Quantcast
Channel: Debian User Forums
Viewing all articles
Browse latest Browse all 3474

/var/log/syslog (9Gb) full of snmpd logs fills my /var !

$
0
0
Hello to all and thanks for reading!
------------------------------------

Since July 7, my /var/syslog (and daemon.log) are full of snmpd messages which look like :

Code:

Jul  7 22:08:10 <hostname> snmpd[<PID>]: send response: Failure in sendto (error parsing snmp message version)Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.1.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.2.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.3.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.4.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.5.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.6.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.7.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.8.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.1Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.2Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.3Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.4Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.5Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.6Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.7Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.8Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.9Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.2.10Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.1Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.2Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.3Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.4Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.5Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.6Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.7Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.8Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.9Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.3.10Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.1Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.2Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.3Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.4Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.5Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.6Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.7Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.8Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.9Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.9.1.4.10Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.1.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.2.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.3.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.4.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.5.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.6.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:11 <hostname> snmpd[<PID>]: send response: Failure in sendto
and it follows with same OID

Code:

Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.1.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.2.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.3.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.4.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.5.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.6.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.7.0Jul  7 22:08:11 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.1.8.0
until

Code:

Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.1.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.2.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.3.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.4.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.5.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.6.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:11 <hostname> snmpd[<PID>]: send response: Failure in sendto
0) <hostname> is the same machine that receives the logs.

1) this logs seem appear from 10/07/2024.

2) /etc/snmp/snmpd.conf was not modified since 2022.

3) Under ACCESS CONTROL in /etc/snmp/snmpd.conf i have:

Code:

view   systemonly  included   .1.3.6.1.2.1.1view   systemonly  included   .1.3.6.1.2.1.25.1
4) Before error message OID iso.3.6.1.2.1.25.1.7.0 appears twice:

Code:

Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:10 <hostname> snmpd[<PID>]:     -- iso.3.6.1.2.1.25.1.7.0Jul  7 22:08:11 <hostname> snmpd[<PID>]: send response: Failure in sendto
Could someone help me to resolve that symptom which fills (9Gb) two of my logs files ?

I have tried to play with force logrotate but it's just a remedy and does not cure the cause.

Thanks in advance.

Philippe

Statistics: Posted by 486DX2 — 2024-07-16 10:02 — Replies 1 — Views 12



Viewing all articles
Browse latest Browse all 3474

Latest Images

Trending Articles



Latest Images