within 24 hours of monitoring, it seems my load average does not go down, I seek advice and help.
I use:
centos 6
with xcache + memcached
Dedicated:
Dual Processor Intel Xeon 3Ghz
2GB RAM
my sites are not really that much traffic. I run 6 sites here
112.205.127.53 <<< this is my home IP not server IP
I also set DA security:
Time before failed login count resets 60 seconds
Remove an IP from the blacklist after 15 minutes
Blacklist IPs for excessive login attempts after 10 login attempts.
This is my last check after 10 min from "top" result above
20 minutes later check:
for 24 hours I dont know if this is normal, usually I just get load average of 1.0 2.0 2.0
it started when I use videoswiper to embed 4k+ videos and load average climbs high at the time of job, but it has been 24 hours and still had high load average.
I dont know if this could be a DOS attack or something similar,if this is please advice.
help
I use:
centos 6
with xcache + memcached
Dedicated:
Dual Processor Intel Xeon 3Ghz
2GB RAM
my sites are not really that much traffic. I run 6 sites here
Code:
top - 03:00:08 up 14:45, 1 user, [COLOR="red"]load average: 89.90, 107.69, 80.06[/COLOR]
Tasks: 333 total, 70 running, 263 sleeping, 0 stopped, 0 zombie
Cpu(s): 94.0%us, 5.5%sy, 0.0%ni, 0.0%id, 0.0%wa, 0.0%hi, 0.4%si, 0.0%st
Mem: 2054680k total, 1801632k used, 253048k free, 38116k buffers
Swap: 4128760k total, 219744k used, 3909016k free, 311912k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
1962 mysql 20 0 2859m 192m 3716 S 41.7 9.6 425:58.22 mysqld
25080 apache 20 0 292m 22m 13m R 13.7 1.1 0:11.36 httpd
25152 apache 20 0 290m 16m 7684 R 13.7 0.8 0:16.74 httpd
25283 apache 20 0 290m 23m 13m R 13.7 1.2 0:04.23 httpd
25155 apache 20 0 290m 17m 8420 R 13.4 0.9 0:17.10 httpd
25662 apache 20 0 290m 13m 3908 R 10.0 0.7 0:03.81 httpd
25457 apache 20 0 292m 17m 8472 R 8.4 0.8 0:05.23 httpd
24795 apache 20 0 298m 35m 20m R 8.1 1.8 0:15.97 httpd
24510 apache 20 0 289m 20m 12m S 7.8 1.0 0:32.35 httpd
25316 apache 20 0 290m 18m 9524 R 7.5 0.9 0:09.49 httpd
24349 apache 20 0 290m 21m 12m R 7.2 1.1 0:35.57 httpd
25315 apache 20 0 290m 15m 6480 R 7.2 0.8 0:13.37 httpd
25194 apache 20 0 290m 20m 12m R 6.2 1.0 0:11.23 httpd
25245 apache 20 0 294m 25m 13m R 6.2 1.2 0:08.63 httpd
25585 apache 20 0 290m 16m 7412 R 6.2 0.8 0:01.73 httpd
25762 apache 20 0 289m 11m 4284 R 6.2 0.6 0:00.22 httpd
25592 apache 20 0 292m 18m 9580 R 5.9 0.9 0:01.53 httpd
25311 apache 20 0 289m 14m 5844 R 5.6 0.7 0:11.48 httpd
25431 apache 20 0 294m 31m 18m R 5.6 1.6 0:06.76 httpd
25489 apache 20 0 290m 14m 5844 R 5.6 0.7 0:06.31 httpd
23899 apache 20 0 290m 21m 13m R 5.3 1.1 0:46.03 httpd
24501 apache 20 0 292m 21m 12m R 5.3 1.1 0:21.89 httpd
24588 apache 20 0 290m 24m 14m R 5.3 1.2 0:24.85 httpd
24401 apache 20 0 290m 19m 10m R 5.0 1.0 0:41.82 httpd
25219 apache 20 0 290m 12m 4240 R 5.0 0.6 0:17.14 httpd
25282 apache 20 0 289m 12m 4300 R 5.0 0.6 0:16.17 httpd
25675 apache 20 0 290m 13m 4420 R 5.0 0.7 0:03.25 httpd
25757 apache 20 0 290m 15m 7348 R 5.0 0.8 0:00.28 httpd
25760 apache 20 0 290m 12m 3904 R 5.0 0.6 0:00.44 httpd
25473 apache 20 0 289m 14m 5496 R 4.7 0.7 0:10.24 httpd
25738 apache 20 0 289m 12m 4176 R 4.7 0.6 0:00.61 httpd
24118 apache 20 0 293m 25m 15m R 4.4 1.2 0:52.25 httpd
Code:
[root@server ~]# tail /var/log/httpd/error_log
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
sh: /usr/local/bin/convert: No such file or directory
112.205.127.53 <<< this is my home IP not server IP
Code:
[root@server ~]# tail /var/log/directadmin/error.log
2011:12:05-10:54:53: Timeout from from 112.205.127.53 : last flagged: Command::doCommand(/CMD_DB)
2011:12:05-11:16:13: Timeout from from 112.205.127.53 : last flagged: getlock(./data/admin/login.hist) : finished
2011:12:05-11:19:27: Timeout from from 112.205.127.53 : last flagged: getlock(./data/users/myuser/login.hist) : finished
2011:12:05-11:29:54: Timeout from from 112.205.127.53 : last flagged: getlock(./data/admin/admin.usage) : finished
2011:12:05-11:31:37: removing old lock: ./data/admin/admin.usage.lock (age: 107 seconds)
2011:12:05-11:36:09: Timeout from from 112.205.127.53 : last flagged: Log::~Log : done
2011:12:05-11:36:10: *** Segmentation fault *** Log::~Log : done : User: admin : (null) : (null) : (null) : (null)
2011:12:05-11:36:35: Timeout from from 112.205.127.53 : last flagged: getDirFilesAndDirs(/usr/local/directadmin/data/sessions, *tlf, *tdlf, diradmin) : done
2011:12:05-23:40:04: Timeout from from 112.205.127.53 : last flagged: Log::~Log : done
2011:12:05-23:40:41: Timeout from from 112.205.127.53 : last flagged: Log::~Log : done
I also set DA security:
Time before failed login count resets 60 seconds
Remove an IP from the blacklist after 15 minutes
Blacklist IPs for excessive login attempts after 10 login attempts.
This is my last check after 10 min from "top" result above
Code:
top - 03:13:08 up 14:58, 1 user, [COLOR="red"] load average: 13.36, 26.72, 49.27[/COLOR]
Tasks: 239 total, 3 running, 235 sleeping, 0 stopped, 1 zombie
Cpu0 : 49.3%us, 0.3%sy, 0.0%ni, 50.3%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Cpu1 : 85.8%us, 4.0%sy, 0.0%ni, 10.2%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Cpu2 : 76.6%us, 11.9%sy, 0.0%ni, 10.9%id, 0.3%wa, 0.0%hi, 0.3%si, 0.0%st
Cpu3 : 32.3%us, 4.0%sy, 0.0%ni, 61.1%id, 2.0%wa, 0.0%hi, 0.7%si, 0.0%st
Mem: 2054680k total, 1255692k used, 798988k free, 66244k buffers
Swap: 4128760k total, 214648k used, 3914112k free, 466836k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
26774 apache 20 0 290m 16m 7600 R 89.8 0.8 0:36.46 httpd
26691 apache 20 0 292m 19m 10m S 55.7 1.0 0:11.14 httpd
27024 apache 20 0 289m 12m 4168 R 50.7 0.6 0:01.53 httpd
1962 mysql 20 0 2858m 191m 3748 S 49.1 9.5 433:31.79 mysqld
26993 apache 20 0 289m 18m 10m S 3.6 0.9 0:03.95 httpd
26885 apache 20 0 291m 19m 10m S 2.0 1.0 0:01.79 httpd
26985 apache 20 0 289m 14m 6112 S 1.3 0.7 0:00.47 httpd
25931 apache 20 0 0 0 0 Z 1.0 0.0 0:30.31 httpd <defunct>
26782 apache 20 0 292m 18m 9236 S 1.0 0.9 0:00.44 httpd
26635 apache 20 0 290m 17m 8828 S 0.7 0.9 0:15.89 httpd
26770 apache 20 0 292m 17m 8432 S 0.7 0.9 0:00.59 httpd
26920 root 20 0 15072 1276 868 R 0.7 0.1 0:00.64 top
26981 apache 20 0 289m 14m 6704 S 0.7 0.7 0:00.41 httpd
827 root 20 0 0 0 0 S 0.3 0.0 0:04.44 jbd2/dm-2-8
2220 named 20 0 392m 12m 1380 S 0.3 0.6 0:54.78 named
14454 root 20 0 285m 8684 4540 S 0.3 0.4 0:06.76 httpd
26006 apache 20 0 291m 24m 14m S 0.3 1.2 0:29.99 httpd
26341 apache 20 0 290m 20m 10m S 0.3 1.0 0:29.10 httpd
26620 apache 20 0 288m 17m 9540 S 0.3 0.9 0:22.29 httpd
26629 apache 20 0 289m 17m 8780 S 0.3 0.9 0:18.27 httpd
26640 apache 20 0 290m 17m 8816 S 0.3 0.9 0:17.33 httpd
26687 apache 20 0 290m 20m 11m S 0.3 1.0 0:16.53 httpd
26783 apache 20 0 288m 18m 10m S 0.3 0.9 0:15.70 httpd
26868 apache 20 0 290m 17m 8340 S 0.3 0.9 0:09.89 httpd
26897 apache 20 0 289m 15m 6884 S 0.3 0.7 0:16.09 httpd
26913 apache 20 0 289m 13m 5740 S 0.3 0.7 0:01.69 httpd
26924 apache 20 0 288m 16m 8592 S 0.3 0.8 0:00.19 httpd
26931 apache 20 0 290m 17m 9864 S 0.3 0.9 0:00.22 httpd
26978 apache 20 0 288m 12m 4844 S 0.3 0.6 0:00.11 httpd
26987 apache 20 0 289m 12m 4788 S 0.3 0.6 0:00.14 httpd
26990 apache 20 0 289m 18m 9576 S 0.3 0.9 0:00.22 httpd
26997 apache 20 0 289m 13m 5500 S 0.3 0.7 0:00.16 httpd
27002 apache 20 0 289m 13m 5300 S 0.3 0.7 0:01.64 httpd
27003 apache 20 0 286m 6344 1660 S 0.3 0.3 0:00.04 httpd
27018 apache 20 0 286m 6092 1592 S 0.3 0.3 0:00.01 httpd
20 minutes later check:
Code:
top - 03:46:32 up 15:31, 1 user, load average: 7.30, 3.70, 9.01
Tasks: 244 total, 7 running, 236 sleeping, 0 stopped, 1 zombie
Cpu0 : 84.0%us, 16.0%sy, 0.0%ni, 0.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Cpu1 : 96.4%us, 3.6%sy, 0.0%ni, 0.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Cpu2 : 98.7%us, 1.3%sy, 0.0%ni, 0.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Cpu3 : 93.1%us, 5.6%sy, 0.0%ni, 0.0%id, 0.0%wa, 0.0%hi, 1.3%si, 0.0%st
Mem: 2054680k total, 1876576k used, 178104k free, 351724k buffers
Swap: 4128760k total, 212524k used, 3916236k free, 626576k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
1962 mysql 20 0 2858m 191m 3752 S 62.5 9.5 447:34.63 mysqld
29899 apache 20 0 290m 18m 9888 R 59.2 0.9 0:02.72 httpd
30132 apache 20 0 289m 12m 4300 R 55.6 0.6 0:01.80 httpd
29880 apache 20 0 292m 19m 10m S 49.3 0.9 0:16.92 httpd
29910 apache 20 0 292m 22m 13m R 44.0 1.1 0:15.74 httpd
30028 apache 20 0 290m 14m 5744 R 44.0 0.7 0:14.56 httpd
29933 apache 20 0 290m 18m 9592 R 42.0 0.9 0:19.82 httpd
29694 apache 20 0 0 0 0 Z 12.6 0.0 0:22.36 httpd <defunct>
29926 apache 20 0 289m 13m 5176 S 12.6 0.7 0:18.15 httpd
30133 apache 20 0 289m 14m 6128 S 2.0 0.7 0:00.13 httpd
29920 apache 20 0 290m 17m 8336 S 1.7 0.9 0:18.69 httpd
30090 apache 20 0 289m 17m 9256 S 1.3 0.9 0:00.27 httpd
30124 apache 20 0 289m 16m 8864 S 1.3 0.8 0:01.11 httpd
30130 apache 20 0 289m 13m 5544 R 1.3 0.7 0:00.05 httpd
2220 named 20 0 392m 13m 2028 S 1.0 0.7 1:03.30 named
for 24 hours I dont know if this is normal, usually I just get load average of 1.0 2.0 2.0
it started when I use videoswiper to embed 4k+ videos and load average climbs high at the time of job, but it has been 24 hours and still had high load average.
I dont know if this could be a DOS attack or something similar,if this is please advice.
help