[Webinar] Streamline your web hosting managementRegister Today

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 278
  • Last Modified:

Where are the logs/how do you turn on logging in AIX?

We have an AIX system no one knows how to use. We need to see the log files (standard /var/log/ stuff in Linux) but apparently it's not there... I'm assuming thats because its not turned on.

How do you find the logs or enable them in AIX?

0
edskee
Asked:
edskee
  • 4
  • 4
  • 2
1 Solution
 
freesourceCommented:
Look in /var/adm

To enable logs read the man pages, AIX has syslogd just like Linux.
0
 
tfewsterCommented:
/etc/syslog.conf defines what is logged (& where) by syslogd
0
 
edskeeAuthor Commented:
Freesource: if I wanted someone to tell me to read the man pages I would not have posted the question here. Jeez.
0
The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

 
tfewsterCommented:
To be fair to freesource, s/he probably meant "read  the man page for syslogd".

From what I can see on the AIX box I have access to, the default location for the syslog log IS /var/log - So it's not there, someone has been messing about with /etc/syslog.conf, and may even have disabled syslogd (started by srcmstr)
0
 
edskeeAuthor Commented:
My /etc/syslog.conf file is all commented out. Can someone post a 'standard' copy of their /etc/syslog.conf file? The man page for syslogd is a bit confusing.

Thanks!

Oh, I don't have syslogd running in my process list, however I do have /usr/sbin/syslog running... any ideas?
0
 
tfewsterCommented:
This standard setup will log just about everything to /var/log/syslog; Comprehensive, but irritating.
#
*.info                  /var/log/syslog
mail.debug              /var/log/maildebug
lpr.debug               /var/log/lpr.log

In AIX  4.3, it's /usr/sbin/syslogd - what's the parent process for your syslog process?
0
 
edskeeAuthor Commented:
The main things we want to log are the user logins, so we can see who is coming in when.

The parent process? Dunno, whats the easiest way to find out?
0
 
tfewsterCommented:
I suggest you use "last" for tracking logins; It shows user, login device & login times. e.g. last |grep tfewster would show you my login history.

syslog will mainly show you errors, e.g. bad "su" attempts.

To find the parent process, I was thinking of
ps -f |grep syslog to get it's parent process id, then  ps -f |grep parent_process_id - sloppy, but quick.
0
 
edskeeAuthor Commented:
Close enough... got me what I needed, thanks!
0
 
freesourceCommented:
Thanks, tfewster, that's exactly what I meant.  And edskee read the man page on syslog.conf it goes into a lot more detail.
0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

  • 4
  • 4
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now