How can I stop this???

 
Thread Tools Search this Thread
Operating Systems Linux Red Hat How can I stop this???
# 1  
Old 02-20-2012
How can I stop this???

I have a user ( and actually me too) getting this messages when the screen is idle, I need help on stopping this messages:

2012 Feb 20 13:30:22 servername Audit[11217]: LENGTH: "330" SESSIONID:[6] "339384" ENTRYID:[1] "1" STATEMENT:[1] "1" USERID:[10] "OPS$PT2ADM" USERHOST:[13] "zzzzzzzzzzz" ACTION:[3] "100" RETURNCODE:[1] "0" COMMENT$TEXT:[96] "Authenticated by: OS; Client address: (ADDRESS=(PROTOCOL=tcp)(HOST=161.134.154.206)(PORT=21889))" OS$USERID:[6] "pt2adm" DBID:[10] "1102948819" PRIV$USED:[1] "5"
2012 Feb 20 13:30:22 zzzzzzzzzzz Audit[11217]: LENGTH: "203" SESSIONID:[6] "339384" ENTRYID:[1] "1" ACTION:[3] "101" RETURNCODE:[1] "0" LOGOFF$PREAD:[1] "0" LOGOFF$LREAD:[2] "27" LOGOFF$LWRITE:[1] "0" LOGOFF$DEAD:[1] "0" DBID:[10] "1102948819" SESSIONCPU:[1] "1"
2012 Feb 20 13:30:22 zzzzzzzzz Audit[11217]: LENGTH: "331" SESSIONID:[6] "339385" ENTRYID:[1] "1" STATEMENT:[1] "1" USERID:[5] "SAPR3" USERHOST:[13] "zzzzzzzzzzz" ACTION:[3] "100" RETURNCODE:[1] "0" COMMENT$TEXT:[102] "Authenticated by: DATABASE; Client address: (ADDRESS=(PROTOCOL=tcp)(HOST=161.134.154.206)(PORT=21889))" OS$USERID:[6] "pt2adm" DBID:[10] "1102948819" PRIV$USED:[1] "5"
# 2  
Old 02-20-2012
Are you logged into the console of the machine? Looks like these are warning messages thrown to the STDERR stream of the console. You should not get these if you login through ssh or do a graphical login.

What application are you running on this machine? SAP (looks like one)? As far as I can tell you, this has nothing to do with RHEL, you may wan to check the application settings.

If the application uses syslog daemon to write logs, you may change *.emerg * to *.emerg /var/log/messages in the /etc/rsyslog.conf (or /etc/syslog.conf depending on the RHEL version) file to redirect the emergency messages to /var/log/messages file.

Last edited by admin_xor; 02-20-2012 at 04:34 PM.. Reason: Added info about rsyslog
This User Gave Thanks to admin_xor For This Post:
# 3  
Old 02-20-2012
Thanks for the note.

The messages are coming from ssh not from console. I get them and the users too.

There is SAP and I believe oracle too.

The *.emerg is commented out in the /etc/rsyslog.conf/rpmsave

I believe we maybe using a custom syslog program that is the one creating those messages.

I found this:

@version:3.2
# syslog-ng configuration file.
#
# This should behave pretty much like the original syslog on RedHat. But
# it could be configured a lot smarter.
#
# See syslog-ng(8) and syslog-ng.conf(5) for more information.
#
options {
flush_lines (0);
time_reopen (10);
log_fifo_size (1000);
long_hostnames (off);
use_dns (no);
use_fqdn (no);
create_dirs (no);
keep_hostname (yes);
};
source s_sys {
file ("/proc/kmsg" program_override("kernel: "));
unix-stream ("/dev/log");
internal();
# udp(ip(0.0.0.0) port(514));
};
destination d_cons { file("/dev/console"); };
destination d_mesg { file("/var/log/messages"); };
destination d_auth { file("/var/log/secure"); };
destination d_mail { file("/var/log/maillog" flush_lines(10)); };
destination d_spol { file("/var/log/spooler"); };
destination d_boot { file("/var/log/boot.log"); };
destination d_cron { file("/var/log/cron"); };
destination d_kern { file("/var/log/kern"); };
destination d_mlal { usertty("*"); };
# Some default filters require modification for DBA
filter f_kernel { facility(kern); };
filter f_default { level(info..emerg) and
not (facility(mail)
or facility(authpriv)
"syslog-ng.conf" [readonly] 111L, 4757C
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Stop the process

I have the following log file running since yesterday and its consuming so much of the disk space. -rw-rw-r-- 1 dev dba 4543237120 Nov 10 09:00 load_run_file1_0.1111091224.lg How do i kill this process. I don't have any idea of stopping this. Any help would be really appreciated. ... (3 Replies)
Discussion started by: bobby1015
3 Replies

2. Solaris

stop - A

I am using solaris x86 with a pc keyboard. i am trying to get to the ok prompt i have tried ctrl-break but it is not working , alt-break will not as well. pls any thought? (4 Replies)
Discussion started by: seyiisq
4 Replies

3. UNIX for Dummies Questions & Answers

To Stop at error

Hi All, I am running parallel process as they all run the same JOBS and only thing which changes is the argument which ia passed. I am doing it as follows script.sh $1 & script.sh $2 & script.sh $3 &.. and so on. Now each process has same set of JOBS which are to be executed. Now say... (1 Reply)
Discussion started by: Prashantckc
1 Replies

4. AIX

a process that never stop

Dears all i have an AIX box in which i am facing a problem with a process as below: /usr/dt/bin/dtexec -open 0 -ttprocid and each time i am killing this process with "kill -9" then it run again after a while. any ideas or solutions will be appreciated. (13 Replies)
Discussion started by: TheEngineer
13 Replies

5. Solaris

Stop+A equal

Hi, I have replaced my current Intel PC machine with Solaris 10, it use to have windows XP. I am sure alot of people already done this and i have seen Solaris running smoothly but having keyboard problem. What is the equal keys in a QWERTY keyboard for selection <Stop+A> ? Is there a... (5 Replies)
Discussion started by: tlee
5 Replies

6. UNIX for Advanced & Expert Users

help me stop spammer

Hello, I am hosting a site that someone is bouncing a huge amount of spam off of and I have not been able to find what file they are using to abuse my server. Short of terminating the account and telling my customer to take a hike I am hoping someone can help me find the file that is being... (1 Reply)
Discussion started by: dorpan
1 Replies

7. UNIX for Advanced & Expert Users

how to stop others users to stop viewing what i am doing ?

Hi , I have one question, suppose i am a normal user and when i use 'w' command , it shows who is logged on and what they are doing . Now i want to stop others users to know what i am doing accept the root ? can i do this ? thanks (5 Replies)
Discussion started by: mobile01
5 Replies

8. SCO

stop commands

i hit ping to ping a server, and it keeps going. how do you stop it? ctrl Z, D, C, nothing works. (2 Replies)
Discussion started by: BG_JrAdmin
2 Replies

9. Filesystems, Disks and Memory

How do I stop this???

Am having trouble trying to stop the process below ... bash# ps -eaf | grep "tape erase" root 29715 1 0 05:16:22 ttyp1 00:00:00 tape erase /dev/rStp0 root 22464 20933 1 03:40:12 ttyp6 00:00:00 grep tape eraseI've tried ... `kill -9 29715` ... but still no luck. Help... (8 Replies)
Discussion started by: Cameron
8 Replies
Login or Register to Ask a Question