LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-25-2006, 11:22 AM   #1
Rufus330Ci
Member
 
Registered: Aug 2002
Location: PA
Distribution: Mandrake Linux v10.2, RHEL3u8, RHEL4u4 & RHEL5 Client Beta2 for desktop
Posts: 59

Rep: Reputation: 15
Please Help on Reoccuring Message in SysLog


I was was wondering if you guys knew of a reoccuring message from maybe DHCP or something that gets sent to your var/syslog. I didnt have problems with overflowing logs until I this most recent Mandrake distro and I install the same programs everytime. It seems informational I just don't want to see it in syslog. Its overflowing this log and bandwidth is filing up too same message. I'd say 20,000 bytes every minute giving the 5gb free space a 5 day lifetime before it won't boot into kde due to space on a reboot I figured my options are a) set logrotate to daily b) write a script maybe to filter this going into the log or c) figure out where it is coming from. I'd like to do option c if possible instead of using up processing power to filter something or emptying a log daily in case I do have a problem. Thanks in advance if anyone has seen this before. Its probably just a flip of character in a config file atleast a hope


[root@rufusland log]# tail syslog
Jan 25 11:43:37 rufusland kernel: BANDWIDTH_IN:IN=eth0 OUT= MAC=00:##:##:##:35:##:00:##:41:##:33:##:08:00 SRC=192.168.1.1 DST=192.168.1.105 LEN=92 TOS=0x00 PREC=0x00 TTL=127 ID=63196 DF PROTO=TCP SPT=4680 DPT=22 WINDOW=64843 RES=0x00 ACK PSH URGP=0
Jan 25 11:43:37 rufusland kernel: BANDWIDTH_OUT:IN= OUT=eth0 SRC=192.168.1.105 DST=192.168.1.1 LEN=92 TOS=0x10 PREC=0x00 TTL=64 ID=40677 DF PROTO=TCP SPT=22 DPT=4680 WINDOW=32767 RES=0x00 ACK PSH URGP=0
Jan 25 11:43:37 rufusland kernel: BANDWIDTH_IN:IN=eth0 OUT= MAC=00:##:##:##:35:##:00:##:41:##:33:##:08:00 SRC=192.168.1.1 DST=192.168.1.105 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=63197 DF PROTO=TCP SPT=4680 DPT=22 WINDOW=64791 RES=0x00 ACK URGP=0
 
Old 01-25-2006, 11:27 AM   #2
Centinul
Member
 
Registered: Jun 2005
Distribution: Gentoo
Posts: 552

Rep: Reputation: 30
Well I think the easiest solution would be a two part process. First look at your syslog configuration file and second read the syslog documentation. Syslog is logging entries from your firewall apparently every time that something enters or leaves your machine.

Actually another alternative would be to look into iptables (the firewall built into linux kernel) and see if you can set what are called the "log limit" and "log burst" flags so not as many entries get put into your logs.

Do a little bit of reading and let us know how it goes. Hope this helps.
 
Old 01-25-2006, 12:57 PM   #3
Rufus330Ci
Member
 
Registered: Aug 2002
Location: PA
Distribution: Mandrake Linux v10.2, RHEL3u8, RHEL4u4 & RHEL5 Client Beta2 for desktop
Posts: 59

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by Centinul
Well I think the easiest solution would be a two part process. First look at your syslog configuration file and second read the syslog documentation. Syslog is logging entries from your firewall apparently every time that something enters or leaves your machine.

Actually another alternative would be to look into iptables (the firewall built into linux kernel) and see if you can set what are called the "log limit" and "log burst" flags so not as many entries get put into your logs.

Do a little bit of reading and let us know how it goes. Hope this helps.
I'll read up an do alittle file snooping on what you said from work. Thanks man I'll let you know how it turns out.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
message from syslog: disabling 1rq#21 ylts Linux - Hardware 0 02-21-2005 12:18 PM
syslog error message saag Linux - Newbie 0 03-20-2004 02:28 PM
Crystal Sound - syslog message... stardotstar Linux - Hardware 3 11-18-2003 01:28 PM
syslog errer message and interrupt problem bass Linux - Newbie 5 04-15-2003 07:37 AM
strange sshd syslog message dunkyb Linux - General 1 12-30-2002 08:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration