Linux - ServerThis forum is for the discussion of Linux Software used in a server related context.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
Hi last night my server went down. Services stopped working, SSH timed out, I plugged monitor and keyboard into and monitor had no signal (like cable wasn't connected) and keyboard didn't light up (not sure if it normally does though).
I rebooted it physically this morning and got these messages from syslog:
#cat /var/log/syslog
Code:
Oct 11 22:17:01 dan CRON[3139]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 11 23:17:01 dan CRON[3143]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 00:17:01 dan CRON[3148]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 01:17:01 dan CRON[3153]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 02:17:01 dan CRON[3157]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 03:17:01 dan CRON[3162]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 04:17:01 dan CRON[3166]: (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Oct 12 07:11:51 dan kernel: imklog 4.2.0, log source = /proc/kmsg started.
Oct 12 07:11:51 dan rsyslogd: [origin software="rsyslogd" swVersion="4.2.0" x-pid="634" x-info="http://www.rsyslog.com"] (re)start
Oct 12 07:11:51 dan rsyslogd: rsyslogd's groupid changed to 103
Oct 12 07:11:51 dan rsyslogd: rsyslogd's userid changed to 101
Oct 12 07:11:51 dan rsyslogd-2039: Could no open output file '/dev/xconsole' [try http://www.rsyslog.com/e/2039 ]
Oct 12 07:11:51 dan kernel: [ 0.000000] Initializing cgroup subsys cpuset
Oct 12 07:11:51 dan kernel: [ 0.000000] Initializing cgroup subsys cpu
I shortened the above messages, but you can see it went down around 4:17am where the last cron ran. And at 7:11 was when I rebooted.
Is there any more info I can get that would give me more information?
Oct 10 06:25:48 dan rsyslogd: [origin software="rsyslogd" swVersion="4.2.0" x-pid="627" x-info="http://www.rsyslog.com"] rsyslogd was HUPed, type 'lightweight'.
Oct 11 06:48:54 dan rsyslogd: [origin software="rsyslogd" swVersion="4.2.0" x-pid="627" x-info="http://www.rsyslog.com"] rsyslogd was HUPed, type 'lightweight'.
Oct 12 07:11:51 dan kernel: imklog 4.2.0, log source = /proc/kmsg started.
As you can see it only has one line logged for the 11th when it happened.
Quote:
Originally Posted by quanta
And have a look at /var/log/dmesg also.
Here's the dmesg but I can't see it showing anything either:
Code:
[ 15.712108] r8169: eth0: link up
[ 15.712131] r8169: eth0: link up
[ 15.773969] No connectors reported connected with modes
[ 15.774036] [drm] Initialized i915 1.6.0 20080730 for 0000:00:02.0 on minor 0
[ 15.774525] HDA Intel 0000:00:1b.0: PCI INT A -> GSI 16 (level, low) -> IRQ 16
[ 15.774592] HDA Intel 0000:00:1b.0: setting latency timer to 64
[ 15.780332] vga16fb: initializing
[ 15.780351] vga16fb: mapped to 0xffff8800000a0000
[ 15.780556] fb0: VGA16 VGA frame buffer device
[ 15.794708] Slow work thread pool: Starting up
[ 15.795395] Slow work thread pool: Ready
[ 15.918442] type=1505 audit(1286181761.274:5): operation="profile_replace" pid=683 name="/sbin/dhclient3"
[ 15.919062] type=1505 audit(1286181761.274:6): operation="profile_replace" pid=683 name="/usr/lib/NetworkManager/nm-dhcp-client.action"
[ 15.919420] type=1505 audit(1286181761.274:7): operation="profile_replace" pid=683 name="/usr/lib/connman/scripts/dhclient-script"
[ 15.923594] type=1505 audit(1286181761.284:8): operation="profile_load" pid=684 name="/usr/sbin/tcpdump"
[ 15.927546] Console: switching to colour frame buffer device 80x30
[ 15.967769] input: HDA Digital PCBeep as /devices/pci0000:00/0000:00:1b.0/input/input4
# Log kernel generated UFW log messages to file
:msg,contains,"[UFW " /var/log/ufw.log
# Uncomment the following to stop logging anything that matches the last rule.
# Doing this will stop logging kernel generated UFW log messages to the file
# normally containing kern.* messages (eg, /var/log/kern.log)
#& ~
There is also (but probably not important) /etc/rsyslog.d/postfix:
Code:
# Create an additional socket in postfix's chroot in order not to break
# mail logging when rsyslog is restarted. If the directory is missing,
# rsyslog will silently skip creating the socket.
$AddUnixListenSocket /var/spool/postfix/dev/log
Also if it helps /var/log/ufw.log is empty.
And /var/log/kern.log doesn't have anything other than a stripped down version of /var/log/syslog. Which is showing nothing at time of crash, only the bootup.
:msg,contains,"[UFW " /var/log/ufw.log
^this line breaks things for me in rsyslog. It'll cause a syntax error when generating the rules in rsyslog. This can be viewed by running it in interactive mode.
Is there any other way I can tell UFW to output to another file, or more to the point, to a remote server (which is my ultimate goal)?
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.