU and return to the main menu.
    Reinstall OS X: Select Reinstall OS X and click on the Continue button.
    Download and install the 10.10.1 update.
    Note: You will need an active Internet connection. I suggest using Ethernet if possible because it is three times faster than wireless.
    Check that you have the current version of Disk Utility.

  • Unable to stop the event logs on access point console

    Hi team,
    I have an AIR-LAP1131AG-E-K9 access point having ios c1130-k9w8-mx.124-21a.JHB1.
    When I am trying to take the console of it there are many logs generated like LWAPP ...Go join the controller, Discover controller etc. and the ap is unable to register to the controller(2112 with ios version I'm trying to enter the command but there are many event msg generated....How do i stop this event log. I tried entering the command no debug all. but still there are many logs...
    I want to enter the the following commands
    #lwapp ap  ip address <ip addr>.
    #lwapp a pip default-gateway <gateway ip addr>
    #lwapp ap controller ip addr <controller ip>
    #wr me
    Revert me back on urgent basis
    Thanks in advance..

    Thanks Rashika,
    Now the access point got registered to the controller..This happened becuse of country Code..
    I have changed the country code to UK, Belgium it started working fine.
    Initially when it was IN the access point was not getting register..
    But now the problem which arised is that the user is unable to get authenticated to the radius server.
    Radius server is reachable and we have done every changes required for radius server authentication.
    Users are getting rejected.
    Customer is saying that the radius server is in IN domain and the WLC/access point is in UK,BE and hence the users are unable to connect..
    Is it so??
    Thanks in advance...

  • Strange entries in lighttpd access log -- help!

    I run a lighttpd server at home. I just use it for working with some scripts, and sharing stuff with my friends. I have a dynamic IP address, so I use dyndns for getting a hostname.
    Today I noticed some strange entries in the lighttpd access log: - [14/Feb/2010:11:38:23 +0530] "POST HTTP/1.0" 200 8 "-" "-" - - [14/Feb/2010:11:38:25 +0530] "CONNECT HTTP/1.0" 501 357 "-" "-" - [14/Feb/2010:11:45:40 +0530] "POST HTTP/1.0" 200 8 "-" "-" - - [14/Feb/2010:11:45:43 +0530] "CONNECT HTTP/1.0" 501 357 "-" "-" - [14/Feb/2010:11:52:58 +0530] "POST HTTP/1.0" 200 8 "-" "-" - - [14/Feb/2010:11:53:01 +0530] "CONNECT HTTP/1.0" 501 357 "-" "-" - [14/Feb/2010:12:00:12 +0530] "POST HTTP/1.0" 200 8 "-" "-" - - [14/Feb/2010:12:00:15 +0530] "CONNECT HTTP/1.0" 501 357 "-" "-" - [14/Feb/2010:12:07:28 +0530] "POST HTTP/1.0" 200 8 "-" "-" - - [14/Feb/2010:12:07:30 +0530] "CONNECT HTTP/1.0" 501 357 "-" "-"
    What is going on here? Some kind of spambot? Note that I don't have the sendmail service installed, and port 25 is not forwarded on my router. Is this a threat and how do I deal with this?

    loafer wrote:I don't know a great deal about this.  However, if you google for "" you'll get a load of hits, which indicate there may be a problem.
    Yes, I did some more searching and apparently its a known problem.
    This thing is trying to send a POST action to another site. Is there any way I can restrict POST actions to my own domain?

  • Regarding accessing log file entries in Oracle 10g

    i need to watch all actions done by users of database to build intrusion detection system...
    how can i get the log file entries and where it is stored in linux(oracle 10g) there any way to access logfile entries one by one..
    in advance

    Probably you are looking for database auditing.

  • Thousands of entries in Apache access logs for a single IP

    We are seeing thousands of connections in our Apache access logs coming from the same IP address connecting to the
    same pages with in a short period of time (~5-20 minutes). We see this in Firefox 27, 28, 29, and 30. Below is an example of the entries, and how they loop continuously. I have not been able to reproduce the problem manually, but this happens several times a week, and I see evidence in our logs, and by monitoring the session count in our database, which increase when this happens.
    Why is this happening? Is this a bug? I see a bug report filed at, but I do not see any replies. - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/login?new_loc=%2Fwebapps%2Fportal%2Fframeset.jsp HTTP/1.1" 302 - "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-" - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/login/?new_loc=%2Fwebapps%2Fportal%2Fframeset.jsp HTTP/1.1" 200 1000 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-" - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/portal/frameset.jsp HTTP/1.1" 200 1160 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-" - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/login?new_loc=%2Fwebapps%2Fportal%2Fframeset.jsp HTTP/1.1" 302 - "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-" - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/login/?new_loc=%2Fwebapps%2Fportal%2Fframeset.jsp HTTP/1.1" 200 1000 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-" - - [18/Jun/2014:16:03:50 -0400] "GET /webapps/portal/frameset.jsp HTTP/1.1" 200 1160 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:30.0) Gecko/20100101 Firefox/30.0" "-"

    Sorry, beyond the scope of this Firefox user support forum.
    You could try posting to the Web Development / Standards Evangelism forum at MozillaZine. The helpers over there are more knowledgeable about web site issues with Firefox.
    You'll need to register and login to be able to post in that forum.
    Or you could add information to that Bug report or create a new Bug report.
    Or the appropriate Google Group, linked in the right column of this page after you scroll-down a bit -

  • Access Log- Stream Play & Stream Stop

    Hello, I am new to Flash. I have recently installed FMIS 3.5.3. In checking the access logs I find data in both logs that display the same stream stop and stream play time . I'm not sure why the time is the same (00:19:27 example below). Videos play fine when testing from work (T3 connection). However, occasionally a very slight hesitation when playing video from home (I have cable connection).
    session    connect    2010-05-24    00:19:25    4576        3073    3073    -    -    -    -    200    -
    stream    play    2010-05-24    00:19:25    4576        3261    3476    lets_drive/rules/Epilogue-Making_an_Appointment    0    15042753    85.681000    200    -
    stream    stop    2010-05-24    00:19:27    4576        3346    500157    lets_drive/rules/Epilogue-Making_an_Appointment    521770    15042753    85.681000    200    -
    stream    play    2010-05-24    00:19:27    4576        3346    500157    lets_drive/rules/Epilogue-Making_an_Appointment    0    15042753    85.681000    200    -
    stream    stop    2010-05-24    00:19:27    4576        3346    527594    lets_drive/rules/Epilogue-Making_an_Appointment    1512    15042753    85.681000    200    -
    stream    play    2010-05-24    00:19:27    4576        3431    527846    lets_drive/rules/Epilogue-Making_an_Appointment    0    15042753    85.681000    200    -
    stream    stop    2010-05-24    00:19:27    4576        3516    654052    lets_drive/rules/Epilogue-Making_an_Appointment    139832    15042753    85.681000    200    -
    stream    play    2010-05-24    00:19:27    4576        3516    654052    lets_drive/rules/Epilogue-Making_an_Appointment    0    15042753    85.681000    200
    Thanks for reviewing and assistance.

    Thanks for the reply Mamata,
    I am using the VOD service to stream videos. I found some code on the adobe site ( to work with playlist. I also use this code for launching individual movies (no playlist displayed). This playlist application uses a custom-made player.
    I observed a video play without any problems (no hesitation) and then checked the access log:
    session     connect     2010-05-24     12:24:42     3052          3073     3073     -      -     -     -     200     -
    stream     play     2010-05-24     12:24:42     3052          3295     3476     media_even t/Sharing_the_Road_with_Motorcycles_Bicycles_500_2pass     0     38782649     343.248000      200     -
    stream     stop     2010-05-24     12:24:42     3052          3397     211301     media_ev ent/Sharing_the_Road_with_Motorcycles_Bicycles_500_2pass     206987     38782649     343.2 48000     200     -
    stream     play     2010-05-24     12:24:42     3052          3397     211301     media_ev ent/Sharing_the_Road_with_Motorcycles_Bicycles_500_2pass     0     38782649     343.248000      200     -
    stream     stop     2010-05-24     12:24:42     3052          3397     217913     media_ev ent/Sharing_the_Road_with_Motorcycles_Bicycles_500_2pass     6368     38782649     343.248 000     200     -
    stream     play     2010-05-24     12:24:42     3052          3499     218199     media_ev ent/Sharing_the_Road_with_Motorcycles_Bicycles_500_2pass     0     38782649     343.248000      200     -

  • Extended format of access.log and log rotation

    I am using WebLogic Server 6.1sp1. I want to use extended format of web
    server access log. I also want to use log rotation based on date. But it
    seems not to work together. After my investigation I can say:
    - access.log in common format can be rotated based on date an on size,
    - access.log in extended format (either in its default form or
    completely redefined) cannot be rotated neither based on date nor size.
    In the second case at first time WebLogic tries to rotate logfile
    IOException is thrown with a message like " Failed
    to rename log file on attempt to rotate logs". Than it throws
    IOException with a message "Exception flushing HTTP log file. (Bad file
    descriptor)." when it tries to flush content of logfile to the disk.
    After that WebLogic server stops to write to access.log.
    Is it possible to rotate access.log in extended format?
    Andrzej Derlacki
    Infovide, Poland
    [email protected]
    [email protected]

    i am pasting the entries below which i see in the log( access_log ) . I don't see DEBUG in them.
    <AGENT_IP_ADDRESS> - - [29/Jun/2007:09:48:23 -0400] "GET /em/upload?ACTION=HEARTBEAT&EMD
    e0%2e0&X-ORCL-EMCV=10%2e2%2e0%2e1%2e0&X-ORCL-EMSV=10%2e2%2e0%2e1%2e0 HTTP/1.1" 2
    00 5
    <AGENT_IP_ADDRESS>- - [29/Jun/2007:09:48:23 -0400] "GET /em/upload?ACTION=HEARTBEAT&EM
    L-EMOV=4%2e0%2e0&X-ORCL-EMCV=10%2e2%2e0%2e1%2e0&X-ORCL-EMSV=10%2e2%2e0%2e1%2e0 H
    TTP/1.1" 200 5
    <AGENT_IP_ADDRESS> - - [29/Jun/2007:09:48:24 -0400] "GET /em/upload?ACTION=HEARTBEAT&E
    %2e0%2e0&X-ORCL-EMCV=10%2e2%2e0%2e1%2e0&X-ORCL-EMSV=10%2e2%2e0%2e1%2e0 HTTP/1.1"
    200 5

Maybe you are looking for

  • SMF service always shows offline even when it is up and running

    I have added a service to SMF under /var/svc/manifest/application and am successful in starting it, but state always shows offline. How can I get it to show up as "online"? Output of svcs -l command: bash-3.00# svcs -l esm fmri svc:/application/esm:d

  • Droid2 data usage jumps from zip to 100's of MB a week

    After seeing similar threads with sudden and unexplained data usage, I want to share my problem with one possible SOLUTION! I was alerted that my account was going over the 150mb limit. I checked online my usage and saw nothing, the usual flat line a

  • File size limintations

    I have a good many high resolution scans that exceed 10,000 pixels in one direction, as well as many asembled panoramas. Is there a chance of getting the maximum pixel dimension increased? 15,000 pixels would handle the 4 x 5's, but a panorama compos

  • Obtain info from nested table in function?

    Oracle9i 2000 I'd like to obtain an ID from a nested table object in order to insert it into an ID field (outside the nested table I'm getting it from). I've got a function that lets me get a foreign key ID from one other table ('ob

  • HT201250 My time machine keeps failing to backup due to space not available.

    I have a 500 gb external that I use for backups, but for some reason there is only 208gb available for backup. When I open up my time machine, I have deleted all  of my old backups. For some reason, I can not get at the other available space. Everyti