Can you verify syslog has the file opened (something like 'lsof -w -n -p `pgrep syslog`' or a 'pgrep -f syslog' and 'fuser /var/log/messages' combo)? Can you verify using something like 'logger PING' an entry can be made? What does your syslog.conf look like? If necessary, can you trace back changes made to the conf, package contents, kernel?
|