OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [discuss] syslog overload after removing pendisk

From: Sergey Latkin (slatkinphg.com)
Date: Thu Oct 02 2003 - 11:36:11 CDT


On Thursday October 2 2003 07:28, Simon Oosthoek wrote:
> On Thu, Oct 02, 2003 at 01:05:28PM +0200, Simon Oosthoek wrote:
> > the messages in syslog don't start immediately when I unmount and extract
> > the pendisk from the usbport.
>
> I've looked at it some more, to see if there was a pattern to the log
> entries.
>
> Some strange things:
> I get lots of
> Oct 1 15:25:47 pc021 fam[4456]: connect: Connection refused
> but they're probably not related.
>
> Between the disconnect message of the usb agent there are no related log
> entries until the syslog file is rotated (or something else that happens at
> that time?) at 04:02. about 1.5 minutes after that, the entries begin and
> continue at a continuous rate.
>
> This is what I see at the top of a syslog file:
> Oct 2 04:02:00 pc021 syslogd 1.4.1: restart.
> Oct 2 04:03:30 pc021 kernel: Device not ready. Make sure there is a disc
> in the drive. Oct 2 04:03:30 pc021 kernel: VFS: Disk change detected on
> device 08:00 Oct 2 04:03:30 pc021 kernel: sda : READ CAPACITY failed.

Something that runs after logrotate in /etc/cron.daily. Probably, msec.
Are you sure the disk was unmounted properly? fam sometimes locks into disks
and after that umount requests fail with 'Device is in use' errors.

Next time after you unmount and remove the disk, type 'mount' on the commend
prompt and see what you get there.

>
> These are the first entries in both cases.
>
> Any ideas where I can look next to find the cause of this?
>
> Cheers
>
> Simon

--
Sergey Latkin
Chief Technology Officer
Pinnacle Health Group
1-(800)-492-7771
http://www.phg.com