Hi Astaro,
we need urgent help:
today i got this mail:
-----------------------------------------------------------------------------------------------
Betreff: [gw01.xxxxx.xx] [WAR 102] Too much memory for a single process
- please check(8 times)
Too much memory for a single process:
258844 kb for /usr/local/bin/fwlogwatch -f /var/log/kernel-20030812.gz -P n -b -m 5 -t -e -n -N -p
root 834 92.6 57.1 258844 257784 ? RN 06:03 575:59 /usr/local/bin/fwlogwatch -f /var/log/kernel-20030812.gz -P n -b -m 5 -t -e -n -N -p
Last WebAdmin login: admin at Wed Aug 13 16:30:45 from 10.10.254.227
System Uptime : 5 days 0 hours 20 minutes
System Load : 0.90
System Version : Astaro Security Linux 4.010
License : Professional Version
Active IP Count : 55 protected IPs
-----------------------------------------------------------------------------------------------
we killed process 834 but it was restarted under another pid:
2324 ? S 0:00 /usr/sbin/cron
1742 ? S 0:00 \_ /USR/SBIN/CRON
1743 ? S 0:00 \_ /bin/bash /usr/local/bin/log-rotate.sh
5979 ? SN 0:00 \_ /usr/bin/perl -w /usr/local/bin/fwlw.pl /var/log/kernel-20030812.gz
12225 ? RN 29:52 \_ /usr/local/bin/fwlogwatch -S -d -f /var/log/kernel-20030812.gz -P n -b -m 5 -t -e -n -N -p
12226 ? SN 0:00 \_ sh -c nice -19 /usr/bin/bzip2 -czq > /var/chroot-report/fwlogwatch/kernel-20030812/Dst_dPort_report.bz2
12227 ? SN 0:00 \_ /usr/bin/bzip2 -czq
the problems seems to be the blaster worm. we had a lot of dropped packets with DPT=135 and now our kernel log (kernel-20030812.gz) is uncompressed about 146 mb !!!
an now the logrotate / fwlogwatch process is growing and growing.
what is the best way to fix this ???
should we delete the kernel-20030812.gz and kill the process again ???
thnx,
gnjb
This thread was automatically locked due to age.