Searching syslogd log messages

You can invoke the search function from different locations in the syslogd browser dialog. You can limit a search operation to a single active syslogd UNIX file, a single archive, or a combination of active syslogd UNIX files and associated available archives.

Perform the following steps to search syslogd log messages:
  1. Enter your search options and search arguments as shown in the following example:
    *------------------------- z/OS CS Syslogd Browser ---------------------------*
    OPTION ===>                                                                    
                                                                                   
    Enter your search options.                                                     
                                                                                   
      Case sensitive  ==> NO         (Yes/No) Are string arguments case sensitive? 
      Maximum hits    ==> 5          (1-99999) Max number of hits to display       
      Result DSN name ==> 'USER1.SYSLOGD.LIST'                                     
      Result DSN UNIT ==> SYSALLDA   Unit name for allocating new result DSN       
      Result DSN disp ==> 1          1:Keep, 2:Delete, 3:Display print menu        
                                                                                   
    Enter your search arguments.  All arguments will be logically ANDed.           
                                                                                   
      From date  . . .==> 2008/10/02 (yyyy/mm/dd) Search from date                 
      - and time . . .==> 10:50:00   (hh:mm:ss) - and time (24-hour clock)         
      To date  . . . .==> 2008/10/03 (yyyy/mm/dd) Search to date                   
      - and time . . .==> 02:00:00   (hh:mm:ss) - and time (24-hour clock)         
      User ID  . . . .==>            z/OS user ID of logging process               
      Job name . . . .==>            z/OS jobname of logging process               
      Rem. host name .==>                                                          
      Rem. IP address ==>                                                          
      Message tag  . .==> Pagent          Enter ? for list                         
      Process ID . . .==>            z/OS UNIX process ID                          
      String 1 . . . .==> PAPI                                                     
      String 2 . . . .==>                                                          
      String 3 . . . .==>                                                          
      String 4 . . . .==>                                                          
                                                                                   
    Message tags are typically component names.  PID availability depends on       
    options set by the logging application.  UserID and Jobnames are available     
    for local messages if syslogd is started with the -u option.                   
                                                                                   
    UserID, jobname, message tag, and remote host name will always be              
    case insensitive.                                                              
                                                                                   
    Press ENTER to start search or the END PF key to return with no search  

    Tip: The case sensitive option applies to search strings 1 - 4 only. The User ID, Job name, Message tag, and Rem. host name fields are not case sensitive.

  2. Optional: For the message tag, you can enter a message tag value to search for, or enter a question mark (?) and press the ENTER key. In that case, a selection list is displayed in which you select the message tag that is to be part of the search arguments.

    Rule: A message must match all the specified search arguments to be considered a hit.

Result: If there are many messages to search, the search might take a few seconds. A popup panel like the following example is displayed while the search is being performed:
+-----------------------------------------+
! *------ z/OS CS Syslogd Browser ------* !
!                                         !
!        *** S E A R C H I N G ***        !
!                                         !
!   1 of 4 files/dsn processed so far     !
!      90000 lines processed so far       !
!                                         !
!       10% |**..................|        !
!                                         !
!            Please be patient.           !
!                                         !
!   Halt by pressing ATTN and enter HI    !
!                                         !
+-----------------------------------------+

Sample of search results:

When the search has completed, the search results are presented in a standard ISPF view panel.

VIEW       USER1.SYSLOGD.LIST                                    24 hits found 
Command ===>                                                  Scroll ===> CSR  
****** ***************************** Top of Data ******************************
000001 z/OS CS Syslogd Browser Search Results - Date: 2 Sep 2008 Time: 12:30:26
000002                                                                         
000003 Case sensitive  . . . NO                                                
000004 Max. number of hits . 200                                               
000005 Syslogd Config  . . . 'user1.tcpcs.tcpparms(syslogt)'                   
000006 Searched files/DSNs . 4                                                 
000007     File/DSN  . . . . /var/syslog/logs/syslog.log                       
000008     File/DSN  . . . . USER1.SYSLOGT.SYSLOG.G0030V00                     
000009     File/DSN  . . . . USER1.SYSLOGT.SYSLOG.G0031V00                     
000010     File/DSN  . . . . USER1.SYSLOGT.SYSLOG.G0032V00                     
000011                                                                         
000012 Search Arguments:                                                       
000013                                                                         
000014     From date . . . . 2008/08/31                                        
000015     and time. . . . .    
000016     To date . . . . . 2008/09/03                                        
000017     and time. . . . .                                                   
000018     User ID . . . . .                                                   
000019     Job name  . . . .                                                   
000020     Remote host name.                                                   
000021     Remote IP addr. .                                                   
000022     Message tag . . . syslogd                                           
000023     Process ID  . . .                                                   
000024     String 1  . . . . FSUM                                              
000025     String 2  . . . .                                                   
000026     String 3  . . . .                                                   
000027     String 4  . . . .                                                   
000028                                                                         
000029 Line no. File or data set: /var/syslog/logs/syslog.log                 
000030 ******** **************************************************************
000031                                                                        
000032 00000001 Sep  2 00:01:00 MVS098/TCPCS    SYSLOGD  syslogd: FSUM1230 Log
000033          file /var/syslog/logs/syslog.log was created                  
000034                                                                        
000035 00000002 Sep  2 00:01:00 MVS098/TCPCS    SYSLOGD  syslogd: FSUM1230 Log
000036           file /var/syslog/logs/pagent.log was created