All ok. I didn't compile with imsolaris. Ayelet Regev-Dabah Sent from my iPhone
On 11 באוג 2011, at 13:34, Rainer Gerhards <[email protected]> wrote: > As usual, patch -p1 < patchfile > >> -----Original Message----- >> From: [email protected] [mailto:rsyslog- >> [email protected]] On Behalf Of Ayelet Regev >> Sent: Thursday, August 11, 2011 12:34 PM >> To: rsyslog-users >> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >> >> How do I apply this patch? >> >> Ayelet Regev-Dabah >> Sent from my iPhone >> >> >> On 11 באוג 2011, at 13:33, Rainer Gerhards <[email protected]> >> wrote: >> >>> Pls try attached patch and send debug log. Note that I currently do >> not have >>> solaris at hand, so I could not compile-test the patch. Expect minor >> quircks, >>> should be easy to fix. >>> >>> Rainer >>> >>>> -----Original Message----- >>>> From: [email protected] [mailto:rsyslog- >>>> [email protected]] On Behalf Of Rainer Gerhards >>>> Sent: Thursday, August 11, 2011 12:25 PM >>>> To: rsyslog-users >>>> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >>>> >>>>> -----Original Message----- >>>>> From: [email protected] [mailto:rsyslog- >>>>> [email protected]] On Behalf Of Ayelet Regev >>>>> Sent: Thursday, August 11, 2011 12:23 PM >>>>> To: rsyslog-users >>>>> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >>>>> >>>>> No, now it worse events are not logged anywhere... >>>> >>>> OK, I see if I can craft a patch quickly so that weg et more info. I >>>> don't >>>> see the actual PRI as it comes in. But I see that none of the >> filters >>>> match. >>>> >>>> RAiner >>>>> >>>>> On Thu, Aug 11, 2011 at 1:21 PM, Ayelet Regev >>>>> <[email protected]>wrote: >>>>> >>>>>> No, now it worse events are not logged anywhere. >>>>>> >>>>>> Ayelet Regev-Dabah >>>>>> Sent from my iPhone >>>>>> >>>>>> >>>>>> On 11 באוג 2011, at 13:13, "Rainer Gerhards" >>>>> <[email protected]> >>>>>> wrote: >>>>>> >>>>>> -----Original Message----- >>>>>> >>>>>> From: [email protected] [mailto:rsyslog- >>>>>> >>>>>> [email protected]] On Behalf Of Ayelet Regev >>>>>> >>>>>> Sent: Thursday, August 11, 2011 11:36 AM >>>>>> >>>>>> To: rsyslog-users >>>>>> >>>>>> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >>>>>> >>>>>> >>>>>> Sorry, this time my event dosnt log anywhere... >>>>>> >>>>>> >>>>>> Does that mean the original problem is solved? If not, I'll create >>>> a >>>>> patch >>>>>> for you, as I don't see the PRI in the current debug log... >>>>>> RAiner >>>>>> >>>>>> >>>>>> On Thu, Aug 11, 2011 at 10:04 AM, Rainer Gerhards >>>>>> >>>>>> <[email protected]>wrote: >>>>>> >>>>>> >>>>>> OK, I should remind myself not to check for bugs in older versions >>>> ;) >>>>>> >>>>>> This >>>>>> >>>>>> one is fixed in 4.7.4... >>>>>> >>>>>> >>>>>> Rainer >>>>>> >>>>>> >>>>>> -----Original Message----- >>>>>> >>>>>> From: [email protected] [mailto:rsyslog- >>>>>> >>>>>> [email protected]] On Behalf Of Ayelet Regev >>>>>> >>>>>> Sent: Wednesday, August 10, 2011 7:05 PM >>>>>> >>>>>> To: rsyslog-users >>>>>> >>>>>> Subject: Re: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >>>>>> >>>>>> >>>>>> Hi Rainer, >>>>>> >>>>>> >>>>>> Thanks for the quick response. >>>>>> >>>>>> Attched. >>>>>> >>>>>> >>>>>> On Wed, Aug 10, 2011 at 6:51 PM, Rainer Gerhards >>>>>> >>>>>> <[email protected]>wrote: >>>>>> >>>>>> >>>>>> Can you provide a debug log that contains an occurence of this >>>>>> >>>>>> problem? >>>>>> >>>>>> This >>>>>> >>>>>> helps us understand what happens. >>>>>> >>>>>> >>>>>> Rainer >>>>>> >>>>>> >>>>>> -----Original Message----- >>>>>> >>>>>> From: [email protected] [mailto:rsyslog- >>>>>> >>>>>> [email protected]] On Behalf Of Ayelet Regev >>>>>> >>>>>> Sent: Wednesday, August 10, 2011 10:00 AM >>>>>> >>>>>> To: <[email protected]>[email protected] >>>>>> >>>>>> Subject: [rsyslog] rsyslog 4.7.2 weird bahaviour on Solaris 10 >>>>>> >>>>>> >>>>>> ** <[email protected]> >>>>>> >>>>>> >>>>>> Hi All, >>>>>> >>>>>> >>>>>> Im testing rsyslog 4.7.2 on Solaris 10. >>>>>> >>>>>> >>>>>> You may see below my syslog-client.conf file. >>>>>> >>>>>> >>>>>> Im running the rsyslog with these parameters and I have >>>>>> >>>>>> validated >>>>>> >>>>>> config >>>>>> >>>>>> file.: >>>>>> >>>>>> (I had to comment imklog module loading and listener commands >>>>>> >>>>>> to >>>>>> >>>>>> make >>>>>> >>>>>> it >>>>>> >>>>>> work without errors.) >>>>>> >>>>>> My biggest problem at the moment is that all events are written >>>>>> >>>>>> to >>>>>> >>>>>> /tmp/kuku >>>>>> >>>>>> no matter their severity... >>>>>> >>>>>> Im executing "logger -p "mail.emerg" "test"" and its written >>>>>> >>>>>> into >>>>>> >>>>>> /tmp/kuku >>>>>> >>>>>> and not to the correct file. >>>>>> >>>>>> >>>>>> Your help is more then apprichiated.... >>>>>> >>>>>> >>>>>> smu15a:/ ROOT > /usr/local/sbin/rsyslogd -c4 -f /etc/rsyslog- >>>>>> >>>>>> client.conf >>>>>> >>>>>> >>>>>> >>>>>> smu15a:/ ROOT > /usr/local/sbin/rsyslogd -c4 -f /etc/rsyslog- >>>>>> >>>>>> client.conf -N4 >>>>>> >>>>>> rsyslogd: version 4.7.2, config validation run (level 4), >>>>>> >>>>>> master >>>>>> >>>>>> config >>>>>> >>>>>> /etc/rsyslog-client.conf >>>>>> >>>>>> rsyslogd: End of config validation run. Bye >>>>>> >>>>>> >>>>>> >>>>>> >>>>>> # Modules >>>>>> >>>>>> >>>>>> $ModLoad imtcp >>>>>> >>>>>> $ModLoad imudp >>>>>> >>>>>> #$ModLoad imuxsock >>>>>> >>>>>> $ModLoad imsolaris >>>>>> >>>>>> #$ModLoad imklog >>>>>> >>>>>> >>>>>> # Templates >>>>>> >>>>>> # log every host in its own directory >>>>>> >>>>>> #$template >>>>>> >>>>>> >>>>>> >>>>>> >>>>> >>>> >> RemoteHost,"/var/syslog/hosts/%HOSTNAME%/%$YEAR%/%$MONTH%/%$DAY%/syslog >>>>>> >>>>>> .log" >>>>>> >>>>>> ### Rulesets >>>>>> >>>>>> # Local Logging >>>>>> >>>>>> $RuleSet local >>>>>> >>>>>> ###user,daemon,uucp,cron,mark.notice >>>>>> >>>>>> /var/adm/messages >>>>>> >>>>>> user.notice /tmp/kuku >>>>>> >>>>>> ###kern.debug >>>>>> >>>>>> /var/adm/messages >>>>>> >>>>>> ###*.emerg;mail.none * >>>>>> >>>>>> #Central logging events >>>>>> >>>>>> #Security logs >>>>>> >>>>>> auth,authpriv.debug /var/log/central/auth.debug >>>>>> >>>>>> #MIPS applicaation logs >>>>>> >>>>>> mail.emerg /var/log/central/MIPSlog >>>>>> >>>>>> #Comverse applications events (other than MIPS) >>>>>> >>>>>> local0.debug /var/log/central/local0.debug >>>>>> >>>>>> #Strore local4 events in /var/log/central/traceall >>>>>> >>>>>> local4.debug /var/log/central/traceall >>>>>> >>>>>> local6.debug >>>>>> >>>>>> /var/cti/logs/SDT/SDT_Audit_Information.log >>>>>> >>>>>> # use the local RuleSet as default if not specified otherwise >>>>>> >>>>>> $DefaultRuleset local >>>>>> >>>>>> # Remote Logging >>>>>> >>>>>> $RuleSet remote >>>>>> >>>>>> *.crit @localhost:666 >>>>>> >>>>>> # Send messages we receive to Gremlin >>>>>> >>>>>> ### Listeners >>>>>> >>>>>> # bind ruleset to tcp listener >>>>>> >>>>>> ###$InputTCPServerBindRuleset remote >>>>>> >>>>>> # and activate it: >>>>>> >>>>>> $InputTCPServerRun 50514 >>>>>> >>>>>> ###$InputUDPServerBindRuleset remote >>>>>> >>>>>> $UDPServerRun 514 >>>>>> >>>>>> $UDPServerRun 1514 >>>>>> >>>>>> >>>>>> >>>>>> Ayelet Regev-Dabah >>>>>> >>>>>> System Software Platform TL >>>>>> >>>>>> *Comverse >>>>>> >>>>>> *Office: +972 3 6459362 >>>>>> >>>>>> *[email protected]* <[email protected]> >>>>>> >>>>>> *www.comverse.com* <http://www.comverse.com/> >>>>>> >>>>>> >>>>>> >>>>>> >>>>>> * ________________________________ * >>>>>> >>>>>> "This e-mail message may contain confidential, commercial or >>>>>> >>>>>> privileged >>>>>> >>>>>> information that constitutes proprietary information of >>>>>> >>>>>> Comverse >>>>>> >>>>>> Technology >>>>>> >>>>>> or its subsidiaries. If you are not the intended recipient of >>>>>> >>>>>> this >>>>>> >>>>>> message, >>>>>> >>>>>> you are hereby notified that any review, use or distribution of >>>>>> >>>>>> this >>>>>> >>>>>> information is absolutely prohibited and we request that you >>>>>> >>>>>> delete >>>>>> >>>>>> all >>>>>> >>>>>> copies and contact us by e-mailing to: [email protected]. >>>>>> >>>>>> Thank >>>>>> >>>>>> You." >>>>>> >>>>>> _______________________________________________ >>>>>> >>>>>> rsyslog mailing list >>>>>> >>>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>>> >>>>>> http://www.rsyslog.com >>>>>> >>>>>> _______________________________________________ >>>>>> >>>>>> rsyslog mailing list >>>>>> >>>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>>> >>>>>> http://www.rsyslog.com >>>>>> >>>>>> >>>>>> _______________________________________________ >>>>>> >>>>>> rsyslog mailing list >>>>>> >>>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>>> >>>>>> http://www.rsyslog.com >>>>>> >>>>>> >>>>>> _______________________________________________ >>>>>> >>>>>> rsyslog mailing list >>>>>> >>>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>>> >>>>>> http://www.rsyslog.com >>>>>> >>>>>> _______________________________________________ >>>>>> rsyslog mailing list >>>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>>> http://www.rsyslog.com >>>>>> >>>>>> >>>>> _______________________________________________ >>>>> rsyslog mailing list >>>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>>> http://www.rsyslog.com >>>> _______________________________________________ >>>> rsyslog mailing list >>>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>>> http://www.rsyslog.com >>> <solaris.patch> >>> _______________________________________________ >>> rsyslog mailing list >>> http://lists.adiscon.net/mailman/listinfo/rsyslog >>> http://www.rsyslog.com >> _______________________________________________ >> rsyslog mailing list >> http://lists.adiscon.net/mailman/listinfo/rsyslog >> http://www.rsyslog.com > _______________________________________________ > rsyslog mailing list > http://lists.adiscon.net/mailman/listinfo/rsyslog > http://www.rsyslog.com _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com

