12-30-2008
HI redoubtable,
Can you please elaborate further on ptrace() solution?
Ya, your suggestion "man-in-middle" is great, but again I need an access to the configuration files and its really do-able if I get to edit syslog.conf. Thanks for the input.
Panos method is also good enough and its similar to the way tail utility has been implemented and I've incorporated this too in my solution and used fstat() to look for the file size changes and lseek() to adjust file pointer and waiting with nanosleep() before subsequent fstat() calls.
Looking further to have another round of discussion on ptrace() .
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
Which programm, deamon or script is responsible for filling the file /var/log/messages ? (1 Reply)
Discussion started by: Cozmic
1 Replies
2. Solaris
hi sirs
can u tell the difference between /var/log/syslogs and /var/adm/messages
in my working place i am having two servers.
in one servers messages file is empty and syslog file is going on increasing..
and in another servers message file is going on increasing but syslog file is... (2 Replies)
Discussion started by: tv.praveenkumar
2 Replies
3. UNIX for Advanced & Expert Users
The /var/adm/messages in Solaris seem to log more system messages/errors compared to /var/log/messages in Linux.
I checked the log level in Linux and they seem OK.
Is there any other log file that contains the messages or is it just that Linux doesn't log great many things? (2 Replies)
Discussion started by: gomes1333
2 Replies
4. Solaris
Hi,
Is the contents in /var/log/syslog and /var/adm/messages are same??
Regards (3 Replies)
Discussion started by: vks47
3 Replies
5. Shell Programming and Scripting
How can view log messages between two time frame from /var/log/message or any type of log files.
when logfiles are very big and especially many messages with in few minutes, I would like to display log messages between 5 minute interval.
Could you pls give me the command? (1 Reply)
Discussion started by: johnveslin
1 Replies
6. UNIX for Dummies Questions & Answers
Whenever a user uses su I get the following error messages in /var/log/messages:
Nov 23 04:24:55 <REMOVED> abrt: saved core dump of pid 26141 (/usr/libexec/fprintd) to /var/spool/abrt/ccpp-1322018695-26141.new/coredump (753664 bytes)
Nov 23 04:24:55 <REMOVED> abrtd: Directory... (3 Replies)
Discussion started by: JakesHat
3 Replies
7. SuSE
How are you?
SUSE V10 and 11.
In /var/log/messages I see these lines in some servers. I'd like to know what causes these errors and how to fix them.
Thank you,
error: PAM: Authentication failure for root from XXXXXXXX
Did not receive identification string from XXXXXXX
Invalid user suse-gm... (2 Replies)
Discussion started by: JDBA
2 Replies
8. Shell Programming and Scripting
Below is my script to log all the command input by any user to /var/log/messages. But I cant achieve the desired output that i want. PLease see below.
function log2syslog
{
declare COMMAND
COMMAND=$(fc -ln -0)
logger -p local1.notice -t bash -i -- "$USER:$COMMAND"
}
trap... (12 Replies)
Discussion started by: invinzin21
12 Replies
9. Shell Programming and Scripting
I have been searching and reading about syslog. I would like to know how to Transfer the logs being thrown into /var/log/messages into another file example /var/log/volumelog.
tail -f /var/log/messages
dblogger: msg_to_dbrow: no logtype using missing
dblogger: msg_to_dbrow_str: val ==... (2 Replies)
Discussion started by: kenshinhimura
2 Replies
10. Red Hat
I am getting a lot of message as follows in /var/log/message files as follows.
messages.1:559:May 4 20:01:56 SERVER2 kernel: session_stat: sync=0 async=33 aretr=0
messages.1:560:May 4 20:02:42 SERVER2 kernel: session_stat: dev=fd:5 state=6 blksize=4096 mmapsize=262144
messages.1:561:May 4... (2 Replies)
Discussion started by: Anjan Ganguly
2 Replies
strerr(1M) System Administration Commands strerr(1M)
NAME
strerr - STREAMS error logger daemon
SYNOPSIS
strerr
DESCRIPTION
strerr receives error log messages from the STREAMS log driver (see log(7D)) and appends them to a log file. The resultant error log files
reside in the directory /var/adm/streams, and are named error.mm-dd, where mm is the month and dd is the day of the messages contained in
each log file.
The format of an error log message is:
<seq> <time> <ticks> <flags> <mid> <sid> <text>
<seq> error sequence number
<time> time of message in hh:mm:ss
<ticks> time of message in machine ticks since boot priority level
<flags> T : the message was also sent to a tracing process F : indicates a fatal error N : send mail to the system administrator
(hardcoded as root)
<mid> module ID number of source
<sid> sub-ID number of source
<text> formatted text of the error message
Messages that appear in the error log are intended to report exceptional conditions that require the attention of the system administrator.
Those messages which indicate the total failure of a STREAMS driver or module should have the F flag set. Those messages requiring the
immediate attention of the administrator will have the N flag set, which causes the error logger to send the message to the system adminis-
trator using mail. The priority level usually has no meaning in the error log but will have meaning if the message is also sent to a tracer
process.
Once initiated, strerr continues to execute until terminated by the user. It is commonly executed asynchronously.
FILES
/var/adm/streams/error.mm-dd error log file.
ATTRIBUTES
See attributes(5) for descriptions of the following attributes:
+-----------------------------+-----------------------------+
| ATTRIBUTE TYPE | ATTRIBUTE VALUE |
+-----------------------------+-----------------------------+
|Availability |SUNWcsu |
+-----------------------------+-----------------------------+
SEE ALSO
attributes(5), log(7D)
STREAMS Programming Guide
NOTES
There is no restriction to the number of strerr processes opening the STREAMS log driver at a time.
If a module or driver is generating a large number of error messages, running the error logger will cause a degradation in STREAMS perfor-
mance. If a large burst of messages are generated in a short time, the log driver may not be able to deliver some of the messages. This
situation is indicated by gaps in the sequence numbering of the messages in the log files.
SunOS 5.10 4 Oct 1994 strerr(1M)