LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Newbie (https://www.linuxquestions.org/questions/linux-newbie-8/)
-   -   Log file question (https://www.linuxquestions.org/questions/linux-newbie-8/log-file-question-450609/)

rlprofessional 06-01-2006 11:26 AM

Log file question
 
Below is a copy of my messager log - it has a gap of information from May 30 - May 31.

The server crashed yesterday and was restarted @ 12:40ish May 31. Can someone look at the log tell if someone physically turn the box off?



May 30 13:34:21 cms-1 sshd(pam_unix)[14314]: session opened for user root by (ui
d=0)
May 30 13:37:50 cms-1 sshd(pam_unix)[14314]: session closed for user root
May 30 16:38:43 cms-1 sshd(pam_unix)[14565]: authentication failure; logname= ui
d=0 euid=0 tty=NODEVssh ruser= rhost=camping44.uninet.com.py user=root
May 30 16:38:53 cms-1 sshd(pam_unix)[14567]: check pass; user unknown
May 30 16:38:53 cms-1 sshd(pam_unix)[14567]: authentication failure; logname= ui
d=0 euid=0 tty=NODEVssh ruser= rhost=camping44.uninet.com.py
May 30 16:39:01 cms-1 sshd(pam_unix)[14569]: check pass; user unknown
May 30 16:39:01 cms-1 sshd(pam_unix)[14569]: authentication failure; logname= ui
d=0 euid=0 tty=NODEVssh ruser= rhost=camping44.uninet.com.py
May 30 16:39:05 cms-1 sshd(pam_unix)[14571]: check pass; user unknown
May 30 16:39:05 cms-1 sshd(pam_unix)[14571]: authentication failure; logname= ui
d=0 euid=0 tty=NODEVssh ruser= rhost=camping44.uninet.com.py
May 30 16:39:11 cms-1 sshd(pam_unix)[14573]: check pass; user unknown
May 30 16:39:11 cms-1 sshd(pam_unix)[14573]: authentication failure; logname= ui
d=0 euid=0 tty=NODEVssh ruser= rhost=camping44.uninet.com.py
May 31 06:29:43 cms-1 sshd(pam_unix)[15734]: session opened for user root by (ui
d=0)
May 31 12:48:42 cms-1 syslogd 1.4.1: restart.
May 31 12:48:42 cms-1 syslog: syslogd startup succeeded
May 31 12:48:42 cms-1 kernel: klogd 1.4.1, log source = /proc/kmsg started.
May 31 12:48:42 cms-1 kernel: Linux version 2.4.21-4.ELsmp (bhcompile@daffy.perf
.redhat.com) (gcc version 3.2.3 20030502 (Red Hat Linux 3.2.3-20)) #1 SMP Fri Oc
t 3 17:52:56 EDT 2003
May 31 12:48:42 cms-1 kernel: BIOS-provided physical RAM map:
May 31 12:48:42 cms-1 kernel: BIOS-e820: 0000000000000000 - 000000000009fc00 (u
sable)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 000000000009fc00 - 00000000000a0000 (r
eserved)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 00000000000f0000 - 0000000000100000 (r
eserved)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 0000000000100000 - 000000007fff3000 (u
sable)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 000000007fff3000 - 000000007fffb000 (A
CPI data)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 000000007fffb000 - 0000000080000000 (r
eserved)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 00000000fec00000 - 00000000fed00000 (r
eserved)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 00000000fee00000 - 00000000fee10000 (r
eserved)
May 31 12:48:42 cms-1 kernel: BIOS-e820: 00000000ffc00000 - 0000000100000000 (r
eserved)
May 31 12:48:42 cms-1 syslog: klogd startup succeeded
May 31 12:48:42 cms-1 kernel: 1151MB HIGHMEM available.
May 31 12:48:42 cms-1 kernel: 896MB LOWMEM available.
May 31 12:48:42 cms-1 irqbalance: irqbalance startup succeeded
May 31 12:48:42 cms-1 kernel: found SMP MP-table at 000f4fa0
May 31 12:48:42 cms-1 kernel: hm, page 000f4000 reserved twice.
May 31 12:48:42 cms-1 portmap: portmap startup succeeded
May 31 12:48:42 cms-1 kernel: hm, page 000f5000 reserved twice.
May 31 12:48:43 cms-1 kernel: hm, page 000f2000 reserved twice.
May 31 12:48:43 cms-1 kernel: hm, page 000f3000 reserved twice.
May 31 12:48:43 cms-1 rpc.statd[3376]: Version 1.0.5 Starting
May 31 12:48:43 cms-1 kernel: On node 0 totalpages: 524275
May 31 12:48:43 cms-1 kernel: zone(0): 4096 pages.
May 31 12:48:43 cms-1 nfslock: rpc.statd startup succeeded
May 31 12:48:43 cms-1 kernel: zone(1): 225280 pages.
May 31 12:48:43 cms-1 keytable: Loading keymap:
May 31 12:48:43 cms-1 kernel: zone(2): 294899 pages.
May 31 12:48:43 cms-1 keytable:
May 31 12:48:43 cms-1 kernel: ACPI: Searched entire block, no RSDP was found.

Tinkster 06-01-2006 01:32 PM

Hi,

And welcome to LQ!

Impossible to tell whether it was switched off, reset was pressed
or there was a glitch in the power. But it definitely went down
without a warning. Might even be a box set-up to reboot on a kernel
panic without human intervention. For us a dying motherboard (capacitors
had come of age) did things like the above, too. Just reset itself at
random times. Heaps of possible reasons, and, as stated above, all you
can tell is that it went down without a warning.


Cheers,
Tink

Oliv' 06-01-2006 01:55 PM

type "last" to see if that's a crash or not:
Code:

olivier  :0                            Wed Sep 21 17:42 - down  (05:30)   
reboot  system boot  2.6.12-gentoo-r1 Wed Sep 21 17:42          (05:31)   
olivier  :0                            Wed Sep 21 08:53 - crash  (08:48)   
reboot  system boot  2.6.12-gentoo-r1 Wed Sep 21 08:53          (14:20)   
olivier  :0                            Tue Sep 20 08:50 - 23:04  (14:14)



All times are GMT -5. The time now is 12:31 AM.