LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-01-2007, 12:06 PM   #1
Harlin
Member
 
Registered: Dec 2004
Location: Atlanta, GA U.S.
Distribution: I play with them all :-)
Posts: 316

Rep: Reputation: 38
Finding Killed Process


We use DB2 on Redhat. An instance of DB2 was running and then died unexpectedly for seemingly no reason. The DB2 support person told us that the reason the instance died was because a kill -9 was issued against a db2 process. I've searched all of the user's history files and was not able to find the issuer. Is there any way to track down a kill -9 issuance from the past few days on the system?

Thanks
 
Old 11-01-2007, 12:55 PM   #2
bsdunix
Senior Member
 
Registered: May 2006
Distribution: BeOS, BSD, Caldera, CTOS, Debian, LFS, Mac, Mandrake, Red Hat, Slackware, Solaris, SuSE
Posts: 1,761

Rep: Reputation: 80
Intresting, how did the DB2 support person know kill -9 was issued since you can't find it in the users command history files? The system log files are usually located in /var/log or /var/adm. I don't recall any typical system log file recording user commands other than a service starting/stopping. Finding when the process was logged as stopped might help to narrow down your search?
 
Old 11-01-2007, 01:24 PM   #3
Harlin
Member
 
Registered: Dec 2004
Location: Atlanta, GA U.S.
Distribution: I play with them all :-)
Posts: 316

Original Poster
Rep: Reputation: 38
It wasn't difficult to find in the db2diag.log file:

2007-10-31-23.24.50.920652-240 E6455446G877 LEVEL: Severe
PID : 22016 TID : 3086423744 PROC : db2gds 0
INSTANCE: expinst1 NODE : 000
FUNCTION: DB2 UDB, oper system services, sqloEDUSIGCHLDHandler, probe:50
DATA #1 : <preformatted>
Detected the death of an EDU with process id 22565
The signal number that terminated this process was 9
Look for trap files (t22565.*) in the dump directory

Any ideas after reading this?

Thanks!
 
Old 11-01-2007, 03:04 PM   #4
bsdunix
Senior Member
 
Registered: May 2006
Distribution: BeOS, BSD, Caldera, CTOS, Debian, LFS, Mac, Mandrake, Red Hat, Slackware, Solaris, SuSE
Posts: 1,761

Rep: Reputation: 80
You may already know this information, if not:

Analyzing trap files

http://publib.boulder.ibm.com/infoce...d/c0020711.htm

Look at your trap file for any clues:
Quote:
Look for trap files (t22565.*) in the dump directory
and

Common signals and exceptions that cause trap file generation

SIGKILL. This Signal #9 can be caused by someone manually (or through a script) killing a DB2(R) process, in which case, no trap file is generated.

http://publib.boulder.ibm.com/infoce...d/c0020711.htm

So, since you have a trap file then termination might not have been caused by someone issuing kill.

Last edited by bsdunix; 11-01-2007 at 08:42 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
find history of a job killed by "kernel: Out of Memory: Killed process" poulacou Linux - Server 3 09-20-2007 04:24 PM
a process being killed for un-known reasons helptonewbie Linux - Software 8 02-13-2007 01:33 PM
how to prevent process from being killed? iclinux Linux - Newbie 7 01-14-2005 10:43 PM
Killed Process Problem chr Slackware 2 05-06-2003 01:33 AM
process is getting killed automatically chens_83 Linux - General 2 09-16-2002 03:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration