Hi there,

I've been seeing the following stack trace in /var/log/messages. It seems
like something is trying to shut down rsyslog causing it to leave its
queues in a bad state. The log line preceding rsyslog termination with
signal 15 happens 14 minutes prior and doesn't give me any information on
who tried to terminate rsyslog. dmesg doesn't show rsyslog being killed
either. Any ideas how to track down what kills rsyslog?

Apr 17 15:57:37 m0058601 dhclient[771]: bound to ...
Apr 17 16:11:58 m0058601 rsyslogd: [origin software="rsyslogd"
swVersion="8.14.0" x-pid="2408" x-info="http://www.rsyslog.com";] exiting on
signal 15.
Apr 17 16:12:05 m0058601 rsyslogd: [origin software="rsyslogd"
swVersion="8.14.0" x-pid="10955" x-info="http://www.rsyslog.com";] start
Apr 17 16:12:05 m0058601 rsyslogd-2040: fatal error on disk queue
'omelasticsearch-event-indexer-http-request.log queue[DA]', emergency
switch to direct mode [v8.14.0 try http://www.rsyslog.com/e/2040 ]
Apr 17 16:12:05 m0058601 rsyslogd-2040: fatal error on disk queue
'omelasticsearch-syslog queue[DA]', emergency switch to direct mode
[v8.14.0 try http://www.rsyslog.com/e/2040 ]
Apr 17 16:12:04 m0058601 rsyslogd-2221: module 'imuxsock' already in this
config, cannot be added  [v8.14.0 try http://www.rsyslog.com/e/2221 ]
Apr 17 16:12:04 m0058601 rsyslogd-2221: module 'imklog' already in this
config, cannot be added  [v8.14.0 try http://www.rsyslog.com/e/2221 ]


Thanks,

Alec
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com/professional-services/
What's up with rsyslog? Follow https://twitter.com/rgerhards
NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of 
sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE 
THAT.

Reply via email to