Syslog clarification LMS3.2

Hi All,
I need some clarification about the syslog.
1) Syslog is enabled in LM3.2 installation time. where the log files are stored?
2) Syslog configuration is in which module?
3) Enabled the logging configuration int he switches, but i am nott getting the logs in the syslog .
Kindly advice how to enable syslog setting in the LMS.

1. If you have logging buffered enable (and it is by default), then messages will be seen in the "show log" output on the device.  The number of messages kept in this buffer depends on the size.  Typically this is 4096 bytes, but it can be increased with the "logging buffered" config command.
2. No.  LMS receives the syslog messages at the same time the logging buffer does.  LMS will only look at the syslog messages it sees in the syslog message file on the LMS server (NMSROOT/log/syslog.log on Windows).  When a messages shows up there, it will be read by the SyslogCollector daemon.  The SyslogCollector daemon will perform any required filtering on the message, then pass all unfiltered messages to the SyslogAnalyzer.  The SyslogAnalyzer will run any configured Automated Actions, and insert the message into the RME database.  Only then will you be able to run reports and see the message.
Please support CSC Helps Haiti
https://supportforums.cisco.com/docs/DOC-8895
https://supportforums.cisco.com

Similar Messages

  • LMS3.2 Syslog reports very slow when send via email

    Hello,
    we have ~5000 devices in LMS3.2 and we have a problem with syslog reports.
    When I create a "severity level summary report" for 5000 devices for the last 24hours and select as run type "immediate" it needs ~2-3 minutes. That's ok.
    But when I create exactly the same report and select the run type "once" , it needs ~3 hours. ("Once" means that the report is send via email after it's finished).  It happens with report type "pdf" and "csv".
    What can be the problem ?  Or is it usual ???
    Regards
    Hendrik

    The scheduled reports can output a full list of messages where as the immediate reports output a limit of 10,000 records.  If you have a lot of syslog messages, it can take a considerable amount of additional time to generate a full report.

  • RME 4.3.1 on new server - 2 issues with Inventory and syslog

    Hi,
    I recently installed new server 2003 with LMS3.2 and after the problems with DevicePackages i resubmitted all device and the device center tasks that was missing now reappeared.
    So I went on and added my two VPN3030 VPN Concentrators.
    This device is supported for RME inventory and syslog
    I got the config-archive running (!) so thats fine (Runs via HTTPS login)
    I have two issues:
    1. I can not get inventory to work .
    I have communication going, and a packet trace/sniff show I have syslog going into RME and i see SNMP GET and respones to/from device
    I see some java error logs in ic_server.log fil
    I have tried with two different LMS32-servers
    I have increased SNMP timeout etc
    I tried deleted the device and rediscover
    log are like this:
    [ Thu Aug 19  10:12:30 CEST 2010 ],ERROR,[Thread-14],com.cisco.nm.rmeng.inventory.ics.core.CollectionController,761, Collection failed for the device : 3748
    com.cisco.nm.xms.xdi.ags.system.CollectionFailed: com.cisco.nm.lib.snmp.lib.SnmpException: SnmpResponseNoSuchName on 10.3.6.2 while performing SnmpWalk(*) at index = 10
        at com.cisco.nm.xms.xdi.pkgs.LibInventory.PortInterfaceAGI_RFC1213_HelperMethods.getIfTableEntriesFromDevice(PortInterfaceAGI_RFC1213_HelperMethods.java:639)
        at com.cisco.nm.xms.xdi.pkgs.SharedInventoryVPN3000.PortInterfaceAGI_RFC1213_Mib.g$eval(PortInterfaceAGI_RFC1213_Mib.java:77)
        at com.cisco.nm.xms.xdi.ags.PortInterfaceAGI.g$eval(PortInterfaceAGI.java:21)
        at com.cisco.nm.xms.xdi.SdiEngine.initAndEvalAGIs(SdiEngine.java:383)
        at com.cisco.nm.xms.xdi.SdiEngine.request(SdiEngine.java:309)
        at com.cisco.nm.xms.xdi.SdiEngine.getDevRepr(SdiEngine.java:302)
        at com.cisco.nm.rmeng.inventory.ics.core.CollectionController.run(CollectionController.java:539)
        at java.lang.Thread.run(Thread.java:595)
    [ Thu Aug 19  10:12:30 CEST 2010 ],INFO ,[Thread-14],com.cisco.nm.rmeng.inventory.ics.core.CollectionController,841,Device collection failed for 10.3.6.2
    2.:I can not get syslog into the devices syslog reports
    This is wierder than issue 1: I have two VPN3030, one actually does syslog fine, but one VPN 3030 does not
    I havent done any thing different for the two device ...
    one simply works, one doesnt ...
    I get no syslog msg in device center for one of the device.
    The syslogs ARE infact in the syslog.log
    The syslog msg DO show up, but in Unexpected device report  ...
    The same VPN device does work with my second server so I think this is related to RME database on one specific server.
    But i have tried delete device and rediscover etc ...
    please help ...

    ok - looks like i need TAC again ...
    As for the syslog issue - this happens only for one device on one of my servers ...
    That is what is strange ... So IP is coorect and ok - (they do get syslogs into DevCenter on one server and on other device)
    Thank you for your reply - really nice that you take your time into this forum !

  • LMS3.2 Log rotation problem

    Hi,
    we use LMS3.2 (windows single-server)  for ~4500 devices and have a problem with log rotation.
    That's our configured log roation:
    Name with location
    Size (kb)
    Format
    No.of Backups
    1.
    D:\CSCOpx\log\dcrclient.log
    102400
    gz
    3
    2.
    D:\CSCOpx\log\ICServer.log
    102400
    gz
    3
    3.
    D:\CSCOpx\log\syslog.log
    1024000
    gz
    5
    The backup directory is the same as the usual log directory. The size of the 3 files is already bigger than the configured size in log roation, see:
    dcrclient.log     2,1 GB
    ICServer.log     1,1 GB
    syslog.log        9,7 GB
    After the log roation configuration we restarted the daemon manager, but it's not working. There are no backup files created and the 3 files are still growing.
    Regards
    Hendrik

    After you configure the log rotation you need and restart the daemons, you need to schedule the job. The schedule buttong is available under
    Common Services -> Server -> Admin -> Log Rotation.

  • No syslog on device center

    Hi all,
    I have test for the ws-c2960s-tc-l to unplug the cable, it can see the syslog in device center. however when i test for cisco3945 to unplug the UTP cable. it doen't show any message on device center. I can see the syslog from the log/syslog.log. why cann't it be seem by the device center. anyone had  the problem before and can give me some advice. thanks. the RME , common service, ciscoview already update.
    Mike

    I am installed the LMS3.2 version and firstly I found that it is not support for the device of the new equipment(cisco3945,cisco2901,ws-c2960s-tc-l.etc)
    then I use the common service--->device update to update the RME,ciscoview, and also common service. after that, it can select the new equipment from common service---->device management. then I add the device of cisco 3945 and ws-c2960s-tc-l for test, however, it only have the log for 2960 but not cisco3945 from the device center.
    when I generate a 24 hour report for syslog on cisco3945 , there have no any log, but if I generate a for example 12-sep-10 to 12-sep-10 report , it can so the syslog for the past 24 hour.

  • Can I and then how do I subscribe my LMS 4.02 to my LMS 3.2 syslog collector?

    We are migrating to LMS 4.0.2, but our syslogs are curerently being sent to our LMS 3.2 server.  Can I subscribe to our LMS3.2 syslog collector?  Or

    read this:
    http://support.apple.com/kb/HT2109

  • Syslog to another server

    I want to forward syslog messages that I recieve in my Cisco Works server to another server,what is the best way to accomplish this. I'm runing LMS3.2 on Solaris 10.

    RME 4.3 in LMS 3.2 also has the option to select "script" as the action type of the automated action. So this should work as well:
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_resource_manager_essentials/4.3/user/guide/syslog.html#wp1211314
    here are other threads to this topic:
    https://supportforums.cisco.com/thread/2099748
    https://supportforums.cisco.com/thread/2030834
    there was also a bug with AA in RME 4.3:
    http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&method=fetchBugDetails&bugId=CSCtc18888
    and a patch was available by contacting TAC

  • Domain Guideance and Clarification using SVN and an Export suggestion

    Hello Oracle SQL Data Modeler Support,
    Apologies if this has been documented somehwere and I have missed reading it, but have gone through the User Guide and cannot find the clarification I want regarding domains.
    1) WHAT IS BEST PRACTICE TO SAVE WHEN USING SVN
    From the forum I have picked up that the domains file is in the following directory:
    ~\datamodeler\datamodeler\types
    File name is 'defaultdomains.xml'
    When I come to save the file using SVN I get 'Choose versioned folder for storing system types'
    I assume this is where the domains file is stored.
    I require the Domains to be avialable centrally to all Designs I create, what should I do?
    a) Set the folder to ~\datamodeler\datamodeler\types
    b) Create a design called 'Domains' and store it in this folder
    c) Any thing you may suggest
    2) EXPORT OF DOMAIN FILE SUGGESTION
    This should be a quick win for you, can you please add an Export Domains function, seems this needs to do no more than make a copy of the defaultdomains.xml file and create it in a specified export directory.
    Will avoid having to go through the forum to pick up that the defaultdomains.xml file needs to be copied and transfered over for new SQL Data Modeler installations.

    Hello,
    I require the Domains to be avialable centrally to all Designs I create, what should I do?Default location is fine if SVN is not used and if all designs are used only on that computer.
    If versioning is used then it's better to have separate directory for domains and this directory shouldn't be part of any design's directory - i.e. for designs you can have directories c:\des_1, c:\des_2 ...c:\des_n - one directory per each design and that directory will contain design DMD file and design folder. For domains you can have directory c:\DM_Sys_types and you need to set this directory in "Tools>Preferences>Data Modeler>system types directory" - logical types, RDBMS sites and scripts also will be stored there.
    Philip

  • How to log successful logins to a syslog server in NX-OS

    Does anyone know how to do this in NX-OS?  I do it in IOS with the following commands:
    login on-failure log
    login on-success log
    logging x.x.x.x
    With that I get a syslog message that I can then log to a file to track who has logged into which device and when.  But I can't find the syntax to do the same thing in the Nexus switches that we have.  Does anyone know what the equivalent commands are?
    Thanks,
    Ben

    Hi Ben,
    By default, failed logins are logged.
    You can checked the log using:
    show logging logfile | last 15
    and for every logging failed (by default) you will get something like this:
    2012 Dec 18 14:51:08 Nexus5010-B %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication
    failed for user en from 2.2.2.1 - login
    To get the success-login to show up in the logs we need to increase the level of the authpriv to 5 (it is 3 by default), and doing this will add a new log for failed or succesful connections.
    Use the following command:
    Nexus5010-A(config)# logging level authpriv 5
    You can check loggin levels by using:
    #show logging level
    After you do this with the logging level you will see in the log something like this when a succesful login takes place:
    2005 Jan  6 03:29:48 Nexus5010-A %AUTHPRIV-5-SYSTEM_MSG:    admin :TTY=unknown
    ; PWD=/var/sysmgr/vsh ; USER=root ; COMMAND=/usr/bin/strings/proc/18340/environ
    - sudo
    Now for a failed login and after increasing the authpriv level you will see the following logs:
    2005 Jan  6 03:31:36 Nexus5010-A %AUTHPRIV-4-SYSTEM_MSG: pam_unix(aaa:auth):check pass; user unknown - aaad
    2005 Jan  6 03:31:36 Nexus5010-A %AUTHPRIV-5-SYSTEM_MSG: pam_unix(aaa:auth):
    aut
    hentication failure; logname= uid=0 euid=0 tty= ruser= rhost=  - aaad
    For logging *****
    Nexus7018(config)# logging ?
      console           Set console logging
      event             Interface events
      ip                IP configuration
      level             Facility parameter for syslog messages
      logfile           Set File logging
      message           Interface events
      module            Set module(linecard) logging
      monitor           Set terminal line(monitor) logging level
      origin-id         Enable origin information for Remote Syslog Server
      server            Enable forwarding to Remote Syslog Server
      source-interface  Enable Source-Interface for Remote Syslog Server
      timestamp         Set logging timestamp granularity
    You can use logging source-interface ....
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ****

  • BI Java Installation: Clarification Needed!

    I'm wondering if someone could help clear this up for me:
    We have installed NW2004s SPS08 on Solaris with only the usage type EP (AS Java/EP). Awhile back I was tasked with connecting our BW ABAP system to our Portal ("Integration into the Portal" - transaction SPRO etc).
    After starting this task I noticed I was missing things that the instructions were telling me to configure; i.e. Items that were related to BI that weren't in the Portal such as certain roles, the BI Repository Manager etc.
    Reading around, it seemed like I need to install the BI usage type.
    I have now been tasked with another installation of the Portal (NW2004s SR1 this time), but am trying to head off the problems I'm experiencing trying to connect the Portal to our BW ABAP system. This will be a Java only installation. I've read that BI-Java requires EP and AS Java, and that if I install the BI-Java usage type, EP and AS-Java will be installed automatically.
    My question is, if I do the BI-Java installation and it automatically installs EP/AS-Java, will the Portal still act the same way as it does in my EP/AS-Java only installation I already have? We have many plans to use the Portal as an entry point for all of our backend systems, so if the Portal's capabilities are not what we see already (in our first installation of just EP/AS-Java) then we will have problems.
    Any clarification is greatly appreciated and I will award points accordingly.
    THANKS!
    Beau.

    I think that's what I needed to know.
    I was actually wondering about DI as well. Our developers are having problems deploying .EAR files to our original EP-only install. They can deploy .PAR files with no problems, but .EAR files always error out. Maybe having DI will solve this problem as well? I'm a little concerned about the hardware capacity of this box with having BI, EP and DI all installed on it. I had contacted SAP about installing DI a while back and basically they had told me to install it on a seperate server, by itself. We're running a Sun Enterprise 420R, 4G of memory and a 450 mhz processor for this new installation. Do you think this box is capable of handle EP, BI and DI (AS-JAVA)?
    Thanks for your help!

  • Clarifications in Asset Accounting

    Dear Experts,
    Please clarify below questions.
    1) What is the difference between Depreciation Area and Depreciation Key?
    2) What is the importance of Recalculate value button in Asset Accounting?
    3) Suppose I have 1000 assets, if I want to run depreciation only for 200 assets how can I do that?
    4) If suppose I have 5 Depreciation areas, I am able to see the book depreciation values only, where I
        can see the other depreciation values? If we can’t see for which purpose we are using other
        depreciation areas?
    5) Vendor and Customer balances get update regularly or once in a month or year?
    6) Where we have to create number ranges either in Production or Development Environment?
    7) How can we transfer GLs from one environment to another?
    Full points will be assigned as way of thanks
    Regards,
    Vineela

    Hi Krishna,
    Thanks for your reply,But still I need some more clarifications please respond........
    2) What is the importance of Recalculate value button in Asset Accounting?-
    (A)recalculates depr when asset parameters are changed
    Where it will be there as it(recalculate button) is not there in AFAB
    3) Suppose I have 1000 assets, if I want to run depreciation only for 200 assets how can I do that?
    (A)select those 200 and run depreciation
    Here Assets Selection option is there only in test run not there in update run.
    4) If suppose I have 5 Depreciation areas, I am able to see the book depreciation values only, where I can see the other depreciation values? If we can’t see for which purpose we are using other depreciation areas? (A)use AW01N- you cans ee all dep areas
    In AW01N only book depreciation values is displayed,how can I see other depreciation area values
    Regards
    Vineela
    Edited by: Vineela Siri on Apr 9, 2008 7:22 AM

  • Can't get syslog to work

    I have been trying to get syslog to work to accept logging from my router (which is directed to syslog to the IP address of my primary Mac), but with no success.
    I've gone through Aaron Adams' procedures:
    http://www.aaronadams.net/index.php/2005/06/02/configuringsyslogd_to_accept_logsfrom
    I've edited my /etc/syslog.conf file:
    .err;kern.;auth.notice;authpriv,remoteauth,install.none;mail.crit /dev/console
    *.notice;authpriv,remoteauth,ftp,install.none;kern.debug;mail.criti /var/log/system.log
    # COMMENT this out for now to see any local4 messages on system log?
    # ;local4.none
    # Send messages normally sent to the console also to the serial port.
    # To stop messages from being sent out the serial port, comment out this line.
    #.err;kern.;auth.notice;authpriv,remoteauth.none;mail.crit /dev/tty.serial
    # The authpriv log file should be restricted access; these
    # messages shouldn't go to terminals or publically-readable
    # files.
    authpriv.*;remoteauth.crit /var/log/secure.log
    lpr.info /var/log/lpr.log
    mail.* /var/log/mail.log
    ftp.* /var/log/ftp.log
    netinfo.err /var/log/netinfo.log
    install.* /var/log/install.log
    install.* @127.0.0.1:32376
    local0.* /var/log/ipfw.log
    *.emerg *
    local0.* /var/log/Airport.log
    local4.* /var/log/local4.log
    # DEBUG: what happens on the other local facilities?
    local1.* /var/log/local1.log
    local2.* /var/log/local2.log
    local3.* /var/log/local3.log
    local5.* /var/log/local5.log
    local6.* /var/log/local6.log
    local7.* /var/log/local7.log
    I've re-loaded /System/Library/LaunchDaemons/com.apple.syslogd.plist, and edited /etc/daily.local, and those mechanisms are working, but always local4.log is an empty file. Empty log files exist in /var/log:
    $ ls -al /var/log | grep "local"
    -rw-r--r-- 1 root wheel 0 Dec 11 11:56 local1.log
    -rw-r--r-- 1 root wheel 41975 Mar 16 16:38 local2.log
    -rw-r--r-- 1 root wheel 0 Dec 11 11:56 local3.log
    -rw-r--r-- 1 root wheel 0 Mar 20 03:15 local4.log
    -rw-r--r-- 1 root wheel 0 Dec 11 11:56 local5.log
    -rw-r--r-- 1 root wheel 0 Dec 11 11:56 local6.log
    -rw-r--r-- 1 root wheel 0 Dec 11 11:56 local7.log
    netstat shows two syslog connections:
    $netstat -f inet -a | grep "syslog"
    udp4 0 0 *.syslog .
    udp46 0 0 *.syslog .
    But a port scan (Apple network Utility) from another LAN computer doesn't show port 514 open. I am not running Apple's software firewall.
    It seems to me that without port 514 open, I'll never get anything, but how do I open it. I had assumed that all of the syslog set-up gyrations would cause it to be open.
    Any ideas?
    G4 "Gigabit" Dual-500   Mac OS X (10.4.8)   1.5GB RAM, 1TB internal, SCSI, 802.11g, USB2.0

    Your question about local4 got me to dig further into a few things.
    Aaron Adams has a couple of good posts on how to set up the syslog.conf and daily actions:
    http://www.aaronadams.net/index.php/2005/06/02/configuringsyslogd_to_accept_logsfrom
    But the following article is what got me on the local4 bandwagon (I don't know why it assumes local4 would be used):
    http://www.macosxhints.com/article.php?story=20060327074531639
    As we now know nothing happens on local4 unless it is specifically set up to do so. The following article has the best big-picture summary and references on how to handle logs from different sources (i.e., setting up syslog to redirect messages from the IP address of my router to a special log:
    http://macosx.com/forums/howto-faqs/47791-howto-syslog-remote-events-etc.html
    Anyway, to make a long story short, the router IS actually sending to syslog (I was expecting messages in local4 and never saw anything in syslog because it only shows *.notice and above, and the router mainly spews out *.info. It took a bunch of playing with tcpdump to figure it out (I can't seem to get tcpflow to show UDP, even though the man page says it uses the same library and expresions as tcpdump). So everything is good now, messages are coming in to a special log and overwhelming syslog, logs get rotated properly overnight, with some filtering I get the distilled info I want, and via GeekTool even see it on my desktop in real-time. Thanks for your help!

  • Firewall notifications and alarms based on syslog keywords

    HI, I have an ASA and we now have a requirement that we need to be notified in case of a security concern.  I have the firewall sending syslog messages to a central syslog server but I would like to know based on what syslog keywords should I be sending out email notifications.  For ex : if I get a syslog with a keyword "SYN ATTACK" (if there is such a syslog message) I will be sending out an alarm to the security team.
    Is there another way of doing this? Another ex is if we have too many dropped packets or something of this type, then I need to be notified?  Does the asdm have such a feature?
    any recommendations?

    Hello Ronni,
    The Security Appliance will send email notifications due to any events you have configured based on a logging level or a logging list you have configured.
    Here is one document I used before to know a little bit more about the email notifications feature.
    http://community.spiceworks.com/how_to/show/388
    Other way you can send the logging messages is using a logging class.
    For example lets say you just want to send events related to failover and webvpn.
    logging class ha mail 7
    logging class webvpn mail 7
    Hope this helps, any other question let me know.
    Do please rate helpful posts.
    Julio

  • How to disable buffering of similar messages in syslog?

    Hi All,
    Following is my system details:
    SunOS mocm 5.10 Generic_138888-03 sun4v sparc SUNW,Sun-Fire-T200
    On this system I see that, similar messages passed to syslog are suppressed after the first entry and only the count of the number of times that message got repeated is printed. However I want all the logs to be printed even if they have same content.
    Here is what I am getting now:
    +Jul 13 12:01:54 mocm Application[26103]: [ID 441523 local1.notice] xxWriting from stub+
    Jul 13 12:01:54 mocm last message repeated 1 time
    +Jul 13 12:02:45 mocm Application[2845]: [ID 188083 local1.notice] Writing from stub+
    Jul 13 12:02:45 mocm last message repeated 2 times
    +Jul 13 12:02:56 mocm Application[4485]: [ID 441523 local1.notice] xxWriting from stub+
    Jul 13 12:02:56 mocm last message repeated 7 times
    and this is what I want:
    +Jul 13 12:01:54 mocm Application[26103]: [ID 441523 local1.notice] xxWriting from stub+
    +Jul 13 12:01:54 mocm Application[26103]: [ID 441523 local1.notice] xxWriting from stub+
    +Jul 13 12:02:45 mocm Application[2845]: [ID 188083 local1.notice] Writing from stub+
    +Jul 13 12:02:45 mocm Application[2845]: [ID 188083 local1.notice] Writing from stub+
    +Jul 13 12:02:45 mocm Application[2845]: [ID 188083 local1.notice] Writing from stub+
    Is there a way I can configure syslogd to print all the log messages instead of buffering similar messages.
    Thanks in advance for replies.
    Santosh
    Edited by: santosh.panda on Jul 13, 2010 6:48 AM

    To disable automatic grouping of duplicate messages, quit Mail then run this command in Terminal:
         defaults write com.apple.mail AlwaysShowDuplicates -bool true
    To revert to the default setting, run this command:
         defaults write com.apple.mail AlwaysShowDuplicates -bool false
    or simply delete the setting altogether with this command:
         defaults delete com.apple.mail AlwaysShowDuplicates
    If you want to see how Mail behaves with this setting enabled, but without modifying your preference file, start Mail from Terminal with this command:
         /Applications/Mail.app/Contents/MacOS/Mail -AlwaysShowDuplicates YES
    I learned of Mail's modifiability (is that a word?) from here:
         http://hints.macworld.com/article.php?story=2004101603285984
    and here:
         http://erikslab.com/2007/07/16/os-x-mailapp-logging/
    I found the AlwaysShowDuplicates option by looking for interesting words similar to 'duplicates' in the Mail executable like this:
              strings /Applications/Mail.app/Contents/MacOS/Mail | grep -i duplicat

  • Directing syslog messages to a particular file in console

    Hi Guys,
    I have successfully been able to direct my Airport Extreme Syslog files to my macmini which is acting as a syslog server.
    I uncommented the networking listening section of the /System/Library/LaunchDaemons/com.apple.syslogd.plist in order to achieve the above.
    I am having trouble however directing the feed to a file specific to the airport extreme in the console.
    I have created a file using:
    sudo touch /private/var/log/AirportRouter.log (and it successfully appears in the console)
    I added the line
    local0.* /private/var/log/AirportRouter.log
    to the com.apple.syslogd.plist and restarted the computer but it does not receive the log data from the airport extreme.
    The airport extreme syslog info simply appears in the 'All Messages" part of the console.
    Any ideas on what I have done wrong?
    Thanks in advance!

    Hi M,
    You should manage these log settings editing /private/etc/syslog.conf and asl.conf
    Backup original files before changes.
    Read the related manual pages and UNIX logger related articles in order to know better how these settings will produce expected reports.
    Remember that log messages are produced by the process to the logger, and settings in those files are about how to handle received messages. Some "applications" accept setting for log level they should produce to logger.
    I like this article http://www.softpanorama.org/Logs/syslog.shtml and you can search this site for Syslog Configuration and reach other top two related articles. This should give you a good handle.
    Do not forget asl.conf.
    And for the record, test settings for local0 to local7.
    Good luck.

Maybe you are looking for

  • Acrobat Pro - Printing Problems

    I've just started having problems printing from Acrobat Pro 9.0.  I've heard there might be a patch or something to solve this issue, but can't find anything.  I realize that this is an old program, but don't have the funds to upgrade, so have to sti

  • A php script works in IE but not in safari .. please help

    The following php works in internet explorer but not in safari or chrome . In IE all files are saved in specified folder . But in safari , xml portion works .. that is myxml.xml is saved in 'uploads/'.$temp directory ... but uploaded files are not sa

  • IdeaCentre b305 Partition details?

    Hello: Could anybody post the details of factory partition from this system. Type, attributes , ID. I have a problem with my one key recovery, because I modified the partitions on my system and I have found this. http://lemon.soju.co.uk/2010/01/27/le

  • Lost ical entries after sync.

    After I performed a sync the other day all my new appointments that I had imputed into my iphone were erased. There is no record of them on the phone or on my mac. I'm really distressed because I lost my ENTIRE work schedule. Can any one tell me how

  • Apps not installing! 'Installation fail'

    I just installed to creative cloud, I followed all the steps to the Applicaion manger but the apps won't install, It gets right to the end of the installation the last thing it says was 'extracting' before it said 'installation fail' in yellow warnin