Safeguard Authentication Services (SAS) 7.0 introduces a new vastool debug capability that allows administrators to easily enable and disable enhanced debug logging for troubleshooting. This feature automatically configures system logging to capture vasd and related system debug output into a single log file, simplifying data collection for Support.
Use this procedure when troubleshooting authentication, authorization, or vasd-related issues and One Identity Support has requested debug logs.
Run the following command as root:
vastool debug enable
This command performs the following actions automatically:
rsyslog)/var/log/sas_debug.log
vasd is not restarted automatically.After enabling debug logging, reproduce the problem you are experiencing (for example, failed authentication, command execution, or domain communication issues).
Once the issue has been reproduced, disable debug logging:
vastool debug disable
This command:
/var/log/sas_debug.log.gz
Upload the following file to your active One Identity Support case:
/var/log/sas_debug.log.gz
[root@cs-redhat1 /]# vastool debug enable
Detected <rsyslog>
Backing up file </etc/systemd/journald.conf> to </etc/systemd/journald.conf.backup>
Modifying </etc/systemd/journald.conf> to disable rate limiting
Restarting journald
Backing up file </etc/rsyslog.conf> to </etc/rsyslog.conf.backup>
Modifying </etc/rsyslog.conf> for debug capture to </var/log/sas_debug.log>
Restarting rsyslog
vasd / system debug logging enabled to </var/log/sas_debug.log>
vasd has NOT been restarted, debug should start within 30 seconds
[root@cs-redhat1 /]# vastool debug disable
Detected <rsyslog>
Restoring file </etc/systemd/journald.conf> from </etc/systemd/journald.conf.backup>
Restarting journald
Restoring file </etc/rsyslog.conf> from </etc/rsyslog.conf.backup>
Restarting rsyslog
vasd / system debug has been disabled and output compressed to </var/log/sas_debug.log.gz>
sas_debug.log.gz before uploading unless instructed by Support.If the issue persists after providing the debug logs, One Identity Support may request additional system information or configuration files as part of the investigation such as /var/log/secure and /var/log/messages.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center