Visit Counter

Tuesday, February 16, 2021

Oracle Linux 7:Found /var/log/messages is Empty And Not Being Updated (Doc ID 2580481.1)

 


Found /var/log/messages is empty and no logs being written eventhough Rsyslog service is running.


Misconfiguration in /etc/rsyslog.d/ignore-systemd-session-slice.conf.



Solution


Edit /etc/rsyslog.d/ignore-systemd-session-slice.conf.

if $programname == "systemd-logind" and ($msg contains "New session" or $msg contains "Removed session" or $msg contains "Removed slice" or $msg contains "Stopping") then stop

if $programname == "systemd" and ($msg contains "Started Session" or $msg contains "Starting Session" or $msg contains "Created slice" or $msg contains "Starting user-0.slice" or $msg contains "Stopping user-0.slice" or $msg contains "Removed slice user-0.slic") then stop


Need to be changed as below .

 

if $programname == "systemd-logind" and ($msg contains "New session" or $msg contains "Removed session" or $msg contains "Removed slice" or $msg contains "Stopping") then stop

if $programname == "systemd" and ($msg contains "Started Session" or $msg contains "Starting Session" or $msg contains "Created slice" or $msg contains "Starting user-0.slice" or $msg contains "Stopping user-0.slice" or $msg contains "Removed slice user-0.slic" or $msg contains "Starting User Slice" or $msg contains "Removed slice User Slice" or $msg contains "Stopping User Slice") then stop


 After this restart the service

#systemctl restart rsyslog.service

After this check /var/log/messages .