How should I go about debugging this? What info can I provide you?
Note that the daemon is getting quite a lot of messages through localhost UDP.
- Code: Select all
# ldd /sbin/rsyslogd
libz.so.1 => /usr/lib64/libz.so.1 (0x0000003d60e00000)
libpthread.so.0 => /lib64/libpthread.so.0 (0x0000003d60600000)
libdl.so.2 => /lib64/libdl.so.2 (0x0000003d5fa00000)
librt.so.1 => /lib64/librt.so.1 (0x0000003d61600000)
libgcc_s.so.1 => /lib64/libgcc_s.so.1 (0x0000003d61e00000)
libc.so.6 => /lib64/libc.so.6 (0x0000003d5f600000)
/lib64/ld-linux-x86-64.so.2 (0x0000003d5f200000)
- Code: Select all
# pmap -x $(pgrep rsyslogd)
1005: rsyslogd -c 3
Address Kbytes RSS Anon Locked Mode Mapping
0000000000400000 244 - - - r-x-- rsyslogd
000000000063d000 16 - - - rw--- rsyslogd
0000000000641000 4 - - - rw--- [ anon ]
00000000092e1000 31184 - - - rw--- [ anon ]
0000000041d5c000 4 - - - ----- [ anon ]
0000000041d5d000 10240 - - - rw--- [ anon ]
000000004275d000 4 - - - ----- [ anon ]
000000004275e000 10240 - - - rw--- [ anon ]
000000004315e000 4 - - - ----- [ anon ]
000000004315f000 10240 - - - rw--- [ anon ]
0000000043b5f000 4 - - - ----- [ anon ]
0000000043b60000 10240 - - - rw--- [ anon ]
0000000044560000 4 - - - ----- [ anon ]
0000000044561000 10240 - - - rw--- [ anon ]
0000003a81800000 236 - - - r-x-- libsepol.so.1
0000003a8183b000 2048 - - - ----- libsepol.so.1
0000003a81a3b000 4 - - - rw--- libsepol.so.1
0000003a81a3c000 40 - - - rw--- [ anon ]
0000003a82000000 84 - - - r-x-- libselinux.so.1
0000003a82015000 2048 - - - ----- libselinux.so.1
0000003a82215000 8 - - - rw--- libselinux.so.1
0000003a82217000 4 - - - rw--- [ anon ]
0000003a82800000 68 - - - r-x-- libresolv-2.5.so
0000003a82811000 2048 - - - ----- libresolv-2.5.so
0000003a82a11000 4 - - - r---- libresolv-2.5.so
0000003a82a12000 4 - - - rw--- libresolv-2.5.so
0000003a82a13000 8 - - - rw--- [ anon ]
0000003d5f200000 112 - - - r-x-- ld-2.5.so
0000003d5f41b000 4 - - - r---- ld-2.5.so
0000003d5f41c000 4 - - - rw--- ld-2.5.so
0000003d5f600000 1328 - - - r-x-- libc-2.5.so
0000003d5f74c000 2048 - - - ----- libc-2.5.so
0000003d5f94c000 16 - - - r---- libc-2.5.so
0000003d5f950000 4 - - - rw--- libc-2.5.so
0000003d5f951000 20 - - - rw--- [ anon ]
0000003d5fa00000 8 - - - r-x-- libdl-2.5.so
0000003d5fa02000 2048 - - - ----- libdl-2.5.so
0000003d5fc02000 4 - - - r---- libdl-2.5.so
0000003d5fc03000 4 - - - rw--- libdl-2.5.so
0000003d60600000 88 - - - r-x-- libpthread-2.5.so
0000003d60616000 2044 - - - ----- libpthread-2.5.so
0000003d60815000 4 - - - r---- libpthread-2.5.so
0000003d60816000 4 - - - rw--- libpthread-2.5.so
0000003d60817000 16 - - - rw--- [ anon ]
0000003d60e00000 80 - - - r-x-- libz.so.1.2.3
0000003d60e14000 2044 - - - ----- libz.so.1.2.3
0000003d61013000 4 - - - rw--- libz.so.1.2.3
0000003d61600000 28 - - - r-x-- librt-2.5.so
0000003d61607000 2048 - - - ----- librt-2.5.so
0000003d61807000 4 - - - r---- librt-2.5.so
0000003d61808000 4 - - - rw--- librt-2.5.so
0000003d61e00000 52 - - - r-x-- libgcc_s-4.1.2-20080825.so.1
0000003d61e0d000 2048 - - - ----- libgcc_s-4.1.2-20080825.so.1
0000003d6200d000 4 - - - rw--- libgcc_s-4.1.2-20080825.so.1
0000003d62200000 8 - - - r-x-- libcom_err.so.2.1
0000003d62202000 2044 - - - ----- libcom_err.so.2.1
0000003d62401000 4 - - - rw--- libcom_err.so.2.1
0000003d64200000 8 - - - r-x-- libkeyutils-1.2.so
0000003d64202000 2044 - - - ----- libkeyutils-1.2.so
0000003d64401000 4 - - - rw--- libkeyutils-1.2.so
00002aaaaaaab000 16 - - - r-x-- lmnsd_ptcp.so
00002aaaaaaaf000 2044 - - - ----- lmnsd_ptcp.so
00002aaaaacae000 4 - - - rw--- lmnsd_ptcp.so
00002aaaac000000 22336 - - - rw--- [ anon ]
00002aaaad5d0000 43200 - - - ----- [ anon ]
00002aaab0000000 19812 - - - rw--- [ anon ]
00002aaab1359000 45724 - - - ----- [ anon ]
00002aaab4000000 22268 - - - rw--- [ anon ]
00002aaab55bf000 43268 - - - ----- [ anon ]
00002b0b7b5c5000 8 - - - rw--- [ anon ]
00002b0b7b5d1000 16 - - - rw--- [ anon ]
00002b0b7b5d5000 20 - - - r-x-- lmnet.so
00002b0b7b5da000 2044 - - - ----- lmnet.so
00002b0b7b7d9000 4 - - - rw--- lmnet.so
00002b0b7b7e5000 40 - - - r-x-- libnss_files-2.5.so
00002b0b7b7ef000 2044 - - - ----- libnss_files-2.5.so
00002b0b7b9ee000 4 - - - r---- libnss_files-2.5.so
00002b0b7b9ef000 4 - - - rw--- libnss_files-2.5.so
00002b0b7b9f0000 2876 - - - r-x-- libnss_ldap-2.5.so
00002b0b7bcbf000 2044 - - - ----- libnss_ldap-2.5.so
00002b0b7bebe000 164 - - - rw--- libnss_ldap-2.5.so
00002b0b7bee7000 64 - - - rw--- [ anon ]
00002b0b7bef7000 8 - - - r-x-- imuxsock.so
00002b0b7bef9000 2048 - - - ----- imuxsock.so
00002b0b7c0f9000 4 - - - rw--- imuxsock.so
00002b0b7c0fa000 20 - - - r-x-- imklog.so
00002b0b7c0ff000 2048 - - - ----- imklog.so
00002b0b7c2ff000 4 - - - rw--- imklog.so
00002b0b7c300000 4 - - - rw--- [ anon ]
00002b0b7c301000 12 - - - r-x-- lmnetstrms.so
00002b0b7c304000 2044 - - - ----- lmnetstrms.so
00002b0b7c503000 4 - - - rw--- lmnetstrms.so
00002b0b7c504000 8 - - - r-x-- lmtcpclt.so
00002b0b7c506000 2044 - - - ----- lmtcpclt.so
00002b0b7c705000 4 - - - rw--- lmtcpclt.so
00007fff2f4d0000 84 - - - rw--- [ stack ]
ffffffffff600000 8192 - - - ----- [ anon ]
---------------- ------ ------ ------ ------
total kB 331988 - - -
Here's the rsyslog.conf:
- Code: Select all
# -/- PUPPET -/- do not edit this file
# Source: rsyslog.conf.erb
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.* /dev/console
$DirCreateMode 0750
$DirGroup sysadmin
$DirOwner root
$FileCreateMode 0640
$FileGroup sysadmin
$FileOwner root
#### MODULES ####
$ModLoad imuxsock.so # provides support for local system logging (e.g. via logger command)
$ModLoad imklog.so # provides kernel logging support (previously done by rklogd)
#$ModLoad immark.so # provides --MARK-- message capability
$ModLoad omrelp
#### GLOBAL DIRECTIVES ####
# Use default timestamp format
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
#note: disabled, to use RFC 3339 instead
# enable high precision timestamps
$ActionForwardDefaultTemplate RSYSLOG_ForwardFormat
# File syncing capability is disabled by default. This feature is usually not required,
# not useful and an extreme performance hit
#$ActionFileEnableSync on
# snmpd is very verbose. Keep it local.
:programname,isequal,"snmpd" /var/log/snmpd
& ~
# "&" at the beginning of the line means reusing the previous rule
# "~" as an action mean dropping the log line; it will not be dispatched
# by futher rules.
# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none /var/log/messages
# The authpriv file has restricted access.
authpriv.* /var/log/secure
# Log all the mail messages in one place.
mail.* -/var/log/maillog
# Daemon related messages
daemon.* /var/log/daemon
# Cluster related messages
local4.* /var/log/cluster
# Log cron stuff
cron.* /var/log/cron
# Everybody gets emergency messages
*.emerg *
# Save news errors of level crit and higher in a special file.
uucp,news.crit /var/log/spooler
# Save boot messages also to boot.log
local7.* /var/log/boot.log
# ### begin forwarding rule ###
# The statement between the begin ... end define a SINGLE forwarding
# rule. They belong together, do NOT split them. If you create multiple
# forwarding rules, duplicate the whole block!
# Remote Logging (we use TCP for reliable delivery)
#
# An on-disk queue is created for this action. If the remote host is
# down, messages are spooled to disk and sent when it is up again.
$WorkDirectory /var/log/spool # where to place spool files
$ActionQueueFileName fwdRule1 # unique name prefix for spool files
$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
$ActionQueueType LinkedList # run asynchronously
$ActionResumeRetryCount -1 # infinite retries if host is down
*.* @@(o,z9)10.0.0.1:514
$ActionQueueFileName fwdRule2 # unique name prefix for spool files
$ActionQueueMaxDiskSpace 1g # 1gb space limit (use as much as possible)
$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
$ActionQueueType LinkedList # run asynchronously
$ActionResumeRetryCount -1 # infinite retries if host is down
*.* @@(o,z9)10.0.0.2:514


