Syslog logging issues

I am having trouble setting up a server for syslogd files on Solaris 10 update 8 (october release, i think). I have this working find on another machine, it has solaris 10 update 7, although I doubt that the difference in Solaris updates is the problem. The working machine is host "Ysera" and the non-working machine is host "malygos".
I have logs coming from a remote host, and I'd like them to be logged to their own log file (travistest). They are coming in through the local4 facility.
Following is the syslog.conf file. This file is identical for both hosts.
### comments ####
local4.debug                     /tmp/travistest
local3.debug                     /tmp/travistest
local1.debug                     /tmp/travistest
*.debug                            /var/adm/messages
*.alert                              root
#  These are tabs and NOT spaces, and no trailing whitespace after the actionThe /etc/services file DOES have the line. This is true for both machines.
syslog      514/udpI can verify that remote logging is activated on both:
root@malygos#svccfg -s system-log listprop | grep remote
config/log_from_remote                     boolean true
root@ysera#svccfg -s system-log listprop | grep remote
config/log_from_remote                     boolean true true trueAny idea why Ysera gives a value of "true true true"?? that is crazy talk to me. Also, strangely, look at the /etc/default/syslogd for Ysera (the working machine)
# all those comments that say that this file is deprecated
# The LOG_FROM_REMOTE setting used to affect the logging of remote messages.
# Its definition here will override the svccfg(1M) settings for log_from_remote
# log_from_remote=yeslog_from remote is still commented out!! so how is it still active?
I have altered the /ect/default/syslogd file in the Malygos (non-working) machine to match this, and also to uncomment it and had no luck. I've attempted to use the setprop command to match the "true true true" property and recieved a syntax error. I tried again trying to put quotes are the "true true true", single quotes, ticks, no marks, and nothing works.
Does anyone have any ideas how I can get the remote log to work?? I know that the port is open...
root@malygos#netstat -an | grep 514
    *.514                         *.*                         0            0      49152           0         LISTENI cannot just make Ysera my log server. Both of these machines are development machines and do not carry the "gold" copy of the system files. In order to send a delivery I need to know why Ysera is working so I can duplicate that code for our final product. Thanks ahead of time for any ideas.

Thanks again for the response!!
root@malygos#svcs -a | grep ipf
disabled 13:59:02 svc:/network/ipfilter:defaultipf.conf
root@malygos#cat /etc/ipf/ipf.conf | grep 514
pass in quick proto tcp from pool/700 to any port = 514 keep state
pass in quick proto udp from pool/800 to any port = 514
root@ysera#more /etc/ipf/ipf.conf
#ipf.conf
# IP Filter rules to be loaded during startup
# See ipf(4) manpage for more information on
#IP Filter rules syntaxDespite the IP filter being disabled, I think that these files being so different is a sign of something. I'll have to check with the team to see why they are different, because I dont' think that they are supposed to be!! (let me know if i'm chasing a ghost again)
The machines are on the same subnet, and I have used Malygos to send message OUT and have other Ysera recieve them...and that works fine. It will not work backwards though, so I agree it's a blocked port or perhaps some of the scripts that start syslogd are not providing the -r option as I expect. A big part of me just wants to jump to Ysera and make that our baseline...but I need to be able to replicate the files. Currently I'm trying to alter /lib/svc/method/system-log to force the -r option. (no worries...I kept the original :-)
I'm also trying to get it to log the parameters that syslogd is started with...so I know exactly what the computer THINKS its doing.
Thanks again dude!!
Edited by: mandarbshadar on Mar 2, 2010 10:34 AM

Similar Messages

  • Socket error on syslog.log

    - machine : HP-rx
    - CPU : Itanium
    - TimesTen 6.0.8
    After OS reboot, below error was in the syslog.log.
    Jun 20 20:51:20 hbepa TimesTen Data Manager 6.0.4.tt60[3000]: 3000: Error -232 reading line from socket 11
    Jun 20 20:51:21 hbepa TimesTen Data Manager 6.0.4.tt60[2997]: 2997: Error -232 reading line from socket 10
    - TimesTen log
    20:54:30 Warn: 4668: : Ignoring '/var/TimesTen/tt60/DBI45159fee.0~'
    20:54:30 Warn: 4668: : TimesTen Daemon Release 6.0.4.tt60 started.
    20:55:28 Warn: 4668: : 3003 exited while connected to data store '/data/DataStore/hss2/hss2' shm 34480620 count=1
    20:55:28 Warn: 4668: : 2998 exited while connected to data store '/data/DataStore/hss2/hss2' shm 34480620 count=1
    21:05:48 Warn: 4668: : 4669/60000000000493e0: Recovery started
    22:24:24 Warn: 4668: : 6480 exited while connected to data store '/data/DataStore/hss2/hss2' shm 101589484 count=1
    23:13:31 Warn: 4668: : 7259 exited while connected to data store '/data/DataStore/hss2/hss2' shm 101589484 count=1
    I am not sure whether it has a relation with this error, but replication was not working properly after this.
    Will it have a relation? If it does what is suppose to be done after this issue occur.

    Hi,
    You say you are using TimesTen 6.0.8 but the log messages say 6.0.4? Could you clarify this please.
    In order to make sense of the log we really need to see all the messages covering the relevant period, not just a selection.
    While these messages are indicative of various things that are not 'normal' none of them on their own would explain why replication would not be working.
    Chris

  • What is the current schedule for 6.1.2 and will it fix the Exchange transaction log issue in 6.1?

    Just spent the entire night with virtually no sleep with our firm's group of IT engineers trying to keep our Exchange system online due to massive transaction log growth. Confirmed the issue related to 6.1 calendar bug with Activesync. The workarounds are not practical for large groups of users who depend on their mobile devices for work. Our users have no way of knowing that they are causing an issue so the Apple guidance isnt terribly useful to communicate to 1000 users. When can we expect a resolution? The problem is only going to get worse as more and more users hit the bug. Does anyone know if the issue will resolve as soon as someone installs the 6.1.2 update, assuming that has the fix. Im not trying to bash anyone but this is a very serious problem in enterprise deployments.

    The update was released some time today. 6.1.2 appears to specifically fix the Exchange issue causing excess comms and logging issues. However, although the update is available i do not see the notification badge on the Settings icon. Is this controlled by Apple or is there a user setting i am missing somewhere? I would prefer that all users see the badge to expedite user action.

  • Config certificate and log issues

    I config certificate and use it to connect ipsec vpn , I just config    
    jinan-neusoft(config)#ip domain-name neusoft.com
    jinan-neusoft(config)#crypto key generate rsa general-keys
    The name for the keys will be: jinan-neusoft.neusoft.com
    Choose the size of the key modulus in the range of 360 to 4096 for your
      General Purpose Keys. Choosing a key modulus greater than 512 may take
      a few minutes.
    How many bits in the modulus [512]:
    % Generating 512 bit RSA keys, keys will be non-exportable...
    [OK] (elapsed time was 0 seconds)
    jinan-neusoft(config)#
    Nov 16 01:05:44.435:  RSA key size needs to be atleast 768 bits for ssh version 2
    jinan-neusoft(config)#
    Nov 16 01:05:44.435: %SSH-5-ENABLED: SSH 1.5 has been enabled
    jinan-neusoft(config)#crypto pki trustpoint CA1
    jinan-neusoft(ca-trustpoint)# enrollment url http://59.44.43.217:80
    jinan-neusoft(ca-trustpoint)# revocation-check crl
    jinan-neusoft(ca-trustpoint)# rsakeypair DMVPN-SY-KEY
    jinan-neusoft(ca-trustpoint)# auto-enrol
    jinan-neusoft(config)#crypto pki authenticate CA1
    Certificate has the following attributes:
           Fingerprint MD5: D5F9D56B 4D9A4260 43F21D39 811D7AD5
          Fingerprint SHA1: 1E49B228 DD57F4DB 43DD2C2F 03870C18 840DA12A
    % Do you accept this certificate? [yes/no]: y
    Trustpoint CA certificate accepted.
    then I have log issues like below ,even I config auto-enroll , I don t get  certificate pending information  from my certificate server ,
    my device is C3925 and ios is c3900-universalk9-mz.SPA.151-4.M4.bin ,how to deal with it ,top players , THX~~~~
    Nov 16 01:07:54.871: %PKI-6-CERTRENEWAUTO: Renewing the router certificate for trustpoint CA1
    Nov 16 01:07:54.951: %CRYPTO-6-AUTOGEN: Generated new 512 bit key pair
    Nov 16 01:07:55.115: CRYPTO_PKI:  Certificate Request Fingerprint MD5: 939AF8C1 854DDA90 8FE03058 5635468F
    Nov 16 01:07:55.115: CRYPTO_PKI:  Certificate Request Fingerprint SHA1: 50F869D2 C0814317 7EB2ECC9 90461F3A 353E7089
    Nov 16 01:07:55.119: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6
    jinan-neusoft(config)#D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    Nov 16 01:07:55.119: %SYS-2-MALLOCFAIL: Memory allocation of 40 bytes failed from 0x6D05DEC, alignment 0
    Pool: Processor  Free: 731143916  Cause: Interrupt level allocation
    Alternate Pool: None  Free: 0  Cause: Interrupt level allocation
    -Process= "<interrupt level>", ipl= 3
    -Traceback= 5564384z 6892328z 68B3064z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z
    Nov 16 01:07:55.119: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    jinan-neusoft(config)#
    Nov 16 01:08:09.719: %PKI-6-CERTRENEWAUTO: Renewing the router certificate for trustpoint CA1
    Nov 16 01:08:09.879: CRYPTO_PKI:  Certificate Request Fingerprint MD5: 939AF8C1 854DDA90 8FE03058 5635468F
    Nov 16 01:08:09.879: CRYPTO_PKI:  Certificate Request Fingerprint SHA1: 50F869D2 C0814317 7EB2ECC9 90461F3A 353E7089
    jinan-neusoft(config)#
    Nov 16 01:08:09.883: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    Nov 16 01:08:09.883: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    jinan-neusoft(config)# Nov 16 01:07:54.871: %PKI-6-CERTRENEWAUTO: Renewing the router certificate for trustpoint CA1
    Nov 16 01:07:54.951: %CRYPTO-6-AUTOGEN: Generated new 512 bit key pair
    Nov 16 01:07:55.115: CRYPTO_PKI:  Certificate Request Fingerprint MD5: 939AF8C1 854DDA90 8FE03058 5635468F
    Nov 16 01:07:55.115: CRYPTO_PKI:  Certificate Request Fingerprint SHA1: 50F869D2 C0814317 7EB2ECC9 90461F3A 353E7089
    Nov 16 01:07:55.119: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6
    jinan-neusoft(config)#D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    Nov 16 01:07:55.119: %SYS-2-MALLOCFAIL: Memory allocation of 40 bytes failed from 0x6D05DEC, alignment 0
    Pool: Processor  Free: 731143916  Cause: Interrupt level allocation
    Alternate Pool: None  Free: 0  Cause: Interrupt level allocation
    -Process= "<interrupt level>", ipl= 3
    -Traceback= 5564384z 6892328z 68B3064z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z
    Nov 16 01:07:55.119: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    jinan-neusoft(config)#
    Nov 16 01:08:09.719: %PKI-6-CERTRENEWAUTO: Renewing the router certificate for trustpoint CA1
    Nov 16 01:08:09.879: CRYPTO_PKI:  Certificate Request Fingerprint MD5: 939AF8C1 854DDA90 8FE03058 5635468F
    Nov 16 01:08:09.879: CRYPTO_PKI:  Certificate Request Fingerprint SHA1: 50F869D2 C0814317 7EB2ECC9 90461F3A 353E7089
    jinan-neusoft(config)#
    Nov 16 01:08:09.883: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D43018z 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    Nov 16 01:08:09.883: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 4127784z
    jinan-neusoft(config)#

    I do not have the answer but have exactly the same issue, looks as if it is a bug of some kind :
    Cisco CISCO3945-CHASSIS (revision 1.0) with C3900-SPE150/K9 with 980992K/67584K bytes of memory.
    Processor board ID FCZ163371P3
    6 FastEthernet interfaces
    3 Gigabit Ethernet interfaces
    1 terminal line
    1 Virtual Private Network (VPN) Module
    DRAM configuration is 72 bits wide with parity enabled.
    255K bytes of non-volatile configuration memory.
    250880K bytes of ATA System CompactFlash 0 (Read/Write)
    System image file is "flash0:c3900-universalk9-mz.SPA.151-4.M4.bin"
    Nov 16 07:37:16.611: CRYPTO_PKI: Signature Certificate Request Fingerprint MD5: 358FF778 7C2E66AE 895BF088 BF022442
    .Nov 16 07:37:16.615: CRYPTO_PKI: Signature Certificate Request Fingerprint SHA1: 5F7A4300 20B62132 83D08C6E 2D315DF4 51EFE94D
    .Nov 16 07:37:16.623: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 412
    7784z
    .Nov 16 07:37:16.623: %SYS-2-MALLOCFAIL: Memory allocation of 72 bytes failed from 0x6D05DEC, alignment 0
    Pool: Processor  Free: 704933204  Cause: Interrupt level allocation
    Alternate Pool: None  Free: 0  Cause: Interrupt level allocation
    -Process= "", ipl= 3
    -Traceback= 5564384z 6892328z 68B3064z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4AC
    B9F4z Nov 16 07:37:16.611: CRYPTO_PKI: Signature Certificate Request Fingerprint MD5: 358FF778 7C2E66AE 895BF088 BF022442
    .Nov 16 07:37:16.615: CRYPTO_PKI: Signature Certificate Request Fingerprint SHA1: 5F7A4300 20B62132 83D08C6E 2D315DF4 51EFE94D
    .Nov 16 07:37:16.623: %SYS-3-INVMEMINT: Invalid memory action (malloc) at interrupt level
    -Traceback= 5564384z 68B3034z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4ACB9F4z 412
    7784z
    .Nov 16 07:37:16.623: %SYS-2-MALLOCFAIL: Memory allocation of 72 bytes failed from 0x6D05DEC, alignment 0
    Pool: Processor  Free: 704933204  Cause: Interrupt level allocation
    Alternate Pool: None  Free: 0  Cause: Interrupt level allocation
    -Process= "", ipl= 3
    -Traceback= 5564384z 6892328z 68B3064z 945A8D0z 6D05DF0z 6D05F70z 6D06B50z 6D07268z 6D4308Cz 6D25044z 6D1988Cz 6D4CCE0z 91F0154z 91F0CC4z 91F0DA4z 4AC
    B9F4z

  • Cisco Security manager syslog.log file problem

    Hello
    I have this problem with the CSM, the next file Syslog.log  (C:\Program Files\CSCOpx\log\Syslog.log  ), this file grows very fast to fill the hard disk and saturates the server, I have tried the log rotation of the cisco works but it doesnt work, what else can i do?
    the hard drive fills in 4 hours. tankyou

    In CSM clinet under Tools > CSM Administration > Debugging you can changing the level to something higher than debugging.
    I hope it helps.
    PK

  • Reverse call log issue

    i keep getting an error when i try to do a reverse call lookup. it says try setting phone list view to "call log" but i don't have that option. It says if this option is unavailable this is a known but and we are working with RIM to correct the issue. If you require assitance accessing the phone list view settings or would like to be notified when a fix is available please use the Send Us Feedback option and indicate Reverse Call Log issue in message. But where is this send us feedback? I'm so confused. Anyone have this problem or know where I can get some help for it? Thanks again

    How did you reload the firmware? Did you backup the data and perform a reset using *#7370# before reloading? Try and reply.
    Nokia C7

  • Syslog Reports not collect Syslog.log file Messages

    I am doing a installation on CiscoWorks 3.2. after two three weeks I found my syslog services is not working properly. Once I checked on the syslog.log its updated with the device logs as normal. But when I am going to generate report it’s not collect data from the syslog log file. I have notice my syslog analyzer and syslog collator processes are shown as = Program started - No mgt msgs received. Is this normal on the LMS serve?
    Anyway I found following error massagers on the SyslogAnalyzer.log file.
    cisco.nm.xms.ctm.common.CTMException: CTMRegistryClient::addNewURNEntry URN : SyslogAnalyzerService ErrMsg : URN already in use
                    at com.cisco.nm.xms.ctm.server.CTMServer.publish(CTMServer.java:253)
                    at com.cisco.nm.xms.ctm.server.CTMServer.publish(CTMServer.java:180)
                    at com.cisco.nm.rmeng.sa.SyslogAnalyzerEngine.registerWithCtm(SyslogAnalyzerEngine.java:2267)
                    at com.cisco.nm.rmeng.sa.SyslogAnalyzerEngine.start(SyslogAnalyzerEngine.java:2189)
                    at com.cisco.nm.rmeng.sa.SyslogAnalyzerService.main(SyslogAnalyzerService.java:109)
    please I need your expertise knowledge to sort out this problem.
    Thank you,
    Chandimal.k
    +94777420771

    Hi,
    Errors Found:
    SyslogCollector - [Thread: main] WARN , 15 Dec 2011 14:33:46,505, Unable to resurrect connection to a subscriber.
    URN : SyslogAnalyzerService ErrMsg : URN already in use
    Try deleting the ctmregistry and ctmregistry.backup files and regenerat your SSL certificate and then resubscribed to the syslog collector.
    1. net stop crmdmgtd
    2. delete all the server.* files in ../CSCOpx/MDC/Apache/conf/SSL
    3. Open a dos shell and cd to:
    ../CSCOpx/MDC/Apache, and run: perl ConfigSSL.pl -disable and then again perl ConfigSSL.pl -enable
    You will see now a lot of questions, please make sure that you enter correctly the question of FQDN!
    4. if you don't want to use SSL, run again: perl ConfigSSL.pl -disable
    If you use SSL please don't do anything.
    5. net start crmdmgtd
    Then wait fifteen minutes for all the LMS services to come up before testing.
    Thanks

  • Ciscoworks 3.1 syslog.log filtering

    Hello Cisco community!
    I would like to ask a question about syslog.log file in Ciscoworks 3.1.
    I was able to forward my syslog messages to another syslog server ( with a syslog-agent forwarding the content of the syslog.log file ), but in the syslog.log file there is other syslog messages that i don't want to forward ( about processes and other things ). I only want to forward the syslog messages that the devices's sent to CW.
    Can i somehow filter out in Ciscoworks the messages that i don't want to forward?
    Thanks for help.

    You mean you can't find the syslog.log file? A trip to regedit may be in order:
    http://www.cisco.com/en/US/products/sw/cscowork/ps2073/products_tech_note09186a00800a7275.shtml
    On a Windows System, the location is defined in the registry [ which can be viewed from regedit]:
    \system\currentControlSet\Services\CRMlog\Parameters
    LogFile = "CSCOpx\log\syslog.log"

  • Syslog Log Rotation

    Dear,
    Just to understand syslog log rotation. I have configured syslog_info file for log rotation and size i have give is 100mb with 0 no of backups. I have scheduled it to run every week with a backup path. Basically i dont want any backups and i want the syslog_info to be overwritten when it reaches 100mb, are my setting correct?
    thanks,
    aamir

    yes that is right,
    you can see it also explained in the logrot document
    http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_common_services_software/3.1.1/user/guide/admin.html#wp645704
    Step 5 Specify the number of archive revisions. If you do not want to keep any archives, enter 0 (the default) for this option.
    hope this is what you are looking for.

  • RMAN BACKUPS AND ARCHIVED LOG ISSUES

    제품 : RMAN
    작성날짜 : 2004-02-17
    RMAN BACKUPS AND ARCHIVED LOG ISSUES
    =====================================
    Scenario #1:
    1)RMAN이 모든 archived log들을 삭제할 때 실패하는 경우.
    database는 두 개의 archive destination에 archive file을 생성한다.
    다음과 같은 스크립트를 수행하여 백업후에 archived redo logfile을 삭제한다.
    run {
    allocate channel c1 type 'sbt_tape';
    backup database;
    backup archivelog all delete input;
    Archived redo logfile 삭제 유무를 확인하기 위해 CROSSCHECK 수행시 다음과
    같은 메시지가 발생함.
    RMAN> change archivelog all crosscheck;
    RMAN-03022: compiling command: change
    RMAN-06158: validation succeeded for archived log
    RMAN-08514: archivelog filename=
    /oracle/arch/dest2/arcr_1_964.arc recid=19 stamp=368726072
    2) 원인분석
    이 문제는 에러가 아니다. RMAN은 여러 개의 arhive directory중 하나의
    directoy안에 있는 archived file들만 삭제한다. 그래서 나머지 directory안의
    archived log file들은 삭제되지 않고 남게 되는 것이다.
    3) 해결책
    RMAN이 강제로 모든 directory안의 archived log file들을 삭제하게 하기 위해서는
    여러 개의 채널을 할당하여 각 채널이 각 archive destination안의 archived file을
    백업하고 삭제하도록 해야 한다.
    이것은 아래와 같이 구현될 수 있다.
    run {
    allocate channel t1 type 'sbt_tape';
    allocate channel t2 type 'sbt_tape';
    backup
    archivelog like '/oracle/arch/dest1/%' channel t1 delete input
    archivelog like '/oracle/arch/dest2/%' channel t2 delete input;
    Scenario #2:
    1)RMAN이 archived log를 찾을 수 없어 백업이 실패하는 경우.
    이 시나리오에서 database를 incremental backup한다고 가정한다.
    이 경우 RMAN은 recover시 archived redo log대신에 incremental backup을 사용할
    수 있기 때문에 백업 후 모든 archived redo log를 삭제하기 위해 OS utility를 사용한다.
    그러나 다음 번 backup시 다음과 같은 Error를 만나게 된다.
    RMAN-6089: archive log NAME not found or out of sync with catalog
    2) 원인분석
    이 문제는 OS 명령을 사용하여 archived log를 삭제하였을 경우 발생한다. 이때 RMAN은
    archived log가 삭제되었다는 것을 알지 못한다. RMAN-6089는 RMAN이 OS 명령에 의해
    삭제된 archived log가 여전히 존재하다고 생각하고 백업하려고 시도하였을 때 발생하게 된다.
    3) 해결책
    가장 쉬운 해결책은 archived log를 백업할 때 DELETE INPUT option을 사용하는 것이다.
    예를 들면
    run {
    allocate channel c1 type 'sbt_tape';
    backup archivelog all delete input;
    두 번째로 가장 쉬운 해결책은 OS utility를 사용하여 archived log를 삭제한 후에
    다음과 같은 명령어를 RMAN prompt상에서 수행하는 것이다.
    RMAN>allocate channel for maintenance type disk;
    RMAN>change archivelog all crosscheck;
    Oracle 8.0:
         RMAN> change archivelog '/disk/path/archivelog_name' validate;
    Oracle 8i:
    RMAN> change archivelog all crosscheck ;
    Oracle 9i:
    RMAN> crosscheck archivelog all ;
    catalog의 COMPATIBLE 파라미터가 8.1.5이하로 설정되어 있으면 RMAN은 찾을 수 없는
    모든 archived log의 status를 "DELETED" 로 셋팅한다. 만약에 COMPATIBLE이 8.1.6이상으로
    설정되어 있으면 RMAN은 Repository에서 record를 삭제한다.

    Very strange, I issue following command in RMAN on both primary and standby machine, but it they don't delete the 1_55_758646076.dbf, I find in v$archived_log, this "/home/oracle/app/oracle/dataguard/1_55_758646076.dbf" had already been applied.
    RMAN> connect target /
    RMAN> CONFIGURE ARCHIVELOG DELETION POLICY TO APPLIED ON ALL STANDBY;
    old RMAN configuration parameters:
    CONFIGURE ARCHIVELOG DELETION POLICY TO APPLIED ON ALL STANDBY;
    new RMAN configuration parameters:
    CONFIGURE ARCHIVELOG DELETION POLICY TO APPLIED ON ALL STANDBY;
    new RMAN configuration parameters are successfully stored
    RMAN>
    ----------------------------------------------------------------------------------

  • Cisco 4710 ACE syslogs generating issue

    I have 4710 ACE load balancer with three virtual contexts, i have configured the three contexts with the syslog configuration to send the logs to a syslog server as below:
    logging enable
    logging trap 5
    logging buffered 7
    logging host 10.x.x.x udp/514
    the issue is that i can see logs in the syslog server from Admin context  only and there are no any logs buffered or sent to the syslog server from the other two context.
    Note that the ACE software version is A3(2.0).
    is there any bug for this software version or any thing missing fron the configuration?

    Mohammed,
    Please repost to the correct forum. This forum is for Wireless/Mobility Security (and Management).
    You will probably find better help here: https://supportforums.cisco.com/community/netpro/security/others
    Justin

  • SYSLOG LOGGING PROBLEMS !!!!

    Hi ALl,
    I am trying to configure a syslog server to log messages from the routers.
    I am trying on the first router, and i issue the command :
    LOGGING (syslog ip address)
    So now the messges should be sent to the syslog server.
    Now supposingly i want to capture the events when an access-list is met namely the DENY IP ANY ANY .... so i should issue the DENY IP ANY ANY LOG command right ??? the LOG keyword should force the router to log the event every time this is met. However i try to do illegal traffic to trigger the DENY IP ANY ANY LOG but it does not show anything logged in the show run, or on the syslog server.
    I know the syslog works fine as it logs the messages
    that i have configured the router from my ip address.
    Is there something i am missing here ???
    Please help ,
    Thanks,
    George

    Hi,
    What trap level have you set on the router??? After going in the configure terminal mode issue the command "logging trap 7" so that you'll get all the messages which are sent.
    If would be better if you could post your config.
    Hope it helps.
    Please rate helpful posts.
    Regards,
    AbhisheK

  • Ciscoworks syslog collector issue

    Hi All,
    In a central location i have a ciscoworks syslog collector version 3.5. The issue is not all the logs generated in the device are collected by  ciscoworks including the devices connected in LAN. The major issue is on Cisco6500 series switches where i see multiple interface flaps in log but only few are found in syslog.
    Regards,
    Sathvik

    Hi,
    check  here Admin > Collection Settings > Syslog > Syslog Collector Status  , see if messages are falling under fitered or Invalid
    then check the filter:
    Admin > Network > Notification and Action Settings > Syslog Message Filters
    I would suggest you to create a filter with all  *  and see if that helps.
    you can look at this thread  as well:
    https://supportforums.cisco.com/thread/2244888?tstart=60
    Thanks-
    Afroz
    [Do rate the useful post]

  • Syslog - log parsing

    Hello,I have started using new syslog feature on my PMS 11.31. Do You have any expirience with parsig logs for SIEM? I am using IBM Qradar and it looks like I will have to parse information collected from Fsecure logs manualy. Do You have any xml file prepared which could help me with that?
    Qradar DSM for F-secure would be ideal.

    Hi there,
    The Connector behavior is documented in detail in the Connector manual,
    I believe. My understanding is that the Connector tries to identify
    "new" event sources based on the *content* of inbound messages - so in
    your example above, it would detect a new source labeled 192.168.30.40.
    In this case it actually doesn't matter if the data was actually being
    sent from some other IP address - the Connector cares about the IP
    address in the syslog header. If, however, the message was sent from IP
    A and no syslog header was present at all (e.g. the message started with
    "A new user..."), then per the RFC the Syslog Connector would inject the
    syslog header and identify a new source with IP A.
    So one possibility is that the second time you tried this, you sent
    data from a different IP address. Also, the Connector doesn't correlate
    IPs/hostnames, so if you sent data with the hostname in the header
    instead of the IP, that would also be seen as a new source.
    I'd check these basics first, and if that still doesn't resolve the
    issue we'll dig deeper.
    DCorlette
    DCorlette's Profile: http://forums.novell.com/member.php?userid=4437
    View this thread: http://forums.novell.com/showthread.php?t=446501

  • Call log issue after upgrading to OS 10.3.1.158​1 from 10.2

    Dear all.
    I have update my BlackBerry 10 os to 10.3.1.1581 and to my surprise i find that the call log os restricted to about 150-200 call whereas it was almost unlimited in the previous 10.2 os .
    BlackBerry should issue a fix asap since this is such a basic features and necessity.
    I find myself in a very bad situation after upgrading.

    I have two call lors. One in the phone app, and one in the hub.
    I feel like the one in the phone app is quite short, but the one in the hub is unlimited.
    Do you confirm on your side?
    That being said, tracking more than 150 previous calls regularly is an extreme usage of the phone, I don't think the OS is made for that. I suggest you use a third party app that will be suited at tracking 200 phone calls a day.
    There are several that are free currently in BlackBerry World (the Free March section).
    The search box on top-right of this page is your true friend, and the public Knowledge Base too:

Maybe you are looking for