Permanently set /var/log/messages* to mode 644

What process constantly changes /var/log/messages* mode back to 640? I want to disable that. Thanks.

I would guess logrotate.  Have you checked /etc/logrotate.d/syslog?  Does it specify a particular permission there?
If not specified, logrotate should retain the permissions of the existing file.
Marc

Similar Messages

  • GG writing more info to /var/log/messages

    Dear All,
    Thank you very much for your continuous support .
    GG version: 11.2
    DB version: 11.2
    OS: OEL 5
    Am seeing log of info being writtent to /var/log/messages.
    AS per reference guide, i have used SYSLOG NONE parameter in GLOBALS file but still am seeing info is being written to /var/log/messages file.
    i have tried SYSLOG ERROR and SYSLOG ERROR, WARN
    but still GG is writing INFO messages to messages file.
    Could some one help me to resolve it.
    Thank you very much in advance
    Best Regards
    Vamshi

    There could be two reasons:
    1. You have to exit GGSCI and restart again for GLOBALS changes to take effect, which you may not have done.
    2. you might still be using SYSLOG in manager parameter file which overrides the GLOBALS setting as per the below explaination from Oracle.
    "You can use SYSLOG as a GLOBALS or Manager parameter, or both. When present in the GLOBALS parameter file, it controls message filtering for all of the Oracle GoldenGate processes on the system. When present in the Manager parameter file, it controls message filtering only for the Manager process. If used in both the GLOBALS and Manager parameter files, the Manager setting overrides the GLOBALS setting for the Manager process."

  • Redirecting Weblogic Logs to /var/log/messages

    Hi all,
    I've seen a few threads on here regarding this but they're all for older WLS versions.  I'm trying to get my server messages into /var/log/messages.
    I've seen and read a few posts about this and using log4j.  I've added the necessary jars to the domain/lib folder and created a log4j.properties file and its the latter part I think is the issue....
    I've tried adding it to the setDomain.sh CLASSPATH and the also to the servers classpath in the WLS Console, however I can't see any record of it getting picked up in the logs.
    The server is set to log4j and I've confirmed this using WLST.  Does anyone have any suggestions?
    Weblogic is version 11.1.1.7
    Thanks
    Dave

    There could be two reasons:
    1. You have to exit GGSCI and restart again for GLOBALS changes to take effect, which you may not have done.
    2. you might still be using SYSLOG in manager parameter file which overrides the GLOBALS setting as per the below explaination from Oracle.
    "You can use SYSLOG as a GLOBALS or Manager parameter, or both. When present in the GLOBALS parameter file, it controls message filtering for all of the Oracle GoldenGate processes on the system. When present in the Manager parameter file, it controls message filtering only for the Manager process. If used in both the GLOBALS and Manager parameter files, the Manager setting overrides the GLOBALS setting for the Manager process."

  • ERROR messages in /var/log/messages

    Hi,
    I encountered a error messages in /var/log/messages please find below
    Dec 9 04:03:08 drs syslogd 1.4.1: restart (remote reception).
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:10:46 drs rpc.mountd: authenticated unmount request from 10.3.141.26:651 for /opt/backup_log/srv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:657 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated unmount request from 10.3.141.26:672 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:677 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:12:01 drs rpc.mountd: authenticated unmount request from 10.3.141.26:849 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:13:20 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    and database (oracle 10g) is running fine, but i cant figure out what could be the problem, can anyone just help me out on this.
    Jafar

    Hi,
    #h1:35:respawn:/etc/init.d/init.cssd run >/dev/null 2>&1 </dev/null
    by commenting above line in initttab file would stop messaging, is this would have any adverse affect on the database. As its a production server, so i am really taking time to resolve it. Your suggestions are welcome. If there is no harm in commenting the above line then i would go forward to comment that line.
    Thanks
    Jafar>

  • Error Mesages in /var/log/messages

    Hi,
    Dec 9 04:03:08 drs syslogd 1.4.1: restart (remote reception).
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:10:46 drs rpc.mountd: authenticated unmount request from 10.3.141.26:651 for /opt/backup_log/srv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:657 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated unmount request from 10.3.141.26:672 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:677 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:12:01 drs rpc.mountd: authenticated unmount request from 10.3.141.26:849 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:13:20 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    I observed above mesages in /var/log/messages, can anyone tell what does it mean
    Version - oracle 10g
    Platform - Linux.
    Thanks
    Jafar

    Hi,
    #h1:35:respawn:/etc/init.d/init.cssd run >/dev/null 2>&1 </dev/null
    by commenting above line in initttab file would stop messaging, is this would have any adverse affect on the database. As its a production server, so i am really taking time to resolve it. Your suggestions are welcome. If there is no harm in commenting the above line then i would go forward to comment that line.
    Thanks
    Jafar

  • Strange error in /var/log/messages and /var/log/warn

    Hi,
    I get following error continuosly:
    kernel: sg_write: data in/out 404/404 bytes for SCSI command 0xd--guessing data in;
    kernel: program java not setting count and/or reply_len properly
    Any idea?
    Ty
    Bye

    Hi,
    #h1:35:respawn:/etc/init.d/init.cssd run >/dev/null 2>&1 </dev/null
    by commenting above line in initttab file would stop messaging, is this would have any adverse affect on the database. As its a production server, so i am really taking time to resolve it. Your suggestions are welcome. If there is no harm in commenting the above line then i would go forward to comment that line.
    Thanks
    Jafar>

  • Improve log messages

    Hi,
    How can I increase the number of events that are logged in /var/log/messages or /var/log/everything?
    I'd like to debug:
      - slow loading of Google Maps
      - wireless connection dropping
      - other issues
    but when I look at the logs there's nothing there. Is there a way to boost log writing? Like a really verbose debug mode for everything?
    Thanks.

    I don't think anything gets logged for browser issues, like google maps. Run the browser from a terminal, you might get some error output.
    Whenever I've had wireless issues, I see messages in everything.log, about "no probe response" and authentication/association timing out - it's been a while so I don't have the exact wording to hand.

  • Decoding a fire wall log message

    I need help decoding the following firewall log message:
    Stealth Mode connection attempt to TCP 192.168.1.97:50459 from 70.42.185.114:80
    Neither of these IP numbers belong to me (but mine is similar to the first).
    Why is my firewall showing a connection attempt to a different computer?

    Do not panic. That may be a more-or-less innocuous probe by, for example, a "web crawler" that's cataloging everything it can find on the internet. Think Google.
    In your Applications/Utilities folder is the +Network Utility+ app. Among many other things, you can look up IP addresses and, often, find out where it's located and/or registered to.

  • /var/adm/messages

    Hi,
    I am trying to get some info from google about the following messages in the /var/am/messages, but I don't get anything.
    ipfs: [ID 103742 kern.notice] /u06: memory limit of 10485760 exceeded
    ipfs: [ID 459658 kern.notice] /u06: active up normal - link stopping (managed)
    ipfs: [ID 859150 kern.notice] /u06: active down repair
    someone can give me some tips.
    I ll apreciate your help.

    That must be an old script .. the real one parse-log1.pl appears to be the one called. Its a more generic version.
    Its tied to the metric "Log File Pattern Matched Line Count".
    Enter "/var/log/messages", and perhaps ERROR in the pattern match, remove the "%" they are wrong and not needed.

  • /var/dam/messages empty

    I have solaris 10 (10/09) server.
    My /var/log/messages file is empty. I know that syslod is up. I have run /usr/sbin/syslogd -d and got the following output:
    main(1): Started at time Thu May 13 12:32:17 2010
    hnc_init(1): hostname cache configured 2037 entry ttl:1200
    getnets(1): found 1 addresses, they are: 0.0.0.0.2.2
    amiloghost(1): testing 129.237.3.241.2.2
    cfline(1): (*.err;kern.notice;auth.notice /dev/console)
    logerror(1): syslogd: line 12: unknown priority name "notice /dev/console"
    logerror_to_console(1): syslogd: line 12: unknown priority name "notice /dev/console"
    cfline(1): (*.alert root)
    logerror(1): syslogd: line 13: unknown priority name "alert root"
    logerror_to_console(1): syslogd: line 13: unknown priority name "alert root"
    cfline(1): (*.emerg *)
    logerror(1): syslogd: line 14: unknown priority name "emerg *"
    logerror_to_console(1): syslogd: line 14: unknown priority name "emerg *"
    cfline(1): (*.debug /var/adm/messages)
    logerror(1): syslogd: line 16: unknown priority name "debug /var/adm/messages"
    logerror_to_console(1): syslogd: line 16: unknown priority name "debug /var/adm/messages"
    syslogd: version 1.105
    Started: Thu May 13 12:32:17 2010
    Input message count: system 0, network 0
    # Outputs: 0
    ------------------------ priority = [file, facility] ------------------------
    0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1 2 2 2 2 2
    0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4
    Facilities:
    [00] kern: 0
    [01] user: 8
    [02] mail: 16
    [03] daemon: 24
    [04] auth: 32
    [05] security: 32
    [06] mark: 192
    [07] syslog: 40
    [08] lpr: 48
    [09] news: 56
    [10] uucp: 64
    [11] audit: 104
    [12] cron: 120
    [13] local0: 128
    [14] local1: 136
    [15] local2: 144
    [16] local3: 152
    [17] local4: 160
    [18] local5: 168
    [19] local6: 176
    [20] local7: 184
    Priorities:
    [00] panic: 0
    [01] emerg: 0
    [02] alert: 1
    [03] crit: 2
    [04] err: 3
    [05] error: 3
    [06] warn: 4
    [07] warning: 4
    [08] notice: 5
    [09] info: 6
    [10] debug: 7
    [11] none: 16
    Per File Statistics
    File Tot Dups Nofwd Errs
    logmsg(2): msg dispatcher started
    sys_poll(3): sys_thread started
    init(1): accepting messages from local system
    hostname_lookup(5): hostname_lookup started
    set_udp_buffer(1): allocate 262144 for fd 4
    init(1): accepting messages from remote
    init(1): syslogd: started
    main(1): off & running....
    net_poll(6): net_thread started
    ^Cmain(1): going down on signal 2
    logerror(1): syslogd: going down on signal 2
    delete_doorfiles(1): revoked door: DoorFd=6
    The same /etc/syslog.conf file didn't create any problems on another Solaris 10 server (5/08). /var/adm/messages* files are produced and when running syslogd -d I have below messages:
    main(1): Started at time Thu May 13 12:40:12 2010
    hnc_init(1): hostname cache configured 2037 entry ttl:1200
    getnets(1): found 1 addresses, they are: 0.0.0.0.2.2
    amiloghost(1): testing 129.237.3.80.2.2
    conf_init(1): I am loghost
    cfline(1): (*.err;kern.notice;auth.notice /dev/console)
    cfline(1): (*.alert root)
    cfline(1): (*.emerg *)
    cfline(1): (*.debug /var/adm/messages)
    syslogd: version 1.104
    Started: Thu May 13 12:40:12 2010
    Input message count: system 0, network 0
    # Outputs: 4
    ------------------------ priority = [file, facility] ------------------------
    0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1 2 2 2 2 2
    0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4
    5 3 3 3 5 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 X CONSOLE: /dev/console
    1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 X USERS: root
    0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 X WALL:
    7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 X FILE: /var/adm/messages
    Facilities:
    [00] kern: 0
    [01] user: 8
    [02] mail: 16
    [03] daemon: 24
    [04] auth: 32
    [05] security: 32
    [06] mark: 192
    [07] syslog: 40
    [08] lpr: 48
    [09] news: 56
    [10] uucp: 64
    [11] audit: 104
    [12] cron: 120
    [13] local0: 128
    [14] local1: 136
    [15] local2: 144
    [16] local3: 152
    [17] local4: 160
    [18] local5: 168
    [19] local6: 176
    [20] local7: 184
    Priorities:
    [00] panic: 0
    [01] emerg: 0
    [02] alert: 1
    [03] crit: 2
    [04] err: 3
    [05] error: 3
    [06] warn: 4
    [07] warning: 4
    [08] notice: 5
    [09] info: 6
    [10] debug: 7
    [11] none: 16
    Per File Statistics
    File Tot Dups Nofwd Errs
    /dev/console 0 0 0 0
    root 0 0 0 0
    WALL 0 0 0 0
    /var/adm/messages 0 0 0 0
    logmsg(6): msg dispatcher started
    writemsg(5): Logging msg 'May 13 12:40:12 sudo: [ID 702911 local2.notice] sbusse : TTY=pts/1 ; PWD=/var/adm ; USER=root ; COMMAND=/usr/sbin/syslogd -d' to FILE /var/adm/messages
    sys_poll(7): sys_thread started
    init(1): accepting messages from local system
    hostname_lookup(9): hostname_lookup started
    set_udp_buffer(1): allocate 262144 for fd 4
    init(1): accepting messages from remote
    net_poll(10): net_thread started
    init(1): syslogd: started
    main(1): off & running....
    ^Cmain(1): going down on signal 2
    logerror(1): syslogd: going down on signal 2
    writemsg(2): Logging msg 'syslogd: going down on signal 2' to CONSOLE /dev/console
    writemsg(5): Logging msg 'syslogd: going down on signal 2' to FILE /var/adm/messages
    delete_doorfiles(1): revoked door: DoorFd=8
    Please help. I need /var/adm/messages back. They existed to some point of time.
    Many thanks in advance.

    Sorry, it should be: /var/adm/messages not /var/dam/messages!
    Edited by: kuna_new on May 14, 2010 10:59 AM
    Resolved.
    Edited by: kuna_new on May 18, 2010 1:57 PM

  • Arch logging errors (/var/logs)

    i got two problems i'd like to solve maybe their cause is the same.
    first: is global arch logging. that's my ls -l of /var/log/
    -rw-r--r-- 1 root root      0   Apr 21 11:27 acpid.log
    -rw-r--r-- 1 root root      0   Apr  7 22:13 acpid.log.1
    -rw-r--r-- 1 root root      0   Apr 21 11:27 auth.log
    -rw-r--r-- 1 root root      0   Apr  7 22:14 auth.log.1
    -rw-r--r-- 1 root root   1092 Nov  7 02:52 boot
    -rw------- 1 root root   1152 Mar 17 08:06 btmp
    drwxr-xr-x 2 root root     72 Nov  7 16:56 ConsoleKit
    -rw-r--r-- 1 root root      0    Apr  7 22:14 crond
    -rw-r--r-- 1 root root      0    Apr 21 11:27 daemon.log
    -rw-r--r-- 1 root root      0    Apr  7 22:18 daemon.log.1
    -rw-r--r-- 1 root root  39494 Apr 22 13:18 dmesg.log
    -rw-r--r-- 1 root root      0    Apr 21 11:27 errors.log
    -rw-r--r-- 1 root root      0    Apr  7 22:18 errors.log.1
    -rw-r--r-- 1 root root      0    Apr 21 11:27 everything.log
    -rw-r--r-- 1 root root      0    Apr  7 22:18 everything.log.1
    -rw------- 1 root root  32032 Apr 22 12:03 faillog
    drwxrwx--T 2 root gdm    1392 Apr 22 13:18 gdm
    drwxr-xr-x 2 root root    368 Apr 21 11:27 httpd
    -rw-r--r-- 1 root root      0 Apr 21 11:27 kernel.log
    -rw-r--r-- 1 root root      0 Apr  7 22:19 kernel.log.1
    -rw-r--r-- 1 root root 292292 Apr 22 12:03 lastlog
    -rw-r--r-- 1 root root      0 Apr 21 11:27 messages.log
    -rw-r--r-- 1 root root      0 Apr  7 22:19 messages.log.1
    drwxr-xr-x 2 root root     48 Feb 26 06:56 old
    -rw-r--r-- 1 root root 151881 Apr 22 13:42 pacman.log
    -rw-r--r-- 1 root root     86 Apr 22 13:18 pm-powersave.log
    -rw-r--r-- 1 root root   6049 Apr 20 10:21 pm-suspend.log
    -rw-r--r-- 1 root root      0 Apr 21 11:27 syslog.log
    -rw-r--r-- 1 root root      0 Apr  7 22:19 syslog.log.1
    -rw-r--r-- 1 root root      0 Apr 21 11:27 user.log
    -rw-r--r-- 1 root root      0 Apr  7 22:19 user.log.1
    -rw-rw-r-- 1 root root 407424 Apr 22 13:29 wtmp
    -rw-rw-r-- 1 root root 415488 Apr  7 18:36 wtmp.1
    -rw-r--r-- 1 root root  13947 Apr 22 13:18 Xorg.0.log
    -rw-r--r-- 1 root root  14486 Apr 22 13:17 Xorg.0.log.old
    all files, that have dublicate name with .1 at the end, are always empty and as time goes by files with the same name but with .2, .3, .4 appear but also empty. It looks like arch is trying to create logs but something goes wrong and nothing is logged.
    second: i got errors from cron if i do run-cron /etc/cron.daily/ related to log files:
    sudo run-cron /etc/cron.daily/
    error: syslog-ng:1 duplicate log entry for /var/log/crond.log
    error: found error in /var/log/messages.log /var/log/auth.log /var/log/mail.log /var/log/kernel.log /var/log/errors.log /var/log/daemon.log /var/log/user.log /var/log/iptables.log /var/log/everything.log /var/log/syslog.log /var/log/acpid.log /var/log/crond.log /var/log/lpr.log /var/log/uucp.log /var/log/news.log /var/log/ppp.log /var/log/debug.log , skipping
    looks like the files r corrupted or something. please help find out the reasons and fix things up.

    I think it has to do with the group log having write permissions...
    # ls -l /var/log/
    total 8240
    drwxr-xr-x 2 root root 4096 Mar 31 01:38 ConsoleKit/
    drwxr-xr-x 2 root root 4096 Apr 4 03:52 httpd/
    drwxr-xr-x 2 http http 4096 Apr 18 03:45 lighttpd/
    drwxr-xr-x 2 root root 4096 Feb 25 23:56 old/
    -rw-r----- 1 root log 29283 Apr 22 11:05 auth.log
    -rw-r----- 1 root log 71395 Apr 18 03:26 auth.log.1
    -rw-r----- 1 root log 62225 Apr 11 03:17 auth.log.2
    -rw-r----- 1 root log 121945 Apr 4 03:41 auth.log.3
    -rw------- 1 root root 0 Mar 29 02:00 btmp
    -rw-r----- 1 root log 6622 Apr 22 09:17 crond.log
    -rw-r----- 1 root log 10756 Apr 18 03:45 crond.log.1
    -rw-r----- 1 root log 10340 Apr 11 03:45 crond.log.2
    -rw-r----- 1 root log 8809 Apr 4 03:45 crond.log.3
    -rw-r----- 1 root log 63451 Apr 22 11:01 daemon.log
    -rw-r----- 1 root log 101060 Apr 18 03:42 daemon.log.1
    -rw-r----- 1 root log 103755 Apr 11 03:37 daemon.log.2
    -rw-r----- 1 root log 72875 Apr 4 03:36 daemon.log.3
    -rw-r--r-- 1 root root 32631 Apr 19 03:27 dmesg.log
    -rw-r----- 1 root log 2881 Apr 21 23:22 errors.log
    -rw-r----- 1 root log 162980 Apr 17 09:55 errors.log.1
    -rw-r----- 1 root log 30491 Apr 9 21:54 errors.log.2
    -rw-r----- 1 root log 31213 Apr 3 18:38 errors.log.3
    -rw-r----- 1 root log 276636 Apr 22 11:01 everything.log
    -rw-r----- 1 root log 1196453 Apr 18 03:45 everything.log.1
    -rw-r----- 1 root log 374844 Apr 11 03:45 everything.log.2
    -rw-r----- 1 root log 610588 Apr 4 03:45 everything.log.3
    -rw------- 1 root root 24144 Apr 22 10:25 faillog
    -rw-r----- 1 root log 185643 Apr 22 10:25 kernel.log
    -rw-r----- 1 root log 1051728 Apr 18 02:02 kernel.log.1
    -rw-r----- 1 root log 250567 Apr 11 03:27 kernel.log.2
    -rw-r----- 1 root log 521352 Apr 3 18:38 kernel.log.3
    -rw-r--r-- 1 root root 293752 Apr 22 10:25 lastlog
    -rw-r----- 1 root log 229278 Apr 22 11:01 messages.log
    -rw-r----- 1 root log 959109 Apr 18 03:42 messages.log.1
    -rw-r----- 1 root log 309842 Apr 11 03:37 messages.log.2
    -rw-r----- 1 root log 489801 Apr 4 03:36 messages.log.3
    -rw-r--r-- 1 root root 77695 Apr 22 10:42 pacman.log
    -rw-r--r-- 1 root root 86 Apr 19 13:23 pm-powersave.log
    -rw-r----- 1 root log 825 Apr 19 03:27 syslog.log
    -rw-r----- 1 root log 1387 Apr 15 15:39 syslog.log.1
    -rw-r----- 1 root log 738 Apr 9 11:36 syslog.log.2
    -rw-r----- 1 root log 1600 Mar 31 00:02 syslog.log.3
    -rw-r----- 1 root log 16287 Apr 22 10:15 user.log
    -rw-r----- 1 root log 24546 Apr 17 03:45 user.log.1
    -rw-r----- 1 root log 626 Apr 11 03:27 user.log.2
    -rw-r----- 1 root log 416 Mar 30 04:12 user.log.3
    -rw-r----- 1 root log 6622 Apr 22 09:17 uucp.log
    -rw-r----- 1 root log 10756 Apr 18 03:45 uucp.log.1
    -rw-r----- 1 root log 10340 Apr 11 03:45 uucp.log.2
    -rw-r----- 1 root log 8809 Apr 4 03:45 uucp.log.3
    -rw-rw-r-- 1 root root 471552 Apr 22 10:25 wtmp
    -rw-r--r-- 1 root root 150528 Apr 1 03:21 wtmp.1
    -rw-r--r-- 1 root wheel 16308 Apr 22 10:25 Xorg.0.log
    -rw-r--r-- 1 root users 23624 Apr 22 10:25 Xorg.0.log.old
    Did you chown -R root:root /var/log on Apr 7?

  • ICal doesn't show delegation, and generates date and time error messages in /var/log/system.log

    I have a problem with my iCal, when I use my caldav account, I can only see my own calendar on my MBA, on my co-workers MBP it works fine with both my account and his. My co-worker can't see other calendars than his own when he uses iCal on my laptop.
    We can reproduce this problem on his computer by setting Location to Automatic rather than Amsterdam, then after deleting iCal's cache files, the caldav account and setting the Location back to Amsterdam solves the problem for him.
    It does not solve the problem for me (or several other co-workers). We've been looking at this for a few weeks, and we can not find any clear pattern why certain machines have this problem and others don't.
    All machines (both affected and unaffected) are running Mac OS 10.7.2 with iCal 5.0.1
    I've spoken to Apple support over the phone (in the Netherlands), unfortunately, they couldn't help with this.
    So far we've tried numerous location and language settings, but on affected machines nothing appears to solve the delegation problem (which we assume to be connected to the error messages iCal generates)
    Starting iCal yeilds the following error messages in /var/log/system.log:
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=3
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=10
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 iCal[23884]: Unexpected EOF, returning last token as fallback
    Jan  5 11:31:05 dhcp-91 iCal[23884]: VTIMEZONE does not match System Time Zone (Europe/Amsterdam) for 20100105T000000 to 20120105T000000: (
                  "interval: 2001-01-01 01:00:00 +0100, offset: 3600"
              ) != (
                  "interval: 2010-03-28 03:00:00 +0200, offset: 7200",
                  "interval: 2010-10-31 02:00:00 +0100, offset: 3600",
                  "interval: 2011-03-27 03:00:00 +0200, offset: 7200",
                  "interval: 2011-10-30 02:00:00 +0100, offset: 3600"
              BEGIN:VTIMEZONE
              X-LIC-LOCATION:Europe/Amsterdam
              TZID:Europe/Amsterdam
              BEGIN:DAYLIGHT
              TZOFFSETFROM:+0100
              TZNAME:CEST
              TZOFFSETTO:+0200
              DTSTART:19700329T020000
              END:DAYLIGHT
              BEGIN:STANDARD
              TZOFFSETFROM:+0200
              TZNAME:CET
              TZOFFSETTO:+0100
              DTSTART:19701025T030000
              END:STANDARD
              END:VTIMEZONE
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=3
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=10
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 iCal[23884]: Unexpected EOF, returning last token as fallback
    Jan  5 11:31:05 dhcp-91 iCal[23884]: VTIMEZONE does not match System Time Zone (Europe/Amsterdam) for 20100105T000000 to 20120105T000000: (
                  "interval: 2001-01-01 01:00:00 +0100, offset: 3600"
              ) != (
                  "interval: 2010-03-28 03:00:00 +0200, offset: 7200",
                  "interval: 2010-10-31 02:00:00 +0100, offset: 3600",
                  "interval: 2011-03-27 03:00:00 +0200, offset: 7200",
        "interval: 2011-10-30 02:00:00 +0100, offset: 3600"
              BEGIN:VTIMEZONE
              X-LIC-LOCATION:Europe/Amsterdam
              TZID:Europe/Amsterdam
              BEGIN:DAYLIGHT
              TZOFFSETFROM:+0100
              TZNAME:CEST
              TZOFFSETTO:+0200
              DTSTART:19700329T020000
              END:DAYLIGHT
              BEGIN:STANDARD
              TZOFFSETFROM:+0200
              TZNAME:CET
              TZOFFSETTO:+0100
              DTSTART:19701025T030000
              END:STANDARD
              END:VTIMEZONE
    And when I close iCal I get:
    Jan  5 11:33:25 dhcp-91 [0x0-0x592592].com.apple.iCal[23894]: token mismatch: 4 != 5

    I'm seeing the same thing, and I can't even find where OS X stores calendars on disk anymore...

  • Normal Startup Messages (System.log; Intel Verbose Mode)?

    Over this past weekend, I wanted to test the backup I had for my 24" iMac. I had always used Apple's Backup program that comes with .Mac when I had my PowerBook, and never tested it. This was bad, because it didn't work when I actually needed it.
    I also suspected there might be something slightly wrong with my iMac, so equipped with about 4 hours and my install DVDs i went to work.
    The only thing I've done so far is get all the Apple updates and setup my iChat account. I changed to boot in verbose mode, and found that the eery messages that scared me prior to doing my reinstallation of OS X (I zeroed the drive, then did a full install) were still there.
    Here is my entire System.log:
    Jan 30 09:22:35 mike-barcas-computer sudo: Mike : TTY=ttyp1 ; PWD=/Users/Mike ; USER=root ; COMMAND=/usr/sbin/nvram boot-args=-v
    Jan 30 09:22:48 mike-barcas-computer shutdown: reboot by Mike:
    Jan 30 09:22:48 mike-barcas-computer SystemStarter[279]: authentication service (287) did not complete successfully
    Jan 30 09:22:48 mike-barcas-computer kernel[0]: (295: ps)tfp: failed on 0:
    Jan 30 09:22:48 mike-barcas-computer kernel[0]: (295: ps)tfp: failed on 0:
    Jan 30 09:22:48 mike-barcas-computer kernel[0]: (295: ps)tfp: failed on 0:
    Jan 30 09:22:49 mike-barcas-computer kernel[0]: (322: ps)tfp: failed on 0:
    Jan 30 09:22:49 mike-barcas-computer SystemStarter[279]: The following StartupItems failed to properly start:
    Jan 30 09:22:49 mike-barcas-computer kernel[0]: (322: ps)tfp: failed on 0:
    Jan 30 09:22:49 mike-barcas-computer SystemStarter[279]: /System/Library/StartupItems/AuthServer
    Jan 30 09:22:49 mike-barcas-computer kernel[0]: (323: ps)tfp: failed on 0:
    Jan 30 09:22:49 mike-barcas-computer SystemStarter[279]: - execution of Startup script failed
    Jan 30 09:23:08 localhost kernel[0]: hi mem tramps at 0xffe00000
    Jan 30 09:23:08 localhost kernel[0]: PAE enabled
    Jan 30 09:23:08 localhost kernel[0]: 64 bit mode enabled
    Jan 30 09:23:08 localhost kernel[0]: standard timeslicing quantum is 10000 us
    Jan 30 09:23:08 localhost kernel[0]: vmpagebootstrap: 512343 free pages
    Jan 30 09:23:08 localhost kernel[0]: migtable_maxdispl = 71
    Jan 30 09:23:08 localhost kernel[0]: Enabling XMM register save/restore and SSE/SSE2 opcodes
    Jan 30 09:23:08 localhost kernel[0]: 80 prelinked modules
    Jan 30 09:23:08 localhost kernel[0]: ACPI CA 20060421
    Jan 30 09:23:08 localhost kernel[0]: AppleIntelCPUPowerManagement: ready
    Jan 30 09:23:08 localhost kernel[0]: AppleACPICPU: ProcessorApicId=0 LocalApicId=0 Enabled
    Jan 30 09:23:08 localhost kernel[0]: AppleACPICPU: ProcessorApicId=1 LocalApicId=1 Enabled
    Jan 30 09:23:08 localhost kernel[0]: Copyright (c) 1982, 1986, 1989, 1991, 1993
    Jan 30 09:23:08 localhost kernel[0]: The Regents of the University of California. All rights reserved.
    Jan 30 09:23:08 localhost kernel[0]: using 10485 buffer headers and 4096 cluster IO buffer headers
    Jan 30 09:23:08 localhost kernel[0]: Enabling XMM register save/restore and SSE/SSE2 opcodes
    Jan 30 09:23:08 localhost kernel[0]: Started CPU 01
    Jan 30 09:23:08 localhost kernel[0]: IOAPIC: Version 0x20 Vectors 64:87
    Jan 30 09:23:08 localhost kernel[0]: ACPI: System State [S0 S3 S4 S5] (S3)
    Jan 30 09:23:08 localhost kernel[0]: Security auditing service present
    Jan 30 09:23:08 localhost kernel[0]: BSM auditing present
    Jan 30 09:23:08 localhost kernel[0]: disabled
    Jan 30 09:23:08 localhost kernel[0]: rooting via boot-uuid from /chosen: 771A8047-7B26-48DC-ABB6-89E46168EE40
    Jan 30 09:23:08 localhost kernel[0]: Waiting on <dict ID="0"><key>IOProviderClass</key><string ID="1">IOResources</string><key>IOResourceMatch</key><string ID="2">boot-uuid-media</string></dict>
    Jan 30 09:23:08 localhost kernel[0]: USB caused wake event (EHCI)
    Jan 30 09:23:08 localhost kernel[0]: FireWire (OHCI) TI ID 8025 built-in now active, GUID 0017f2fffe6db760; max speed s800.
    Jan 30 09:23:08 localhost kernel[0]: Got boot device = IOService:/AppleACPIPlatformExpert/PCI0@0/AppleACPIPCI/SATA@1F,2/AppleAHCI/PRT2 @2/IOAHCIDevice@0/AppleAHCIDiskDriver/IOAHCIBlockStorageDevice/IOBlockStorageDri ver/ST3500641AS Q Media/IOGUIDPartitionScheme/AppleHFS_Untitled2@2
    Jan 30 09:23:08 localhost kernel[0]: BSD root: disk0s2, major 14, minor 2
    Jan 30 09:23:08 localhost kernel[0]: CSRHIDTransitionDriver::probe: -v
    Jan 30 09:23:08 localhost kernel[0]: CSRHIDTransitionDriver::start before command
    Jan 30 09:23:08 localhost kernel[0]: CSRHIDTransitionDriver::stop
    Jan 30 09:23:08 localhost kernel[0]: IOBluetoothHCIController::start Idle Timer Stopped
    Jan 30 09:23:08 localhost kernel[0]: Jettisoning kernel linker.
    Jan 30 09:23:08 localhost kernel[0]: Resetting IOCatalogue.
    Jan 30 09:23:08 localhost kernel[0]: GFX0: family specific matching fails
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 1
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 2
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 2
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 2
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 2
    Jan 30 09:23:08 localhost kernel[0]: Matching service count = 2
    Jan 30 09:23:08 localhost kernel[0]: NVDANV40HAL loaded and registered.
    Jan 30 09:23:08 localhost kernel[0]: GFX0: family specific matching fails
    Jan 30 09:23:08 localhost kernel[0]: wl0: Broadcom BCM4328 802.11 Wireless Controller
    Jan 30 09:23:08 localhost kernel[0]: 4.80.76.0Previous Shutdown Cause: 3
    Jan 30 09:23:08 localhost memberd[38]: memberd starting up
    Jan 30 09:23:08 localhost mDNSResponder-108.2 (Aug 25 2006 14: 50:48)[31]: starting
    Jan 30 09:23:10 localhost lookupd[44]: lookupd (version 369.6) starting - Tue Jan 30 09:23:10 2007
    Jan 30 09:23:13 localhost diskarbitrationd[37]: disk0s2 hfs 8AAF2196-1366-34AB-B7BC-3D96F131E9AD Macintosh HD /
    Jan 30 09:23:13 localhost DirectoryService[43]: Launched version 2.1 (v353.5)
    Jan 30 09:23:13 localhost kernel[0]: yukonosx: Ethernet address 00:16:cb:9e:39:58
    Jan 30 09:23:13 localhost kernel[0]: AirPort_Brcm43xx: Ethernet address 00:17:f2:99:63:9d
    Jan 30 09:23:13 localhost lookupd[56]: lookupd (version 369.6) starting - Tue Jan 30 09:23:13 2007
    Jan 30 09:23:14 mike-barcas-computer configd[35]: setting hostname to "mike-barcas-computer.local"
    Jan 30 09:23:14 mike-barcas-computer kernel[0]: Registering For 802.11 Events
    Jan 30 09:23:14 mike-barcas-computer /System/Library/CoreServices/loginwindow.app/Contents/MacOS/loginwindow: Login Window Application Started
    Jan 30 09:23:14 mike-barcas-computer kernel[0]: [HCIController][setupHardware] AFH Is Supported
    Jan 30 09:23:16 mike-barcas-computer mDNSResponder: Adding browse domain local.
    Jan 30 09:23:16 mike-barcas-computer loginwindow[50]: Login Window Started Security Agent
    Jan 30 09:23:17 mike-barcas-computer kernel[0]: SetCryptoKey T: len 16, idx 0
    Jan 30 09:23:17 mike-barcas-computer kernel[0]: SetCryptoKey R: len 16, idx 1
    Jan 30 09:23:17 mike-barcas-computer /System/Library/PrivateFrameworks/Apple80211.framework/Resources/airport: Currently connected to network Ferrari
    Jan 30 09:23:20 mike-barcas-computer configd[35]: executing /System/Library/SystemConfiguration/Kicker.bundle/Contents/Resources/enable-net work
    Jan 30 09:23:20 mike-barcas-computer configd[35]: posting notification com.apple.system.config.network_change
    Jan 30 09:23:20 mike-barcas-computer lookupd[88]: lookupd (version 369.6) starting - Tue Jan 30 09:23:20 2007
    Jan 30 09:23:20 mike-barcas-computer ntpdate[126]: no servers can be used, exiting
    Jan 30 09:23:21 mike-barcas-computer configd[35]: target=enable-network: disabled
    The lines that concern me are the ones bolded at the top of System.log
    The other thing that is a bit unnerving to me is that when I have it set to boot in verbose mode, and then restart the computer, I get a screen that looks out of place. It is a box with a dark background in the center of the screen with text in there, and then it quickly switches to full screen verbose mode. The first line of full screen verbose mode (which is what I'm used to since I always used verbose mode on my PowerBook) is this one:
    Jan 30 09:23:08 localhost kernel[0]: hi mem tramps at 0xffe00000
    In the centered text, it mentions something about "loading drivers" followed by many lines of periods. It is only up for about 5 seconds, and then switches to full screen verbose mode. Is that centered window for verbose mode new to intel Macs? I never recall seeing it on my PowerBook.
    When i googled around for the "hi mem tramps" message, i found it might be linked to bad ram. I used memtest and did 3 passes to check the ram, and it found no errors.
    Are these messages in System.log normal?
    Thanks!

    Hi, Mike.
    First, please don't use the "scatter gun" or "post everywhere" approach. I see you've also post the same question here. I appreciate your urgent desire for help, but it would be very annoying to anyone answering questions here to spend time researching your question in one post, only to find it already answered in another place where it was also posted. The "scatter gun" approach is a good way to get all your future posts ignored.
    According to what I read in the second post of this topic on another forum, I suspect you may have a Startup Item that's causing the highlighted messages to be written to system.log. Perhaps some PowerPC code you may have migrated over to your Intel-based Mac if you used the Setup / Migration Assistant to move to the new Mac from a pervious Mac.
    There have been numerous posts about the tfp: failed on 0 message, which can be seen in this search of the Discussions. However, I suspect the explanation I've cited above fits your situation.
    If an errant Startup Item is the cause, my "Troubleshooting Startup and Login Items" FAQ can help you pin that down if such an item is causing the problem.
    As to hi mem tramps…, that may be normal. If you read this item and click on the link for dmesg you'll see a typical output someone else posted as, I suspect, an example of "normal."
    Good luck!
    Dr. Smoke
    Author: Troubleshooting Mac® OS X
    Note: The information provided in the link(s) above is freely available. However, because I own The X Lab™, a commercial Web site to which some of these links point, the Apple Discussions Terms of Use require I include the following disclosure statement with this post:
    I may receive some form of compensation, financial or otherwise, from my recommendation or link.

  • Every time I start iTunes I get the message: "iTunes exec has been set to run in compatability mode for an older version of Windows. Turn off compatability mode for iTunes before you open it." How do I turn off the compatability mode?

    Every time I start iTunes I get the message: "iTunes exec has been set to run in compatability mode for an older version of Windows. Turn off compatability mode for iTunes before you open it." How do I turn off the compatability mode? Particularly when I have to do it before I turn on iTunes.

    Try the following document, only be sure that none of the boxes in the compatibility mode tab are checked (not just the compatibility mode box itself):
    iTunes for Windows: How to turn off Compatibility Mode

  • Getting error message that states itunesexe has been set to run in compatibilty mode for an older versions of windows for best results turn off compatibility mode for itunes before you open it .How do i turn off compatibility mode?

    recieved error message that states" itunes exe has been set to run in compatibility mode for an older versions of windows for best results turn off compatibility mode for itunes before you open it. How do i access compatibility mode and turn it off ? Believe i have Windows 7.

    Try the following document, only be sure that none of the boxes in the compatibility tab are checked (not just the compatibility mode box itself): 
    iTunes for Windows: How to turn off Compatibility Mode

Maybe you are looking for

  • Installation failed on Windows 7 platform

    I am attempting to install Oracle Enterprise edition on a Windows 7 32 bit platform. During the installation, several errors are displayed stating that certain files could not be found within the installation directory. So I continued from these erro

  • Word report with ActiveX

    I would like to generate a report in Word via ActiveX. I found an example on NI's site that should make it fairly easy. However, I noticed that some of Word's ActiveX methods parameters have changed between whichever version the example was written w

  • Connecting my samsung jet s8000 to btfon

    can anybody tell me how to connect my mobile phone to btfon/openzone when on the move outside of my home. thank you. i have no trouble connecting to my bt homehub while i am at home.

  • 2602i lightweight to autonomous issue

    I currently have a 2602i access point that I need to load autonomous image ap3g2-k9w7-tar.153-3.JAA.tar on to, with no WLC. I have already tried the steps from the following links... http://www.cisco.com/c/en/us/td/docs/wireless/access_point/conversi

  • Query name

    Hi, what is the name of query,if we write it before from clause . Example 1.select empno,ename ,(select sal as sal from emp a1 where a2.empno=a1.empno ) from emp a2;