/var/adm/csalog file

Hello -
I'm looking for some sort of definitive answer to a dilema I am facing, which is whether the csalog generated on UNIX boxes by syslogd is actually needed for audit purposes or should the log files kept on the CSAMC be deemed authotitative?
I have some Unix SA's that are rotating the /var/adm/csalog files based on the syslog.conf file and they are changing the permissions of the csalog file which of course is triggering alerts.
Are these files redundant? Can I definitively say that any log file information I would need to satisfy an audit requirement could be found on the CSA MC?

Make sure /var/adm/message is writable by root only (chmod 600) and restart syslogd (svcadm restart system-log)

Similar Messages

  • Getting lot of errors like :0x408 in /var/adm/messages file in Solaris 10

    Hi,
    Can anyone help me regarding the following errors being found in the /var/adm/messages file:
    Nov 24 03:36:07 x9ce1 :0x408
    Nov 24 03:36:07 x9ce1 dtcp: [ID 702911 kern.notice] WARNING GW (dtcp_klib.c,198) (53449,33458) (0xac120fd5,0xac126503)
    Nov 24 03:36:07 x9ce1 dtcp: [ID 702911 kern.notice] WARNING PS (ps_udp.c,415) Error ps_do_DB_PS_Udp_Placement
    Nov 24 03:36:07 x9ce1 :0x408
    Nov 24 03:56:06 x9ce1 :0x408
    Nov 24 03:56:06 x9ce1 dtcp: [ID 702911 kern.notice] WARNING GW (dtcp_klib.c,198) (55961,33458) (0xac120fd5,0xac126503)
    Nov 24 03:56:06 x9ce1 dtcp: [ID 702911 kern.notice] WARNING PS (ps_udp.c,415) Error ps_do_DB_PS_Udp_Placement
    Nov 24 03:56:06 x9ce1 :0x408
    The frequency of this error is very high and I wanted to find out what could be the reason behind its occurrence?
    Thanks.
    Any useful comments will be most welcome :)
    Jahan

    Check /etc/init.d/dtcp , i guess it would be copyrighted to fujitsu-siemens if its the fujitsu dtcp. You can also9 do a pkginfo -l SMAWdtcp, which seems to be the name of the fujitsu package. Hmm, odd name for a Fujitsu package.
    Actually i found the following Fujitsu bug:
    A0559315 Fix flood of messages like dml_send DB_PS_Udp_Con_Remove_List failed
    - caused by trying to send the message to a node that is down.
    .. which seems rather familiar.
    Its fixed with fujitsu patch 901199-08
    Other Fujitsu DTCP patches are
    901191-08 and 901244-01
    Note that to get Fujitsu patches you need a special account, once you have an account you can download them from http://patches.ts.fujitsu.com/

  • Finding Errors in /var/adm/messages file

    Hi,
    I am new to UNIX admin, i am going to write a script in such a way that it has to send a mail to root if any errors in /var/adm/messages file.
    Can any one please send useful links or sample script file?
    Thanks
    Ramesh

    http://www.sunfreeware.com/indexsparc9.html
    look for logsurfer+-1.7-sol9-sparc-local.gz package (there's one for solaris8 and Solaris10, too). Also, you can search on http://www.sun.com/bigadmin/home/index.html
    for these types of scripts.
    John

  • /var/adm/messages file not updatiing

    Hi All!
    Can you pls help, I´m new into solaris, so I´ve got a problem, ever since I didi "> messages" inside the /var/adm/ direcotory the messages file does not update anymore.~
    I´ve done ps -ef ! grep syslogd, and the deamon is running. So pls can you help?
    regards
    F.R.

    Make sure /var/adm/message is writable by root only (chmod 600) and restart syslogd (svcadm restart system-log)

  • /var/adm/messages file empty

    Do not know the reason y messages file is empty already restarted the syslog daemon but still its showing empty .
    xxxxxxx# more /var/adm/messages
    xxxxxx#
    # ps -efo zone,pid,ppid,time,comm | grep syslog | grep global
    global 11861 1 00:10 /usr/sbin/syslogd
    svcs /system/system-log
    STATE STIME FMRI
    online Sep_10 svc:/system/system-log:default

    HI
    What happens if you type in :
    logger TEST
    Does it write it out to the file.
    Have you checked your /etc/syslog.conf file.
    Make sure it has tabs and not spaces between eg:
    *.debug /var/adm/messages

  • /var/adm/wtmpx file size control ?

    Hi :)
    The /var folder on our DNS server has reached > 90% capacity and is rising 1% a day. ls -ltr shows that the most current files are /var/adm/wtmpx and utmpx as well as lastlog and messages. Is it possible to cap the size of the wtmpx file, which seems to be the file that is growing the fastest ?
    Regards
    Annib
    Solaris 8 on Sunfire 6800

    Certainly, there are a couple of ways of doing this;
    If you want to save the old data (and you might want to if its a firewall), you can always copy the wtmpx file to something else, and then copy /dev/null over wtmpx:
    # cp /var/adm/wtmpx /var/adm/wtmpx.0
    # cp /dev/null /var/adm/wtmpx
    Then its of course a good idea to compress the old file.
    If you don't want to save any data, just copy /dev/null to wtmpx.
    A somewhat more complicated way of doing this is to hack the wtmx file and only save, for example, the 1000 last lines. This can be done with the /usr/lib/acct/fwtmp command.
    The fwtmp command lets you export the wtmpx file to something human readable (and editable), which you then may edit and convert back into your wtmpx file.
    However, there are a few bugs in this commands, so it will not work without the latest 'n' greatest fwtmp patch: 116943-02.

  • Scsi messages in /var/adm/messages file

    Hi,
    After open the /var/adm/messages i have the SCSI error messages:
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    Jul 8 15:45:13 kapttdw2 scsi: [ID 107833 kern.warning] WARNING: /ssm@0,0/pci@1a,600000/SUNW,qlc@1/fp@0,0/ssd@w5006048452a65588,2 (ssd129):
    Jul 8 15:45:13 kapttdw2 Corrupt label; wrong magic number
    bash-2.05$
    Please help me to correct this error
    Thank

    This issue on hostname `kapttdw2` seems to be the same as you reported in your other thread for hostname `kapttdw1`.
    [http://forums.sun.com/thread.jspa?threadID=5391935|http://forums.sun.com/thread.jspa?threadID=5391935]
    Perhaps you just need to label these disks (as you were advised for those other disks).
    Also, since these drives are in an EMC peripheral, you might consider opening a support case with that storage vendor and get advice from them.

  • Email notification of warning messages generated in /var/adm/messages

    I�m using �mdmonitord� to periodically check status of my disks in RAID 1 (using Solaris Volume Management) If/when problem occurs the errors/warnings will be logged to[b] /var/adm/messages file. What do I need to configure/enable to monitor /var/adm/messages for particual WARNING messages and to notify me via email.
    Similar utility on LINUX is Logwatch: http://www2.logwatch.org:81/index.html

    Check /etc/init.d/dtcp , i guess it would be copyrighted to fujitsu-siemens if its the fujitsu dtcp. You can also9 do a pkginfo -l SMAWdtcp, which seems to be the name of the fujitsu package. Hmm, odd name for a Fujitsu package.
    Actually i found the following Fujitsu bug:
    A0559315 Fix flood of messages like dml_send DB_PS_Udp_Con_Remove_List failed
    - caused by trying to send the message to a node that is down.
    .. which seems rather familiar.
    Its fixed with fujitsu patch 901199-08
    Other Fujitsu DTCP patches are
    901191-08 and 901244-01
    Note that to get Fujitsu patches you need a special account, once you have an account you can download them from http://patches.ts.fujitsu.com/

  • Solaris 9 - INIT: Cannot create /var/adm/utmpx (System Hangs)

    Hello,
    I am unable to boot into solaris 9 after I did a init 0. I did init 0 because shutdown -y -g0 -i0 did not work.
    This is the error message I get
    Hardware watchdog enabled
    INIT: Cannot create /var/adm/utmpx
    INIT: failed write of utmpx entry:" "
    INIT: failed write of utmpx entry:" "
    INIT: SINGLE USER MODE
    Type control-d to proceed with normal startup,
    (or give root password for system maintenance):
    After it asks for the password it HANGS.
    I entered the password, but NOTHING HAPPENS.
    I can go into sc console though.
    I also rebooted using Solaris 9 cdrom in single user mode. Checked the filesystem using fsck, and no faults were found. I also tried creating a new /var/adm/utmpx file but that did not work too.
    Any help would be appreciated,
    Thank you,
    Jacob.

    Hello,
    Check for /var filesystem usage,if it is not mouted as seperate filesystem then check for "/" FS usage.
    There may be chances you get to have this problem if your FS is full.
    If everything normal then follow the below steps, which solved similar kind of issues in the past for me.
    Logon to the system and when you get prompt just run fsck on your root filesystem.
    Check /etc/vfstab file to ensure that you are running fsck on correct fs name.
    After completing fsck just say "reboot". The machine will boot normally.
    In b/w is this machine disks are mirrored?? if so then you may need to choose the disks carefully before you run fsck.
    thanks.

  • Monitoring /var/adm/messages

    Hello to all,
    we are developing system for monitoring of the servers trough reading of the /var/adm/messages file.
    Since there are numerous messages in this file we are wondering what regular expressions to use in order to extract serious/critical alerts from this file.
    Does anybody have set of regular expressions to search for in this file for serious/critical events?
    Thanks in advance.
    Dejan

    Hi ,
    You can try to play whit /etc/syslog.conf . In this way you can made a filter for emergency and critical problem and redirect it to a specific file .
    For example , the following line will redirect all the the emargency and critical message to /var/adm/message.critical
    *.emerg;*.crit;* /var/adm/message.critical
    I hope this help to develop your tool
    xavier

  • /var/adm/messages regopen warning

    Hello,
    I am observing a warning message in the /var/adm/messages
    file of my Solaris 2.8 machine after I have run my application
    for several hours (under a load). The resulting behavior is that
    my application no longer responds to external requests and essentially
    appears to hang.
    The warning is the following:
    Aug 23 16:44:07 eas1nc2 reg: [ID 286125 kern.warning] WARNING: regopen: failed, attempted to open > 1000 streams
    Does anyone have any ideas as to what could be causing this
    as well as possible resolutions.
    Thanks in advance!!
    Brad

    Hello,
    Take a look at /etc/syslog.conf. I think that by deafult this file should contain two entries that make the system log into /var/adm/messages. Are there these entries?
    Bye,
    Joseba M. Iturbe

  • /var/adm/messages error

    Hi All,
    New to solaris
    I am getting the following error in the solaris 5.9 /var/adm/messages file.
    Mar 15 13:33:39 dxb01-sol-tfs in.routed[135]: [ID 798604 daemon.error] empty response from 10.1.251.4
    Is this any telnet related error or anything serious? Please advise
    Any help appreciated
    Rgds
    Najmal

    The first thing that you have to do is to snoop
    10.1.251.4 to see the traffic between localhost and
    that IP Address.Hi,
    Thanks veru much for the response.
    I have tried snoop and it gives the following message. What does this mean? Please help
    10.1.251.4 -> 10.1.255.255 RIP R (0 destinations)
    Rgds

  • Var/adm/loginlog not showing any data?

    hai all
    i wanted to watch anyone who has tried to access the system but failed. for that i crate a file /var/adm/loginlog
    then i changed its mode to 600
    chgrp 600 /var/adm/loginlog
    chgrp sys /var/adm/loginlon
    after these command i tried to login in to system for more than 6 or 8 time, but after checking /var/adm/loginlog file i couldnt find any in formation can anybody share the reason behind this

    What is the method you has used to login?
    dtlogin does not and has never used the loginlog file. loginlog is
    used only by /bin/login.

  • Cmn_err doesnt log to /var/adm/messages

    HI,
    I am trying cmn_err to log my messages using different error level. But it is not logging messages to /var/adm/messages file, also not printing on console. I have tried diff options like ! ^ etc. but all efforts proved futile. Can anyone help me?
    - Mayur Talati

    We had a problem on one system similar to yours.
    It tured out that the problem was caused by someone
    removing /usr/ccs/bin/m4 in order to favor a locally
    installed version of m4 in /usr/local/bin. The problem is,
    the syslog daemon needs to find m4 when it starts
    and apparently it must be in /usr/ccs/bin/m4.
    Check if you have /usr/ccs/bin/m4 on your system and
    look in /var/adm/messages for any syslogd startup errors.

  • What is the significance of /var/adm/siebel/vdp.properties file

    Can you please Tell me the Significant of /var/adm/siebel/vdp.properties file...
    What is the main purpose of this File..?
    Regards,
    Balaji

    Balaji,
    vpd.properties file is created by installshield embedded in siebel installers, other software that also uses installshield may also use the same vpd.properties. Good practice is to take backups after/before each siebel installation, including patch install. Doc ID 476955.1 in support.oracle.com has some information about this file.
    Hope it helps,
    Wilson

Maybe you are looking for

  • How (and where) can I create a new Nokia Messaging...

    Hi, I just got a new E7 which I am currently pretty happy with, however when I go to email.nokia.com I only see a log-in form for the existing customers. Where can new users register and how can I do it? I can see that there is a Nokia Mail by Yahoo,

  • Regarding erecruiment reports

    hi , any one can give sample  e -recruitment  program write in abaphr Thanks&Regards babasish

  • What adobe software do I use to design graphics for a 24 grid window display?

    Hi there, I know in some designing cases you use multiple programs to complete your design goal and I'm thinking this may be a case. If you could help me figure out what programs to use, I'd appreciate it. I have a large storefront window system that

  • Java.io.Reader - java.io.InputStream

    Hi! Is there a way to wrap a java.io.Reader into an java.io.InputStream (like java.io.InputStreamReader does but in the other direction)? I found now class doing this job (deduced from java.io.InputStream, taking an java.io.Reader as Constructor Para

  • Apple TV audio, mirroring movie from iPhone

    Haven't bought the Apple TV yet. I'm not talking about airplay. When I mirror a movie playing on safari browser through the Apple TV to my tv, I was told I must keep the safari browser "open". True? In other words, the iPhone screen must stay on, whi