Syslog not processing Authentication messages on ES40

"Halte, James" <[email protected]> Fri, 12 Jun 2009 09:12:39 -0700
Newsgroups gmane.os.tru64.managers,gmane.spam.detected
Message-ID <[email protected]>
Currently my ES40 server (Tru64 v.5.1B firmware level 7.3-1), is not automa=
tically sending authentication messages
to the auth.log.

1) I can however get the "/var/adm/syslog.dated/current/auth.log" to be upd=
ated by using the following:
# logger -p auth.debug "This is a test"

2) I modified the /etc/syslog.conf as follows, but still get no auth messag=
es posted.

#
# *****************************************************************
# *                                                               *
# *   Copyright 2002 Compaq Information Technologies Group, L.P.  *
# *                                                               *
# *   The software contained on this media  is  proprietary  to   *
# *   and  embodies  the  confidential  technology  of  Compaq    *
# *   Computer Corporation.  Possession, use,  duplication  or    *
# *   dissemination of the software and media is authorized only  *
# *   pursuant to a valid written license from Compaq Computer    *
# *   Corporation.                                                *
# *                                                               *
# *   RESTRICTED RIGHTS LEGEND   Use, duplication, or disclosure  *
# *   by the U.S. Government is subject to restrictions  as  set  *
# *   forth in Subparagraph (c)(1)(ii)  of  DFARS  252.227-7013,  *
# *   or  in  FAR 52.227-19, as applicable.                       *
# *                                                               *
# *****************************************************************
#
# HISTORY
#
# @(#)$RCSfile: syslog.conf,v $ $Revision: 4.1.8.1 $ (DEC) $Date: 2000/10/1=
9 19:13:52 $
#
#
# syslogd config file
#
# facilities: kern user mail daemon auth syslog lpr binary
# priorities: emerg alert crit err warning notice info debug
kern.debug        /var/adm/syslog.dated/kern.log
user.debug        /var/adm/syslog.dated/user.log
mail.debug        /var/adm/syslog.dated/mail.log
daemon.debug            /var/adm/syslog.dated/daemon.log
auth.debug        /var/adm/syslog.dated/auth.log
syslog.debug            /var/adm/syslog.dated/syslog.log
lpr.info          /var/adm/syslog.dated/lpr.log

msgbuf.err        /var/adm/crash/msgbuf.savecore

kern.debug        /var/adm/messages
kern.debug        /dev/console
user.debug        /var/adm/messages
user.debug        /dev/console
auth.debug        /dev/console
auth.debug        /var/adm/messages
*.emerg                 *

local0.notice           /dev/console
# %LGT713_BEGIN% - DO NOT MODIFY OR DELETE (Fri Feb 22 11:27:39 2008)
# The following lets NetWorker use the syslog facility
daemon.notice           /dev/console
daemon.notice           /nsr/logs/messages
daemon.notice           operator
local0.notice           /nsr/logs/summary
local0.alert            root,operator
# %LGT713_END% - DO NOT MODIFY OR DELETE

3) After changing the syslog.conf, I did restart the syslogd as follows:
# /sbin/rc3.d/S09syslog stop
# /sbin/rc3.d/S09syslog start
System error logger started
Finally, I verified that the syslogd process was running.
Tested by attempting a login from the xterm and typing the wrong password. =
Verified that NO auth.log messages were posted.

---------------------------------------------------------------------------=
--
Thank you, and please feel free to contact me by phone or email.

James Halte
Tacoma Power - T&D EMS Senior Engineer
Office: (253) 502-8094
Cell:    (253) 381-4088