LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-11-2006, 01:20 PM   #1
Swakoo
Member
 
Registered: Apr 2005
Distribution: Red Hat / Fedora / CentOS
Posts: 508

Rep: Reputation: 30
Logs: What to check and where to find them?


Recently, my servers suffered a "DoS". I quoted it because it was caused by us, maxing our given bandwidth... but here's the interesting thing:

Our servers, throughout the 6hours "blackout", recorded low load (via 'top')

I checked /var/log/messages in some of the servers but didn't register much info from there.... and this has always been something that puzzle me.. where else should i look when it comes to tracing problem? What log shows what... what show I know... what should i look out first etc.. is there some kind of a "logs bible"?

I'm using Redhat, RHEL3 & 4 and FC4 mostly.

Would appreciate some guidiance here.

Many thanks!
 
Old 01-11-2006, 03:18 PM   #2
saman007uk
Member
 
Registered: Dec 2003
Location: ~root
Distribution: Debian
Posts: 364

Rep: Reputation: 33
I would recommend using something like LogCheck, which checks your logs for suspicious activity such as failed logins, etc.

A DDOS attack does not need to grind your machine to a halt, but rather use all of your available bandwidth - so that geniuine users will have a leesser chance of accessing the server.
 
Old 01-12-2006, 03:35 AM   #3
Swakoo
Member
 
Registered: Apr 2005
Distribution: Red Hat / Fedora / CentOS
Posts: 508

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by saman007uk
I would recommend using something like LogCheck, which checks your logs for suspicious activity such as failed logins, etc.

A DDOS attack does not need to grind your machine to a halt, but rather use all of your available bandwidth - so that geniuine users will have a leesser chance of accessing the server.

How do I identify if it is a possible DDOS?

Our datacentre say our traffic pattern don't suggest it is a DDOS
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Reboots - What Logs Should I Check? MoghNX01 Linux - Newbie 6 12-15-2005 11:09 AM
how to check logs after a black screen freeze? TokyoYank Fedora 5 11-04-2005 06:45 PM
Perl Script To Check Logs Crashed_Again Programming 0 11-13-2004 03:13 PM
My computer froze last night - which logs do i check? rosscopeeko Mandriva 2 06-02-2004 08:57 AM
what logs do I check? mehesque Linux - Newbie 1 02-12-2004 07:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 06:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration