im trying to find a good solution for centralized syslog managmenet and analysis. Basically im sick of reading all those logwatch mails
Is there anyone that could point me to the 'Best' solution to go with?.
It should run on a linux server, vmware appliance will do as well. If there is no linux solution - which i doubt - than i will also consider having a windows solution.
I looked at ManageEngine Eventlog Analyzer which is kinda what im looking for - but the pricing is not what i expected.
Its more than ok if it is a paid solution you are offering or pointing to!
Windows has a variety of items that it logs locally, logins, security alerts, etc, etc. Is there a software solution that can take computer level activity i.e. logins, security alerts, etc, etc and log it to a local or remote syslog server?
I installed syslog-ng in hopes that i could change this behaviour but to no avail. the real problem i see is that shorewall/iptables only logs to "kern" facility...
has anyone found a way arround this? maybe even using some other firewall?
I have just noticed that for several days I'm constantly receiving these infos in /var/log/messages. I haven't done anything that would invoke them. How can I disable these messages? Are they anything to worry about?
Code: Feb 6 14:28:18 server kernel: [<c014f600>] find_extend_vma+0x12/0x4f Feb 6 14:28:18 server kernel: [<c0134383>] get_futex_key+0x39/0x108 Feb 6 14:28:18 server kernel: [<c011d305>] finish_task_switch+0x30/0x66 Feb 6 14:28:18 server kernel: [<c02cf618>] schedule+0x844/0x87a Feb 6 14:28:18 server kernel: [<c027734b>] sys_socketcall+0x1df/0x1fb Feb 6 14:28:18 server kernel: [<c0125bc5>] sys_gettimeofday+0x53/0xac Feb 6 14:28:18 server kernel: [<c02d137f>] syscall_call+0x7/0xb Feb 6 14:28:18 server kernel: [<c02d007b>] _read_lock_irq+0x4/0x1e Feb 6 14:28:18 server kernel: Badness in dst_release at include/net/dst.h:149 Feb 6 14:28:18 server kernel: [<f8d8a555>] ip6_push_pending_frames+0x340/0x369 [ipv6] Feb 6 14:28:18 server kernel: [<f8d9883f>] udp_v6_push_pending_frames+0x169/0x185 [ipv6]Badness in dst_release at include/net/dst.h:149 Feb 6 14:28:18 server kernel: [<c0278fa8>] Feb 6 14:28:18 server kernel: [<f8d98e7d>] udpv6_sendmsg+0x622/0x770 [ipv6] Feb 6 14:28:18 server kernel: [<c027a498>] __kfree_skb+0x55/0xf7 Feb 6 14:28:18 server kernel: [<c027e1b8>] skb_dequeue+0x40/0x46 Feb 6 14:28:18 server kernel: [<c027b009>] net_tx_action+0x60/0xfc Feb 6 14:28:18 server kernel: [<c0126354>] skb_recv_datagram+0x61/0x9b Feb 6 14:28:18 server kernel: [<c02b1ed7>] __do_softirq+0x4c/0xb1 Feb 6 14:28:18 server kernel: [<c010814b>] do_softirq+0x4f/0x56 Feb 6 14:28:18 server kernel: ======================= Feb 6 14:28:18 server kernel: [<c0107a60>] do_IRQ+0x1a2/0x1ae Feb 6 14:28:18 server kernel: [<c02d1d3c>] udp_recvmsg+0x5f/0x271 Feb 6 14:28:18 server kernel: [<c02b7b35>] common_interrupt+0x18/0x20 Feb 6 14:28:18 server kernel: [<c02d007b>] inet_sendmsg+0x38/0x42 Feb 6 14:28:18 server kernel: [<c02757f5>] _read_lock_irq+0x4/0x1e Feb 6 14:28:18 server kernel: sock_sendmsg+0xdb/0xf7 Feb 6 14:28:18 server kernel: [<c02757f5>] sock_sendmsg+0xdb/0xf7 Feb 6 14:28:18 server kernel: [<c011fee1>] autoremove_wake_function+0x0/0x2d Feb 6 14:28:18 server kernel: [<c027a89e>] verify_iovec+0x76/0xc2 Feb 6 14:28:18 server kernel: [<c0276f44>] sys_sendmsg+0x1ee/0x23b Feb 6 14:28:18 server kernel: [<c011cb7d>] activate_task+0x88/0x95 Feb 6 14:28:18 server kernel: [<c011d00a>] try_to_wake_up+0x225/0x230 Feb 6 14:28:18 server kernel: [<c011d00a>] try_to_wake_up+0x225/0x230 Feb 6 14:28:18 server kernel: [<c0170776>] inode_update_time+0x80/0x87 Feb 6 14:28:18 server kernel: [<c0164748>] pipe_writev+0x310/0x31c Feb 6 14:28:18 server kernel: [<c02cf622>] schedule+0x84e/0x87a Feb 6 14:28:18 server kernel: [<c027734b>] sys_socketcall+0x1df/0x1fb Feb 6 14:28:18 server kernel: [<c0125bc5>] sys_gettimeofday+0x53/0xac Feb 6 14:28:18 server kernel: [<c02d137f>] syscall_call+0x7/0xb Feb 6 14:28:18 server kernel: [<c02d007b>] _read_lock_irq+0x4/0x1e Feb 6 14:28:18 server kernel: Badness in dst_release at include/net/dst.h:149 Feb 6 14:28:18 server kernel: [<f8d98ef7>] udpv6_sendmsg+0x69c/0x770 [ipv6] Feb 6 14:28:18 server kernel: [<c027a498>] skb_dequeue+0x40/0x46 Feb 6 14:28:18 server kernel: [<c027b009>] skb_recv_datagram+0x61/0x9b Feb 6 14:28:18 server kernel: [<c02b1ed7>] udp_recvmsg+0x5f/0x271 Feb 6 14:28:18 server kernel: [<c02b7b35>] inet_sendmsg+0x38/0x42 Feb 6 14:28:18 server kernel: [<c02757f5>] sock_sendmsg+0xdb/0xf7 Feb 6 14:28:18 server kernel: [<c02757f5>] sock_sendmsg+0xdb/0xf7 Feb 6 14:28:18 server kernel: [<c011fee1>] autoremove_wake_function+0x0/0x2d Feb 6 14:28:18 server kernel: [<c027a89e>] verify_iovec+0x76/0xc2 Feb 6 14:28:18 server kernel: [<c0276f44>] sys_sendmsg+0x1ee/0x23b Feb 6 14:28:18 server kernel: [<c011cb7d>] activate_task+0x88/0x95 Feb 6 14:28:18 server kernel: [<c011d00a>] try_to_wake_up+0x225/0x230 Feb 6 14:28:18 server kernel: [<c011d00a>] try_to_wake_up+0x225/0x230 Feb 6 14:28:18 server kernel: [<c0170776>] inode_update_time+0x80/0x87 Feb 6 14:28:18 server kernel: [<c0164748>] pipe_writev+0x310/0x31c Feb 6 14:28:18 server kernel: [<c02cf622>] schedule+0x84e/0x87a Feb 6 14:28:18 server kernel: [<c027734b>] sys_socketcall+0x1df/0x1fb Feb 6 14:28:18 server kernel: [<c0125bc5>] sys_gettimeofday+0x53/0xac Feb 6 14:28:18 server kernel: [<c02d137f>] syscall_call+0x7/0xb Feb 6 14:28:18 server kernel: [<c02d007b>] _read_lock_irq+0x4/0x1e
I've got 25 domains on a Virtuozzo/Plesk8.6/CentOS5 VPS. Each domain has one up-to-date install of WordPress, most have very little traffic (average 200mb per month), maybe 2 domains get 5-7gb traffic per month.
I monitor port 80 connections and rarely see more than 10 at a time. That should in my opinion be no problem at all for a VPS with 768mb guaranteed ram and 2.4ghz cpu. I've got 30gb hard drive spare too.
But.... about 8 or 10 times a day it grinds to a complete halt: server load at 500-1000%, sites timing out, plesk takes 3mins to load, often I can't even connect with SSH, and the plesk web server, apache
80 seconds sounds like a huge amount of time for a MySQL insert to me! Does anyone know if this is likely to be the cause of my trouble? Some problem with Plesk and the database? Or could it be something else?
I need to backup some emails from my VPS, Can you please tell me where my emails are stored, I have a VPS running CENTOS, PLESK and POSTFIX mail server.
Does anyone know what the following events in /var/log/messages mean. It looks like some sort of failure on the ata bus. Does the last line mean that it successfully wrote all data using the cache, or could there be data loss?
The output of smartctl looks ok for the disk.
Code: Jul 26 16:44:35 server1 kernel: ata1.00: exception Emask 0x0 SAct 0x0 SErr 0x0 action 0x2 frozen Jul 26 16:44:35 server1 kernel: ata1.00: cmd c8/00:08:9d:e2:8a/00:00:00:00:00/ec tag 0 cdb 0x0 data 4096 in Jul 26 16:44:35 server1 kernel: res 40/00:01:00:4f:c2/00:00:00:00:00/00 Emask 0x4 (timeout) Jul 26 16:44:42 server1 kernel: ata1: port is slow to respond, please be patient (Status 0xd0) Jul 26 16:45:05 server1 kernel: ata1: port failed to respond (30 secs, Status 0xd0) Jul 26 16:45:05 server1 kernel: ata1: soft resetting port Jul 26 16:45:10 server1 kernel: ata1.00: revalidation failed (errno=-2) Jul 26 16:45:10 server1 kernel: ata1: failed to recover some devices, retrying in 5 secs Jul 26 16:45:15 server1 kernel: ata1: soft resetting port Jul 26 16:45:15 server1 kernel: ata1.00: configured for UDMA/133 Jul 26 16:45:15 server1 kernel: ata1: EH complete Jul 26 16:45:15 server1 kernel: SCSI device sda: 976773168 512-byte hdwr sectors (500108 MB) Jul 26 16:45:15 server1 kernel: SCSI device sda: drive cache: write back
I have a VPS with Future Hosting and recently I have been getting more and more notifications from LFD regarding high CPU load. For example:
Time: Sun Jun 14 06:50:48 2009 -0500 1 Min Load Avg: 9.47 5 Min Load Avg: 6.25 15 Min Load Avg: 3.68 Running/Total Processes: 2/105
I am getting at least one of these a day now and I am also getting alerts about services failing, SPAMD in particular but also EXIM (and messages about LFD being unable to determine the exim queue length). External monitors are also warning me about SMTP timeouts during the same time period that I get the "high load" errors.
Tech support seems a bit stumped by this one and ALWAYS come back with "load looks fine right now". With the frequency of the warning emails increasing I am getting very concerned about the stability of my VPS.
I am not running anything significant on my VPS yet with minimal visitors and load (RAM usage consistently stays below 300MB on a VPS with 1+GB RAM.
all at the same hour,minutes and seconds, this that i wrote is an example (the ip's are reals) but like it i found a lot of more, and is in the same time that the server overload. the server is RHE and i have APF and BFA installed.
I just ran 'rkhunter -c --quiet' and this is the error messages I got:
Line: Warning: This operating system is not fully supported! Line: Warning: This operating system is not fully supported! Warning: Cannot find md5_not_known Some errors has been found while checking. Please perform a manual check on this machine debian
It appears that MSN / Hotmail have recently began blocking an awful lot of servers I manage. Several of them (for a company I work for) are in a few blacklists however a number of the IP addresses I manage are 100% clean.
Anyone know of something MSN/Hotmail recently began enforcing? The blocks began at around 6 PM EST on Thursday of last week.
The error message is as follows:
Your e-mail was rejected for policy reasons on this gateway. Reasons for rejection may be related to content such as obscene language, graphics, or spam-like characteristics (or) other reputation problems. For sender troubleshooting information, please go to http://postmaster.msn.com. Please note: if you are an end-user please contact your E-mail/Internet Service Provider for assistance.
I feel like a pawn for asking this on WHT but from what I can see it's fairly widespread.
The domains in question do have basic SPF implemented as well. not limited to a contact at hotmail / msn that would enjoy a phonebeating.
Feb 19 15:57:39 server proftpd[1363]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:06:02 server proftpd[1982]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:06:02 server proftpd[1982]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:14:24 server proftpd[2471]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:14:24 server proftpd[2471]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:22:46 server proftpd[3062]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:22:46 server proftpd[3062]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:31:09 server proftpd[3696]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:31:09 server proftpd[3696]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:39:31 server proftpd[4185]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:39:31 server proftpd[4185]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:47:53 server proftpd[4946]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:47:53 server proftpd[4946]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 16:56:16 server proftpd[5495]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 16:56:16 server proftpd[5495]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 17:04:38 server proftpd[6206]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 17:04:38 server proftpd[6206]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 17:13:00 server proftpd[6661]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 17:13:00 server proftpd[6661]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed. Feb 19 17:21:23 server proftpd[7225]: server.com (127.0.0.1[127.0.0.1]) - FTP session opened. Feb 19 17:21:23 server proftpd[7225]: server.com (127.0.0.1[127.0.0.1]) - FTP session closed.
I see over a few hundred of these lines in /var/log/messages. The timestamp is exactly the same for every 2 lines (Proftp session- Opened and Closed). It's occuring every hour of the day. Is someone attacking the ftp daemon or something?
We're on a VPS and lately we've been getting a few 'exim has failed...A restart was attempted automagicly.' messages. Support indicated that we're hitting our limits and suggested that we move to a bigger package or remove accounts. I only have 2 active sites on this account. We're new at this and don't know if there's anything else we can do.
Does anyone know what could be causing exim to fail?
I have 2.4.3 (Win-64) installed and running. When it starts up, I get a command prompt window that has messages in it, but the window closes so quickly, I can't read the messages. They don't appear in the log. I have tried to manually start the server, but when I do, the messages do not appear!
How can I get that window to stay open or where can I see those messages?
We've got a dedicated server at our company that hosts several sites and email accounts. Today I noticed that in the mail queue (from Plesk) we have like 5 or 6 messages from the same customer with around 400 destination addresses for EACH one. This would be like 2000-3000 emails to be sent. It isn't spam as it's some kind of newsletter.
I don't really know how the QMail server handles this, but it's been 5 hours since some of those messages entered the queue, and they are still there, so it seems that is having some difficulty.
I don't pretend to limit the amount of emails an user can send per minute or per hour, but I would like to know if there is any way of managing the queue like, lets say, send 50 message per minute. As far as I know, the mail queue right now (by default) starts sending the messages as they come, which means it could send 1000 in a few seconds if it can handle it.
I don't even know if this would be better or worse, meaning that maybe messages could get queued when the server could handle them, so some customers would see that emails are not working instantly as they do now. It also would be good if this tool (if exists) could report the current status of the queue, saturation, etc...
We're a bit worried because a couple of days ago we had some kind of attack and our server started sending hundreds of emails with fake sender and the CPU went overloaded and the mail queue was too big.
i'm wanting my users to be able to upload pictures to their accounts via email by sending the picture to a central email address (pics@mysite.com, for example).
from there, i'd like to take that incoming email and parse it how i see fit. (matching the email address to the user account, inserting the subject as the photo title, etc...)
I have hundreds and hundreds of messages in mail queue waiting delivering. Log file says:
connect to remote.host[000.000.000.000]: server refused to talk to me: 421 4.7.0 remote.host Error: too many connections from my-servers-ip
delivery temporarily suspended: connect to remote.host[000.000.000.000]: Connection timed out
(I replaced real IP addresses with 000, my-servers-ip and hostname with "remote host")
It happends only with one host (the most popular free email provider in my country). All emails to yahoo, gmail etc are being delivered without any problems.
What does it mean - too many connections from my server? I have a busy dating website and php script sends out a lot of email notifications (for example - when users get new instant messages). Anyway, I never heard that email providers limit the number of emails from the same server. During the night time all messages from mail queue are being delivered, but at day time this number sometimes grows to 1000.