Re: Bind9 im chroot loggt trotz vorhandenem Log-Socket nicht

From: Bernd Walter <ticso(at)cicely8.cicely.de>
Date: Wed, 6 Nov 2002 14:16:14 +0100

On Wed, Nov 06, 2002 at 01:19:43PM +0100, Bjoern Engels wrote:
> # /usr/sbin/syslogd -ss -l /var/namedb/var/run/log -d
> can't open /dev/klog (2)
> off & running....
> init
> cfline("*.err;kern.debug;auth.notice;mail.crit /dev/console",
> f, "*", "*")
> cfline("*.notice;kern.debug;lpr.info;mail.crit;news.err
> /var/log/messages", f, "*", "*")
> cfline("security.*
> /var/log/security", f, "*", "*")
> cfline("mail.info
> /var/log/maillog", f, "*", "*")
> cfline("lpr.info
> /var/log/lpd-errs", f, "*", "*")
> syslogd: /var/log/lpd-errs: No such file or directory
> logmsg: pri 53, flags 4, from news, msg syslogd: /var/log/lpd-errs: No
> such file or directory
> Logging to CONSOLE /dev/console
> cfline("cron.* /var/log/cron",f, "*", "*")
> cfline("*.err root", f, "*", "*")
> cfline("*.notice;news.err root", f, "*", "*")
> cfline("*.alert root", f, "*", "*")
> cfline("*.emerg *", f, "*", "*")
> cfline("*.* /var/log/slip.log", f, "startslip", "*")
> cfline("*.* /var/log/ppp.log", f, "ppp", "*")
> 7 3 2 3 5 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 X FILE: /dev/console
> 7 5 2 5 5 5 6 3 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 X FILE:/var/log/messages
> X X X X X X X X X X X X X 8 X X X X X X X X X X X FILE:/var/log/security
> X X 6 X X X X X X X X X X X X X X X X X X X X X X FILE: /var/log/maillog
> X X X X X X 6 X X X X X X X X X X X X X X X X X X UNUSED:
> X X X X X X X X X 8 X X X X X X X X X X X X X X X FILE: /var/log/cron
> 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 X USERS: root,
> 5 5 5 5 5 5 5 3 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 5 X USERS: root,
> 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 X USERS: root,
> 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 X WALL:
> 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 X FILE:/var/log/slip.log
> (startslip)
> 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 8 X FILE: /var/log/ppp.log
> (ppp)
> logmsg: pri 56, flags 4, from news, msg syslogd: restart
> syslogd: restarted
> logmsg: pri 36, flags 0, from news, msg Nov 6 10:29:11 named[57247]:
> client 192.168.101.30#1366: query: stderr.mydailyoffers.com IN MX
> logmsg: pri 36, flags 0, from news, msg Nov 6 10:29:16 named[57247]:
> client 192.168.101.30#1368: query: stdin-bs-01.mydailyoffers.com IN
> AAAA
> logmsg: pri 36, flags 0, from news, msg Nov 6 10:29:21 named[57247]:
> client 192.168.101.30#1370: query: stdin-bs-01.mydailyoffers.com IN A
> logmsg: pri 36, flags 0, from news, msg Nov 6 10:29:23 named[57247]:
> client 192.168.101.30#1371: query: 69.113.9.217.in-addr.arpa IN PTR

pri 56 ist LOG_NEWS(7)/LOG_EMERG(0)
pri 36 ist LOG_WARNING(4)/LOG_AUTH(4)
Erscheint mir bei dem Inhalt unlogisch.
Der Bind sollte die Einträge als LOG_DAEMON veschicken.
Eigendlich müssten die Pri 36 Nachrichten nach Spalte 4 in
/var/log/messages und an den User root gehen, da die Zeilen >=4 stehen
haben.

Normalerweise sollte das dann auch da stehen:
logmsg: pri 26, flags 0, from cicely5, msg Nov 6 13:46:48 sendmail[14866]: STARTTLS=server, relay=gif-cicely.cosmo-project.de [IPv6:3ffe:400:8d0:101::2], version=TLSv1/SSLv3, verify=OK, cipher=EDH-RSA-DES-CBC3-SHA, bits=168/168
Logging to FILE /var/log/maillog
Logging to FILE /var/log/all.log

Im Fall des fehlenden lpd-errs File schreibt er das ja auch.
Ich bin da jetzt auch ein wenig ratlos.

-- 
B.Walter              COSMO-Project         http://www.cosmo-project.de
ticso(at)cicely.de         Usergroup           info(at)cosmo-project.de
To Unsubscribe: send mail to majordomo(at)de.FreeBSD.org
with "unsubscribe de-bsd-questions" in the body of the message
Received on Wed 06 Nov 2002 - 14:16:23 CET

search this site