I use accesslog too, try with it in both masters, I'm now using bdb, change
it to your backend definition
Migue
>> allow bind_v2
>> include /usr/local/openldap/etc/openldap/schema/core.schema
>> include /usr/local/openldap/etc/openldap/schema/corba.schema
>> include /usr/local/openldap/etc/openldap/schema/cosine.schema
>> include /usr/local/openldap/etc/openldap/schema/nis.schema
>> include
>> /usr/local/openldap/etc/openldap/schema/inetorgperson.schema
>> pidfile /usr/local/openldap/var/run/slapd.pid
>> argsfile /usr/local/openldap/var/run/slapd.args
>> modulepath /usr/local/openldap/libexec/openldap
>> moduleload syncprov
>> password-hash {SSHA}
>>
>
database bdb
suffix cn=accesslog
rootdn "cn=accesslog"
directory "/usr/local/var/access"
index default eq
index entryCSN eq
index entryUUID eq
index objectClass,reqEnd,reqResult,reqStart,reqDN,contextCSN
access to *
by dn="cn=admin,dc=ar" read
by * read
database hdb
>> suffix "dc=***,dc=com"
>> rootdn "cn=root,dc=***,dc=com"
>> rootpw {SSHA}yZkqhHmELfmUTsaQyfxgXBqq95gugTA4
>> directory /usr/local/openldap/var/openldap-data
>> index uid pres,eq
>> index cn,sn pres,eq,approx,sub
>> index objectClass eq
>> index entryCSN,entryUUID eq
>> syncrepl rid=001
>> provider=ldap://192.168.1.12
>> type=refreshAndPersist
>> retry="5 5 300 +"
>> searchbase="dc=***,dc=com"
>> attrs=*
>> binddn="cn=root,dc=***,dc=com"
>> credentials=secret
>>
>
>
>
>> overlay syncprov
>> syncprov-checkpoint 50 10
>>
>
overlay accesslog
logdb cn=accesslog
logops writes
logsuccess TRUE
logpurge 2+00:00 1+00:00
logold (objectclass=auditDelete)
logoldattr reqDeleteOldRDN
database monitor
>> loglevel 256
>>
> mirrormode true