Results 1 to 7 of 7
  1. #1

    Server Crashing (long post sorry)

    Hello All,

    I have a box that goes down every 5-7 days. I am running Redhat 7.3 with esim pro with power tools. 1 gig memory.





    I have Logwatch installed and have posted a copy for review.

    The server runs fine for awhile the only issue in the logs is :
    Unmatched Entries**
    Command stream end of file, while reading line [email protected] host=server1.*********.com [66.139.75.17]: 5 Time(s)
    imap service init from 66.139.75.17: 111 Time(s)

    then almost like clock work around the 5 th day the server goes down. When I check the logs I see:

    WARNING: Kernel Errors Present
    hda: dma_intr: error=0x84 { DriveStat...: 5 Time(s)
    hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }...: 5 Time(s) see below for full copy of log.

    I have search for info on the errors and have found refines to , drives going bad, file system problems , even bad memory problems.

    Any help with ID the issues and how to fix, also if it is a hard issues how can I document it and or test it to give to hosting CO.

    Many thanks

    Kevin

    Logwatch Info:

  2. #2

    log info part 1

    POP3, IMAP] Logins:
    ====================
    User | Logins | Size
    ---------------------------------------------------- | ------ | -----------
    [email protected] | 103 |
    ---------------------------------------------------------------------------
    103 | 0



    **Unmatched Entries**
    Command stream end of file, while reading line [email protected] host=server1********.com [66.139.75.17]: 5 Time(s)
    imap service init from 66.139.75.17: 111 Time(s)

    ---------------------- courier-mta End -------------------------


    --------------------- Cron Begin ------------------------



    Commands Run:
    User root:
    /usr/bin/mrtg /etc/mrtg/mrtg.cfg: 288 Time(s)
    /usr/bin/run-parts /etc/logrotate/d: 4 Time(s)
    /usr/lib/opcenter/virtualhosting/MailQueueCleaner: 24 Time(s)
    /usr/lib/sa/sa1 1 1: 144 Time(s)
    /usr/lib/sa/sa2 -A: 1 Time(s)
    /usr/local/bin/weblogs: 144 Time(s)
    /usr/local/sbin/bwcron: 1 Time(s)
    /usr/local/sim/sim -q >> /dev/null 2>&1: 288 Time(s)
    nice --adjustment=15 /usr/local/sbin/update_site_summary_cache: 12 Time(s)
    run-parts /etc/cron.daily: 1 Time(s)
    run-parts /etc/cron.hourly: 24 Time(s)
    run-parts /var/VhbackupSchedules/schedule_daily/0\:2: 1 Time(s)
    run-parts /var/VhbackupSchedules/schedule_daily/0\:3: 1 Time(s)
    run-parts /var/VhbackupSchedules/schedule_daily/14\:2: 1 Time(s)
    run-parts /var/VhbackupSchedules/schedule_daily/30\:3: 1 Time(s)
    run-parts /var/VhbackupSchedules/schedule_daily/30\:4: 1 Time(s)

    CRON Restarted 2 Time(s)

    ---------------------- Cron End -------------------------


    --------------------- httpd Begin ------------------------

    0.00 MB transfered in 308 responses (1xx 308, 2xx 0, 3xx 0, 4xx 0, 5xx 0)
    0 Images (0 bytes),
    0 Documents (0 bytes),
    0 Archives (0 bytes),
    0 Sound files (0 bytes),
    0 Movies files (0 bytes),
    0 Windows executable files (0 bytes),
    0 Content pages (0 bytes),
    0 Redirects (0 bytes),
    0 Proxy Configuration Files (0 bytes),
    0 Program source files (0 bytes),
    0 CD Images (0 bytes),
    308 Other (0 bytes)

    A total of 1 unidentified 'other' records logged
    with response code(s)

    ---------------------- httpd End -------------------------


    --------------------- Init Begin ------------------------

    Entered or switched to runlevel 6: 1 Time(s)

    ---------------------- Init End -------------------------


    --------------------- Kernel Begin ------------------------


    WARNING: Kernel Errors Present
    hda: dma_intr: error=0x84 { DriveStat...: 5 Time(s)
    hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }...: 5 Time(s)

    2 Time(s): ide0: BM-DMA at 0xfc00-0xfc07, BIOS settings: hdaMA, hdbio
    2 Time(s): ide1: BM-DMA at 0xfc08-0xfc0f, BIOS settings: hdcio, hddio
    2 Time(s): BIOS-e820: 0000000000000000 - 000000000009fc00 (usable)
    2 Time(s): BIOS-e820: 000000000009fc00 - 00000000000a0000 (reserved)
    2 Time(s): BIOS-e820: 00000000000f0000 - 0000000000100000 (reserved)
    2 Time(s): BIOS-e820: 0000000000100000 - 000000003f7f0000 (usable)
    2 Time(s): BIOS-e820: 000000003f7f0000 - 000000003f7f8000 (ACPI data)
    2 Time(s): BIOS-e820: 000000003f7f8000 - 000000003f800000 (ACPI NVS)
    2 Time(s): BIOS-e820: 00000000fec00000 - 00000000fec01000 (reserved)
    2 Time(s): BIOS-e820: 00000000fee00000 - 00000000fee01000 (reserved)
    2 Time(s): BIOS-e820: 00000000fffc0000 - 0000000100000000 (reserved)
    2 Time(s): hda: hda1 hda2 hda3
    2 Time(s): 119MB HIGHMEM available.
    2 Time(s): 8139too Fast Ethernet driver 0.9.26
    2 Time(s): 896MB LOWMEM available.
    2 Time(s): Adding Swap: 1052248k swap-space (priority -1)
    2 Time(s): BIOS-provided physical RAM map:
    2 Time(s): Based upon Swansea University Computer Society NET3.039
    2 Time(s): Buffer-cache hash table entries: 65536 (order: 6, 262144 bytes)
    2 Time(s): CPU: AMD Athlon(tm) XP 2100+ stepping 01
    2 Time(s): CPU: L1 I Cache: 64K (64 bytes/line), D cache 64K (64 bytes/line)
    2 Time(s): CPU: L2 Cache: 256K (64 bytes/line)
    2 Time(s): Calibrating delay loop... 3473.40 BogoMIPS
    2 Time(s): Checking 'hlt' instruction... OK.
    2 Time(s): Console: colour VGA+ 80x25

  3. #3

    log info part 2

    2 Time(s): Dentry cache hash table entries: 131072 (order: 8, 1048576 bytes)
    2 Time(s): Detected 1741.975 MHz processor.
    2 Time(s): Detected PS/2 Mouse Port.
    2 Time(s): EXT3 FS 2.4-0.9.19, 19 August 2002 on ide0(3,1), internal journal
    2 Time(s): EXT3 FS 2.4-0.9.19, 19 August 2002 on ide0(3,3), internal journal
    1 Time(s): EXT3-fs: INFO: recovery required on readonly filesystem.
    4 Time(s): EXT3-fs: mounted filesystem with ordered data mode.
    1 Time(s): EXT3-fs: recovery complete.
    1 Time(s): EXT3-fs: write access will be enabled during recovery.
    2 Time(s): Enabling fast FPU save and restore... done.
    2 Time(s): Enabling unmasked SIMD FPU exception support... done.
    2 Time(s): FDC 0 is a post-1991 82077
    2 Time(s): Freeing initrd memory: 119k freed
    2 Time(s): Freeing unused kernel memory: 116k freed
    2 Time(s): IP Protocols: ICMP, UDP, TCP, IGMP
    2 Time(s): IP: routing cache hash table of 8192 buckets, 64Kbytes
    2 Time(s): Initializing CPU#0
    2 Time(s): Initializing RT netlink socket
    2 Time(s): Inode cache hash table entries: 65536 (order: 7, 524288 bytes)
    2 Time(s): Inspecting /boot/System.map-2.4.20-28.7
    2 Time(s): Intel machine check architecture supported.
    2 Time(s): Intel machine check reporting enabled on CPU#0.
    2 Time(s): Journalled Block Device driver loaded
    2 Time(s): Kernel command line: ro root=/dev/hda3
    1 Time(s): Kernel log daemon terminating.
    1 Time(s): Kernel logging (proc) stopped.
    2 Time(s): Linux IP multicast router 0.06 plus PIM-SM
    2 Time(s): Linux NET4.0 for Linux 2.4
    2 Time(s): Linux version 2.4.20-28.7 ([email protected]) (gcc version 2.96 20000731 (Red Hat Linux 7.3 2.96-126)) #1 Thu Dec 18 11:18:28 EST 2003
    2 Time(s): Loaded 17281 symbols from /boot/System.map-2.4.20-28.7.
    2 Time(s): Loaded 78 symbols from 7 modules.
    2 Time(s): Memory: 1019776k/1040320k available (1161k kernel code, 17024k reserved, 983k data, 116k init, 122816k highmem)
    2 Time(s): Mount cache hash table entries: 512 (order: 0, 4096 bytes)
    2 Time(s): NET4: Frame Diverter 0.46
    2 Time(s): NET4: Linux TCP/IP 1.0 for NET4.0
    2 Time(s): NET4: Unix domain sockets 1.0/SMP for Linux NET4.0.
    2 Time(s): On node 0 totalpages: 260080
    4 Time(s): PCI: Hardcoded IRQ 14 for device 00:11.1
    2 Time(s): PCI: PCI BIOS revision 2.10 entry at 0xfdb01, last bus=1
    2 Time(s): PCI: Probing PCI hardware
    2 Time(s): PCI: Using IRQ router default [1106/3177] at 00:11.0
    2 Time(s): PCI: Using configuration type 1
    2 Time(s): POSIX conformance testing by UNIFIX
    2 Time(s): Page-cache hash table entries: 262144 (order: 8, 1048576 bytes)
    2 Time(s): Partition check:
    2 Time(s): RAMDISK driver initialized: 16 RAM disks of 4096K size 1024 blocksize
    2 Time(s): RAMDISK: Compressed image found at block 0
    2 Time(s): Real Time Clock Driver v1.10e
    2 Time(s): Serial driver version 5.05c (2001-07-08) with MANY_PORTS MULTIPORT SHARE_IRQ SERIAL_PCI ISAPNP enabled
    2 Time(s): Starting kswapd
    2 Time(s): Symbols match kernel version 2.4.20.
    2 Time(s): TCP: Hash tables configured (established 262144 bind 65536)
    2 Time(s): Uniform Multi-Platform E-IDE driver Revision: 7.00beta3-.2.4
    2 Time(s): VFS: Disk quotas vdquot_6.5.1
    2 Time(s): VFS: Mounted root (ext2 filesystem).
    2 Time(s): VP_IDE: IDE controller at PCI slot 00:11.1
    2 Time(s): VP_IDE: VIA vt8235 (rev 00) IDE UDMA133 controller on pci00:11.1
    2 Time(s): VP_IDE: chipset revision 6
    2 Time(s): VP_IDE: not 100%% native mode: will probe irqs later
    2 Time(s): allocated 32 pages and 32 bhs reserved for the highmem bounces
    2 Time(s): apm: BIOS version 1.2 Flags 0x03 (Driver version 1.16)
    2 Time(s): blk: queue c0372d40, I/O limit 4095Mb (mask 0xffffffff)
    2 Time(s): eth0: RealTek RTL8139 Fast Ethernet at 0xf88b8f00, 00:20:ed:74:b7:25, IRQ 12
    2 Time(s): eth0: Setting half-duplex based on auto-negotiated partner ability 0000.
    2 Time(s): hda: 117231408 sectors (60022 MB) w/2048KiB Cache, CHS=7297/255/63, UDMA(100)
    2 Time(s): hda: ST360015A, ATA DISK drive
    2 Time(s): hda: attached ide-disk driver.
    2 Time(s): hda: host protected area => 1
    4 Time(s): ide-floppy driver 0.99.newide
    2 Time(s): ide0 at 0x1f0-0x1f7,0x3f6 on irq 14
    1 Time(s): ide0: reset: success
    4 Time(s): ide: Assuming 33MHz system bus speed for PIO modes; override with idebus=xx
    2 Time(s): ip_tables: (C) 2000-2002 Netfilter core team
    2 Time(s): isapnp: No Plug & Play device found
    2 Time(s): isapnp: Scanning for PnP cards...
    4 Time(s): kjournald starting. Commit interval 5 seconds
    2 Time(s): klogd 1.4.1, log source = /proc/kmsg started.
    2 Time(s): md: ... autorun DONE.
    2 Time(s): md: Autodetecting RAID arrays.
    2 Time(s): md: autorun ...
    2 Time(s): md: md driver 0.90.0 MAX_MD_DEVS=256, MD_SB_DISKS=27
    2 Time(s): mtrr: detected mtrr type: Intel
    2 Time(s): mtrr: v1.40 (20010327) Richard Gooch ([email protected])
    2 Time(s): pty: 2048 Unix98 ptys configured
    2 Time(s): ttyS0 at 0x03f8 (irq = 4) is a 16550A
    2 Time(s): ttyS1 at 0x02f8 (irq = 3) is a 16550A
    2 Time(s): zone(0): 4096 pages.
    2 Time(s): zone(1): 225280 pages.
    2 Time(s): zone(2): 30704 pages.

    ---------------------- Kernel End -------------------------


    --------------------- MailScanner Begin ------------------------


    MailScanner Status:
    249 messages Scanned by MailScanner
    1985291 Total Bytes
    110 messages Tagged as Spam by MailScanner
    1 Viruses found by MailScanner
    1 Banned attachments found by MailScanner
    3 Content Problems found by MailScanner
    249 messages Delivered by MailScanner

    Virus Report: (Total Seen = 1 )
    Worm.SomeFool.P: 1 Times(s)

    Content Report: (Total Seen = 3 )
    Microsoft-specific exploits: 3 Times(s)

    Filename Report: (Total Seen = 1 )
    Possible MS-Dos program shortcut attack (websites01_pantyhose_pimps_house.pif) : 1 Times(s)

    **Unmatched Entries**
    Skipping sender of precedence bulk : 1 Time(s)

    ---------------------- MailScanner End -------------------------


    --------------------- Named Begin ------------------------

    Named started: 4 Time(s)
    Named shutdown: 1 Time(s)

    Loaded Zones:
    0.0.127.in-addr.arpa/IN: 2 Time(s)
    bombardierds650.com/IN: 2 Time(s)
    localhost/IN: 2 Time(s)

    **Unmatched Entries**
    named shutdown failed: 1 Time(s)

    ---------------------- Named End -------------------------


    --------------------- PAM_pwdb Begin ------------------------


    Opened Sessions:
    Service: su
    User gots8q - 2 Time(s)
    User eg47az - 2 Time(s)
    User suzu - 2 Time(s)
    User bomb4 - 2 Time(s)
    User xfms2q - 1 Time(s)
    User choice7 - 2 Time(s)
    User fight4 - 2 Time(s)
    User hfr7q - 2 Time(s)
    User honda - 2 Time(s)
    User test - 1 Time(s)
    User tcsrac9 - 1 Time(s)
    User perd49 - 1 Time(s)
    Service: ftp
    User suzu - 3 Time(s)
    User eg47az - 1 Time(s)
    User gots8q - 9 Time(s)
    User choice7 - 24 Time(s)
    User tmoss23 - 7 Time(s)

    Authentication Failures:
    (uid=0) -> dkid
    Service: imap: 3 time(s)

    ---------------------- PAM_pwdb End -------------------------


    --------------------- pam_unix Begin ------------------------

    sshd:
    Sessions Opened:
    ---------------------- pam_unix End -------------------------


    --------------------- proftpd-messages Begin ------------------------


    Failed FTP Logins:

    Invalid Username:
    anonymous:
    host6-65.pool80116.interbusiness.it : 1 Time(s)
    ip68-2-126-230.ph.ph.cox.net : 2 Time(s)
    ip68-231-71-27.ph.ph.cox.net : 4 Time(s)
    p508F79D0.dip.t-dialin.net : 1 Time(s)
    [email protected]:
    ip68-231-71-27.ph.ph.cox.net : 1 Time(s)

    **Unmatched Entries**
    server1.choice-technologies.com (ip68-3-92-168.ph.ph.cox.net[68.3.92.168]) - FTP session idle timeout, disconnected.
    proftpd startup succeeded
    server1.choice-technologies.com - ProFTPD 1.2.7 (stable) (built Wed Sep 24 16:26:44 IST 2003) standalone mode STARTUP
    server1.choice-technologies.com - ProFTPD killed (signal 15)
    server1.choice-technologies.com - ProFTPD 1.2.7 standalone mode SHUTDOWN
    proftpd shutdown succeeded
    proftpd startup succeeded
    server1.choice-technologies.com - ProFTPD 1.2.7 (stable) (built Wed Sep 24 16:26:44 IST 2003) standalone mode STARTUP
    server1.choice-technologies.com - /etc/shutmsg present: all incoming connections will be refused.
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)
    server1.choice-technologies.com (ip68-231-71-27.ph.ph.cox.net[68.231.71.27]) - ProFTPD terminating (signal 11)

    ---------------------- proftpd-messages End -------------------------

    Apr 20 18:33:10 hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }
    Apr 20 18:33:10 hda: dma_intr: error=0x84 { DriveStatusError BadCRC }
    Apr 20 18:58:08 hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }
    Apr 20 18:58:08 hda: dma_intr: error=0x84 { DriveStatusError BadCRC }
    Apr 20 18:58:08 hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }
    Apr 20 18:58:08 hda: dma_intr: error=0x84 { DriveStatusError BadCRC }
    Apr 20 18:58:09 hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }
    Apr 20 18:58:09 hda: dma_intr: error=0x84 { DriveStatusError BadCRC }
    Apr 20 18:58:09 hda: dma_intr: status=0x51 { DriveReady SeekComplete Error }
    Last edited by ctech; 04-27-2004 at 12:09 AM.

  4. #4
    Join Date
    Mar 2003
    Location
    California USA
    Posts
    13,294
    Your drive is at the end of its life, i suggest you get it replaced asap
    Steven Ciaburri | Industry's Best Server Management - Rack911.com
    Software Auditing - 400+ Vulnerabilities Found - Quote @ https://www.RACK911Labs.com
    Fully Managed Dedicated Servers (Las Vegas, New York City, & Amsterdam) (AS62710)
    FreeBSD & Linux Server Management, Security Auditing, Server Optimization, PCI Compliance

  5. #5
    How can I test the drive or see the drives info, my host has replaced the drive or say did in the last 90 days.


    Thank you

  6. #6
    Join Date
    Apr 2004
    Posts
    78
    Originally posted by ctech
    How can I test the drive or see the drives info, my host has replaced the drive or say did in the last 90 days.


    Thank you
    hdparm -I /dev/hde

    That should give u more info then you need to know =) Just replace hde with your drive name.

  7. #7
    Thx everyone

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •