[rsyslog] rsyslog 5.2.0 meets signal 11.

Martin Mielke martinmie at PartyGaming.com
Thu Nov 5 13:51:38 CET 2009


Hi,

Yesterday I successfully upgraded our logservers to the stable rsyslog
5.2.0.
This morning I found out that the rsyslog process on the primary server
was dead.

Digging a bit in the logs I found this:
--
# grep stop logserver.20091104.log
2009-11-04T07:32:01.970288-05:00 logserver kernel: Kernel logging (proc)
stopped.
--

According to the audit.log, it received a SIGSEGV (kill -11):
--
type=ANOM_ABEND msg=audit(1257340663.009:19009): auid=4294967295 uid=0
gid=0  ses=4294967295 pid=25881 comm="rsyslogd" sig=11
--

...so, the application died on nov. 4th 2009 @ 8:17:43 EST
--
# date -d @1257340663.009
Wed Nov  4 08:17:43 EST 2009
--

Has this been observed for this v5 stable branch?? And is there any fix?

And, auditd was needed in order to determine the reason why rsyslogd was
stopped. Could it be possible to have a more verbose message when the
process stops due to an anomaly?



Cheers,
Martin


This email and any attachments are confidential, and may be legally privileged and protected by copyright. If you are not the intended recipient dissemination or copying of this email is prohibited. If you have received this in error, please notify the sender by replying by email and then delete the email completely from your system. 

Any views or opinions are solely those of the sender.  This communication is not intended to form a binding contract unless expressly indicated to the contrary and properly authorised. Any actions taken on the basis of this email are at the recipient's own risk.





More information about the rsyslog mailing list