Re: [evlog-dev] Program name issue
Hien Nguyen <[email protected]> Fri, 31 Oct 2003 10:04:33 -0800
| Newsgroups | gmane.linux.kernel.event-logging |
|---|---|
| Message-ID | <[email protected]> |
Oops, the 'make install' should be make -f Makefile.mk install (as root) Regards, Hien. Hien Nguyen wrote: > Hi Seo, > > Attach is a patch for the libevlsyslog (syslog forwarder). With this > patch the syslog forwarder will capture the ident and pid (if specified > by the caller). > > You should apply this patch against the evlog-1.5.3 source tree. > > > Applying patch > -------------- > copy the patch to your evlog source dir > > cd evlog > patch -p01 < libevlsyslog.patch > > Build evlog and install libevlsyslog > ------------------------------------ > cd user > make -f Makefile.mk > cd user/libevlsyslog > make install (as root) > > > Please let me know if you have any problem. > > Regards, Hien. > > > > O'Riordain, Seosamh wrote: > >> Hi Hien, >> >> I used the syslog forwarder. The syslogat API needs to >> be used within the application to make use of it's features. >> That's good for new applications but I'm looking at gathering >> the logs from existing OS applications (eg DHCP, NIS,NTP,Samba,etc) >> from multiple servers to a central location (and I don't want to touch >> their code!). It's been decided that the syslog ident string is a >> piece of information >> that's not acceptable to lose - hence we need it but still want to use >> the full capabilities of evlog. >> >> I've now started to look at adding an "ident=<tag>" attribute to >> the log entry structure. Just curious if someone else has done this >> (or wanted this) before ? >> >> Regards, >> Seo >> >> -----Original Message----- >> From: Hien Nguyen [mailto:[email protected]] Sent: 30 October 2003 19:50 >> To: O'Riordain, Seosamh >> Cc: [email protected] >> Subject: Re: [evlog-dev] Program name issue >> >> >> Hi Seo, >> >> May I ask you how did you log the events to evlog? did they come from >> syslogat api or you just turned on the syslog forwarder? >> >> Notes: For more information about syslogat see man page for evlgentmpls. >> >> Thanks, Hien. >> >> >> O'Riordain, Seosamh wrote: >> >>> Hi, >>> >>> I've been looking at using evlog as a replacement for syslog, and also >> >> >> >>> for being a central log consolidator. Now it provides plenty of >>> excellent features that I can and want to use. The only thing it >>> doesn't provide compared to syslog, is the program >>> name. See below, for a comparison in output of syslog and evlog >> >> >> created >> >>> by doing an rsh >>> to a machine. >>> >>> /var/log/messages extract >>> Oct 30 11:33:46 angel2 pam_rhosts_auth[27509]: allowed to root@angel3 as >>> root >>> Oct 30 11:33:46 angel2 login(pam_unix)[27510]: session opened for user >> >> >> >>> root by (uid=0) >>> Oct 30 11:33:46 angel2 login -- root[27510]: ROOT LOGIN ON pts/1 FROM >>> angel3 >>> >>> evlview -n --syslog >>> Oct 30 11:33:46 angel2 allowed to root@angel3 as root >>> Oct 30 11:33:46 angel2 session opened for user root by (uid=0) Oct 30 >>> 11:33:46 angel2 ROOT LOGIN ON pts/1 FROM angel3 >>> >>> On the central log server, when viewing the logs for this host (current >>> or archived) one would >>> not be able to tell what program caused these or whether one used rsh >> >> >> or >> >>> some other login mechanism, >>> say ssh. >>> >>> My questions become, was this a deliberate decision not to provide the >>> program name >>> in evlog ? >>> What would it take to provide this functionality ? >>> Thanks. >>> >>> /Regards/Seo >>> >> >> >> >> >> >> ------------------------------------------------------- >> This SF.net email is sponsored by: SF.net Giveback Program. >> Does SourceForge.net help you be more productive? Does it >> help you create better code? SHARE THE LOVE, and help us help >> YOU! Click Here: http://sourceforge.net/donate/ >> _______________________________________________ >> evlog-developers mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/evlog-developers >> > > > ------------------------------------------------------------------------ > > --- /home/nguyhien/prj/sandbox/v1.5.3/evlog/user/libevlsyslog/libevlsyslog.c Wed Nov 13 16:36:52 2002 > +++ evlog/user/libevlsyslog/libevlsyslog.c Thu Oct 30 14:02:39 2003 > @@ -39,7 +39,7 @@ > static int _evlSysBlockSignals(sigset_t *oldset); > static void _evlSysRestoreSignals(sigset_t *oldset); > static int _evlSysGetProcId(); > -static int_nonBlkConnection(const char *socketpath, struct sockaddr_un *sa, int nsec); > +static int _nonBlkConnection(const char *socketpath, struct sockaddr_un *sa, int nsec); > > /* > * Globals copied from glibc-2.2.3/misc/syslog.c > @@ -47,6 +47,8 @@ > static int LogMask = 0xff; /* mask of priorities to be logged > */ > static int LogFacility = LOG_USER; /* default facility code */ > +static int LogOption = 0; > +static const char *LogIdent = "syslog"; > > static char libclibrary[40]; > static char *configFile = "/etc/evlog.d/libevlsyslog.conf"; > @@ -187,7 +189,7 @@ > { > char evlbuf[POSIX_LOG_ENTRY_MAXLEN + REC_HDR_SIZE + 1]; > char *plog_data, *pheader; > - int log_data_size; > + int log_data_size = 0; > > struct posix_log_entry entry; > int gotTimeStamp = 0; > @@ -217,7 +219,23 @@ > /* Fill the buffer with log data first so we can get the length */ > pheader = evlbuf; > plog_data = pheader + REC_HDR_SIZE; > - log_data_size = vsnprintf(plog_data, POSIX_LOG_ENTRY_MAXLEN, fmt, ap); > + if (LogIdent) { > + strcpy(plog_data, LogIdent); > + log_data_size = strlen(plog_data); > + plog_data +=log_data_size; > + } > + if (LogOption & LOG_PID) { > + sprintf(plog_data, "[%d]", getpid()); > + log_data_size += strlen(plog_data); > + plog_data += strlen(plog_data); > + } > + if (LogIdent) { > + *plog_data++ = ':'; > + *plog_data++ = ' '; > + log_data_size += 2; > + } > + > + log_data_size += vsnprintf(plog_data, POSIX_LOG_ENTRY_MAXLEN, fmt, ap); > > /* Capture the time stamp ASAP. */ > #ifdef _POSIX_TIMERS_1 > @@ -294,6 +312,9 @@ > openlog (const char *ident, int logstat, int logfac) > { > LogFacility = logfac; > + LogOption = logstat; > + if (ident != NULL) > + LogIdent = ident; > glibc_openlog(ident, logstat, logfac); > } > ------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code? SHARE THE LOVE, and help us help YOU! Click Here: http://sourceforge.net/donate/