Overload Logs
Mar 25, 2008I think my apache is killing my servers with crazy overload with logs... how do I turn this off?
View 2 RepliesI think my apache is killing my servers with crazy overload with logs... how do I turn this off?
View 2 Repliesis it possiable to delete these files in the server access_logs and errors_logs
View 1 Replies View Relatedi have vps 512 MB ram From  HostForWeb  working Fine! in 160 websites! Hosted 
But! in swvps.com with 2 gig ram! Low Working! OverLoad and CPU Usage is Red Alert
But HostForWeb VPS with 512 MB Ram good Working  I Dont Know Why SWvps.com Is Low with 2 gig ram for me?
I am not sure if my dedicated server is being attacked or if it is legitimate traffic.  I need help figuring out the difference and if it is an attack, how to prevent it, and if it is legitimate traffic, how to configure the server to handle the load.
My server information is below:
HardwareIntel Xeon 3220-Quad Core [2.4GHz
8GB DDR2
SATAII 500GB
SoftwareCentOS 5.3-32
Apache2
MySQL 5
PHP 5
When I do ps aux|grep httpd|wc -l I get the count of current connected clients of 259 which is always maxing out my MaxClients of 256.  I had increased it to 512, and it maxed out, I had increased it to 1024 and it maxed out, and lastly I had setup to 2048 and it works, but slows the entire server down.
currently i purchase a reseller. when i click in server status, i found out that the detail is as below:
 
cpsrvd up [green]
Server Load 5.41 (1 cpu) [red]
Memory Used 46.7 % [green]
Swap Used 9.51 %  [green]
Disk /dev/sda1 (/boot) 13 %  [green]
Disk /dev/sdb (/mount) 57 %  [green]
Disk /dev/sda3 (/) 88 %  [yellow]
i found that the server load is in red color, and the last item Disk/dev/sda3 is in yellow color. may i know what is the problem?
My server is out of memory....how do I find which script or domain is causing for memory abuse on server?
Its Plesk server 3.0Ghz + 1GB Ram
the server is overloaded some times during a day.
There is one process of httpd witch use 80-90% of memory. Load increases to 90 or 200 :/
I installed strace and when the process appeared I run on that process and there is:
mmap(NULL, 364544, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2b25e60000
There is a lot of that entries.
I am using a AP7901, and at 12AMP I am getting a red led status overload. At 11AMP the led is green status, which is perfect.
 
Is this a problem? Shouldn't I be able to use 16AMP? Is it safe/ok to use more AMP?
My webserver keeps on overloading, causing pages to lag and mysql connections to get clogged. Each time it overloads, it's because of there being too many MySQL connections, and I really just don't know why there are so many. I am not sure whether someone is sabotaging my server or whether there is a hole in my php scripts that causes an abundance of connections, or some very slow query.
View 2 Replies View RelatedIm using Vmware on dedicated server:
each 2 Intel(R) Xeon(TM) CPU 3.00GHz
1- in vmware show: 
2 CPUs x 2 Cores
but i check in SSH we have 7 core ! 
Code:
# cat /proc/cpuinfo
processor       : 0
vendor_id       : GenuineIntel
cpu family      : 15
model           : 6
model name      :                   Intel(R) Xeon(TM) CPU 3.00GHz
stepping        : 4
cpu MHz         : 7680.000
cache size      : 2048 KB
physical id     : 0
siblings        : 4
core id         : 0
cpu cores       : 2
apicid          : 0
fpu             : yes
fpu_exception   : yes
cpuid level     : 6
wp              : yes
flags           : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm syscall nx lm constant_tsc pni monitor ds_cpl vmx est cid cx16 xtpr lahf_lm
bogomips        : 6012.44
clflush size    : 64
cache_alignment : 128
address sizes   : 36 bits physical, 48 bits virtual
power management:
processor       : 1
vendor_id       : GenuineIntel
cpu family      : 15
model           : 6
model name      :                   Intel(R) Xeon(TM) CPU 3.00GHz
stepping        : 4
cpu MHz         : 5120.000
cache size      : 2048 KB
physical id     : 1
siblings        : 4
core id         : 0
cpu cores       : 2
apicid          : 4
fpu             : yes
fpu_exception   : yes
cpuid level     : 6
wp              : yes
flags           : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm syscall nx lm constant_tsc pni monitor ds_cpl vmx est cid cx16 xtpr lahf_lm
bogomips        : 5984.27
clflush size    : 64
cache_alignment : 128
address sizes   : 36 bits physical, 48 bits virtual
i want to kill apache/http and restart it again automatically. i need this because sometime we are not in front of the server to fix an overload issue immediately, which can affect a server very badly. i believe many of us already face this kind of situation and hope there is some kind of script or way to do this.
View 5 Replies View RelatedI have a small VPS, with few websites each one with very low visitors in average less than100 visits per day 
CentOS 2.6.9
Plesk
PHP    5.1.6 
Apache/2.2.3 
Few days ago some Forum spammers signed up to one of the forums. One of them: stopforumspam.com/ipcheck/212.178.2.3
Today I was away for few 5 hours after I came back I recived a notice from my script that "SMF could not connect to the database"
I checked and I noticed almost all of my sites are not responding. MySql was working. A script on remote server which uses mysql from my server loaded but with dealy
------------------Next step------------------- 
log to SSH
# uptime 
#  12:XX:XX up XXX days,  5:06,  X users,  load average: 10.58, 8.86, 5.86
my normal load is less than 0.9
-----------------check open ports ---------------------------
netstat -nap
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address               Foreign Address             State       PID/Program name   
tcp        0      0 0.0.0.0:995                 0.0.0.0:*                   LISTEN      1936/couriertcpd    
tcp        0      0 0.0.0.0:3306                0.0.0.0:*                   LISTEN      32447/mysqld        
tcp        0      0 0.0.0.0:106                 0.0.0.0:*                   LISTEN      14307/xinetd        
tcp        0      0 0.0.0.0:139                 0.0.0.0:*                   LISTEN      9943/smbd           
tcp        0      0 0.0.0.0:110                 0.0.0.0:*                   LISTEN      1916/couriertcpd    
tcp        0      0 0.0.0.0:143                 0.0.0.0:*                   LISTEN      1840/couriertcpd    
tcp        0      0 0.0.0.0:8880                0.0.0.0:*                   LISTEN      9626/httpsd         
tcp        0      0 0.0.0.0:80                  0.0.0.0:*                   LISTEN      7645/httpd          
tcp        0      0 0.0.0.0:465                 0.0.0.0:*                   LISTEN      14307/xinetd        
tcp        0      0 0.0.0.0:21                  0.0.0.0:*                   LISTEN      14307/xinetd        
tcp        0      0 [MyServerIP]:53            0.0.0.0:*                   LISTEN      13619/named         
tcp        0      0 [MyServerIP]:53            0.0.0.0:*                   LISTEN      13619/named         
tcp        0      0 [MyServerIP]:53            0.0.0.0:*                   LISTEN      13619/named         
tcp        0      0 127.0.0.1:53                0.0.0.0:*                   LISTEN      13619/named         
tcp        0      0 0.0.0.0:22                  0.0.0.0:*                   LISTEN      13820/sshd          
tcp        0      0 0.0.0.0:25                  0.0.0.0:*                   LISTEN      14307/xinetd        
tcp        0      0 127.0.0.1:953               0.0.0.0:*                   LISTEN      
Today my server was down cause it was overloaded and when i restart my server its running how to stop such problem in the future
View 10 Replies View RelatedCan someone who really knows what they are talking about write me up a very quick parag. on the reasons why the internet is becoming overloaded w/ e-mail & why people don't get their e-mails besides spam filters filtering them, for example the grey/black list, detecting viruses in Word when the person's anti virus isn't picking it up, etc.
View 4 Replies View RelatedI have heard a lot of cases when customers used forbidden PHP scripts on shared servers and as a result their accounts were suspended due to the server overload. I am just wondering what scripts it is desirable not to use within shared hosting packages?
View 6 Replies View Relatedi see alot hosting have a good trick which is auto suspend site over the normal load of 5% .... so what is this script that suspend site for period time and unsuspend it automaticly
View 4 Replies View RelatedI have heard a lot of cases when customers used forbidden PHP scripts on shared servers and as a result their accounts were suspended due to the server overload. I am just wondering what scripts it is desirable not to use within shared hosting packages?
View 4 Replies View RelatedDebian Server Ubnormal CPU
View 3 Replies View Relatedhow can i find out what has caused my server to hang/overload once its rebooted?
I know that the SWAP maxed out but i am unsure why.
i am continously getting warning mail form cpanel cpu watch that my cpu got overloaded as like follows,
IMPORTANT: Do not ignore this email.
This is cPanel cpuwatch on xxx.com!
While processing, the cpu has been
maxed out for more than a 6 hour period. The current load/uptime line on the server at the time of
this email is
19:05:10 up 143 days, 20:38, 0 users, load average: 1.11, 0.69, 0.63
You should check the server to see why the load is so high and take
steps to lower the load. If you want stats to continue to run even with a high load; Edit
/var/cpanel/cpanel.config and change extracpus to a number larger then 0 (run
/usr/local/cpanel/startup afterwards to pickup the changes).
I searched on load average and found that average load for 1 cpu is 2 and default value is 5 to 10.but here i am getting mail for 1.11 itself.I changed the value of threshold of load average in stat and logs of tweak setting to 4.but no improvement.now also i am getting more than 4 mails for average load i.e 1.23 also
My questions are:
1)what is the criteria cpanel is checking for sending cpu-watch warning mail?
2)i am getting nothing more than rsync and exim at the time of overload(while using TOP command).So why now only i am getting warning mail?
what is the cause of this problem?
I was getting idea from internet to create account without stat/ log analyse function .But not sure how will it work and afraid of doing this.......
Is there a way to protect apache server from overload? For example Nginx has a module called SysGuard when system load or memory use goes too high all subsequent requests will be redirected to the URL specified by the 'action' parameter.
View 1 Replies View RelatedMy problem is server overload.I think it's a mysql optimization problem. But i dont change any setting.
Core(TM)2 Quad CPU    Q9400  @ 2.66GHz
8 GB Ram
[url]
[url]
[url]
[url]
CENTOS 5.3 i686 standard on server
cPanel 11.24.4-C37008 - WHM 11.24.2 - X 3.9
I have a fairly busy server, and received a High Load warning from my firewall monitoring software.  Showing a high 5 minute load average alert of 13.89.
I'm presuming extra memory and a more powerful CPU would be required to sort this out?
Time:                    Thu Jul  3 12:22:06 2008
1 Min Load Avg:          42.90
5 Min Load Avg:          13.89
15 Min Load Avg:         5.82
Running/Total Processes: 51/359
Output from ps:
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND ...
I have been receiving these a couple time a day lately and not sure what to do or how to go about checking what might be overloading the server.  IF this looks familiar to anyone, I'd appreciate some helpful tips.  I'm still a novice, but can muddle my way around the server if given enough guidance.  Here is the email I've been getting:
"IMPORTANT: Do not ignore this email.
  This is cPanel stats runner on host.myserverhost.com!
  While processing the log files for user xxxxxxx, the cpu has been maxed out for more than a 6 hour period.  The current load/uptime line on the server at the time of this email is
  19:20:10 up 2 days,  7:06,  0 users,  load average: 15.17, 13.24, 8.00
  You should check the server to see why the load is so high and take steps to lower the load.  If you want stats to continue to run even with a high load; Edit /var/cpanel/cpanel.config and change extracpus to a number larger then 0 (run /usr/local/cpanel/startup afterwards to pickup the changes)."
I guess my question is, how would I go about determining what is causing the excess load?  Seems to happen even when not many folks are on my site.
I'm on a low-end dedicated server that I run 2 decent sized blogs on. I'm getting several traffic spikes a day where the load goes through the roof and I think I need my server optimized.
My server admin says I need a bigger server and he has never steered me wrong but this is ridiculous:
My blogs use Wordpress as its blogging platform....I know they hog server resources and I've recently installed Super cache so that seems to help.
I average about 5,000 pageviews a day and I would think even a low-end box should handle this but maybe I am wrong.
Here's the server specs:
Processor #1 Vendor: GenuineIntel
Processor #1 Name: Intel(R) Celeron(R) CPU 2.40GHz
Processor #1 speed: 2394.661 MHz
Processor #1 cache size: 128 KB
Memory: 1033924k/1048016k available (2171k kernel code, 13360k reserved, 723k data, 172k init, 130512k highmem)
hda: ST380011A, ATA DISK drive
hdc: Lite-On LTN486S 48x Max, ATAPI CD/DVD-ROM drive
hda: max request size: 1024KiB
hda: 156250000 sectors (80000 MB) w/2048KiB Cache, CHS=16383/255/63, UDMA(100)
hda: cache flushes supported
hdc: ATAPI 48X CD-ROM drive, 120kB Cache, UDMA(33)
Memory:
total used free shared buffers cached
Mem: 1035148 993356 41792 0 151312 527008
-/+ buffers/cache: 315036 720112
Swap: 2040212 476700 1563512
Total: 3075360 1470056 1605304
how check which database / user MySQL overload the server?
View 2 Replies View RelatedI have 3 questions.
1.) I have a user that's kinda knows a lot about linux. More than me. He has a lot of stuff on the system which I have no idea what it is. Is there any way I can install a SSH log, so I can monitor what he does in shell?
2.) My server seems REALLY sluggish. I ran a top in shell, and mysqld was taking up from 70% to 110% of the cpu. Is there any way to fix this or find out why? I've restarted the server, and it's fluctuating between 50% and 90% now.
3.) I think this MIGHT be related to the sqld issue, but I've received about 12 emails saying 
Quote:
"[statscheck] Stats/Server Overload on my server". "MPORTANT: Do not ignore this email.
This is cPanel stats runner on server1.cewxp.com!
While processing the log files for user cewxp, the cpu has been
maxed out for more than a 6 hour period.  The current load/uptime line on the server at the time of this email is 15:49:16 up 5 days, 10:52,  2 users,  load average: 27.59, 31.36, 31.83"
and also another email
Quote:
IMPORTANT: Do not ignore this email.
This is cPanel stats runner on server1.cewxp.com!
While processing the log files for user vegapunk, the cpu has been maxed out for more than a 6 hour period.  The current load/uptime line on the server at the time of this email is 12:34:26 up 5 days,  7:37,  2 users,  load average: 19.90, 17.59, 17.97
The vps has 
256MB(512 burstable) of memory 
10GB of HardDisk space
Using Lighttpd, PHP and MySQL
ControlPanel is LXAdmin
top - 05:59:24 up 36 min,  1 user,  load average: 0.42, 0.60, 0.62
Tasks:  31 total,   1 running,  29 sleeping,   0 stopped,   1 zombie
Cpu(s):  0.0%us,  0.0%sy,  0.0%ni,100.0%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:   1048576k total,    55216k used,   993360k free,        0k buffers
Swap:        0k total,        0k used,        0k free,        0k cached
  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND
    1 root      15   0  1964  660  568 S    0  0.1   0:00.46 init
 3922 root      15   0  7824 2104 1720 S    0  0.2   0:00.01 sshd
 9868 root      15   0  2352 1272 1064 S    0  0.1   0:00.00 bash
11693 root      18   0  2104 1020  820 R    0  0.1   0:00.10 top
17861 root      16   0  1632  620  520 S    0  0.1   0:00.00 syslogd
17918 dbus      25   0  2636  468  328 S    0  0.0   0:00.00 dbus-daemon
17955 root      18   0  5116  956  644 S    0  0.1   0:00.00 sshd
18093 tinydns   18   0  1544  304  252 S    0  0.0   0:00.00 tinydns
18106 root      23   0  1596  372  308 S    0  0.0   0:00.00 tcpserver
18131 apache    18   0  8452 4276  812 S    0  0.4   0:02.27 lighttpd
18132 admin     15   0 38704  24m 6652 S    0  2.4   2:58.37 php-cgi
18224 addons    20   0 22024 8456 4572 S    0  0.8   0:00.01 php-cgi
18278 root      15   0  2348 1112  968 S    0  0.1   0:00.00 sh
19519 root      15   0  4032 1432 1172 S    0  0.1   0:00.00 lxadmin.exe
19557 root      17   0  2608  884  712 S    0  0.1   0:00.00 xinetd
19594 lxlabs    18   0  5364 2220 1160 S    0  0.2   0:00.13 lxadmin.httpd
19879 root      18   0  2344 1124  964 S    0  0.1   0:00.00 mysqld_safe
19921 mysql     15   0 13688 5240 3904 S    0  0.5   0:17.51 mysqld
20250 qmails    15   0  1804  476  372 S    0  0.0   0:00.00 qmail-send
20256 qmaill    18   0  1564  472  404 S    0  0.0   0:00.00 splogger
20260 root      22   0  1576  344  268 S    0  0.0   0:00.00 qmail-lspawn
20261 qmailr    15   0  1572  372  296 S    0  0.0   0:00.00 qmail-rspawn
20275 qmailq    18   0  1560  352  284 S    0  0.0   0:00.00 qmail-clean
21824 root      18   0  6200 1296  960 S    0  0.1   0:00.00 authdaemond
21828 root      15   0  1596  376  312 S    0  0.0   0:00.00 tcpserver
21834 root      25   0  1592  368  308 S    0  0.0   0:00.00 tcpserver
21838 root      18   0  6200  460  124 S    0  0.0   0:00.00 authdaemond
21842 root      18   0  1592  372  312 S    0  0.0   0:00.00 tcpserver
21861 root      25   0  1592  368  308 S    0  0.0   0:00.00 tcpserver
21890 root      18   0  3184 1108  576 S    0  0.1   0:00.00 crond
I just got an email from my vps saying that a BFD attack was stopped and the ip was banned after 40 failed attempts of logging into ftpdpro. I logged in and started looking around and I noticed that in my apf log file there was:
Code:
Jan 15 00:54:07 s1 apf(22290): {glob} firewall initalized
Jan 15 00:54:07 s1 apf(22290): {glob} fast load snapshot saved
Jan 15 00:58:06 s1 apf(32425): {glob} uptime less than 5 minutes, going full load
Jan 15 00:58:06 s1 apf(32425): {glob} activating firewall
Jan 15 00:58:06 s1 apf(32500): {glob} unable to load iptables module (ip_tables), aborting.
Jan 15 00:58:06 s1 apf(32425): {glob} firewall initalized
Jan 15 00:58:06 s1 apf(32425): {glob} fast load snapshot saved
Jan 15 01:00:04 s1 apf(3950): {glob} uptime less than 5 minutes, going full load
My concern is that it says "unable to load iptables module (ip_tables), aborting.
is there anything that logs server load and what processes have caused any spikes?
one of my servers keeps going down under high load, well it seems to lock up and the noc has to reboot, but ofcourse the techs can't diagnose a problem after as it runs fine and when i send them a ticket it's because the server can't be reached at all and then they can't diagnose it either