Hi there, I've been seeing the following stack trace in /var/log/messages. It seems like something is trying to shut down rsyslog causing it to leave its queues in a bad state. The log line preceding rsyslog termination with signal 15 happens 14 minutes prior and doesn't give me any information on who tried to terminate rsyslog. dmesg doesn't show rsyslog being killed either. Any ideas how to track down what kills rsyslog?
Apr 17 15:57:37 m0058601 dhclient[771]: bound to ... Apr 17 16:11:58 m0058601 rsyslogd: [origin software="rsyslogd" swVersion="8.14.0" x-pid="2408" x-info="http://www.rsyslog.com"] exiting on signal 15. Apr 17 16:12:05 m0058601 rsyslogd: [origin software="rsyslogd" swVersion="8.14.0" x-pid="10955" x-info="http://www.rsyslog.com"] start Apr 17 16:12:05 m0058601 rsyslogd-2040: fatal error on disk queue 'omelasticsearch-event-indexer-http-request.log queue[DA]', emergency switch to direct mode [v8.14.0 try http://www.rsyslog.com/e/2040 ] Apr 17 16:12:05 m0058601 rsyslogd-2040: fatal error on disk queue 'omelasticsearch-syslog queue[DA]', emergency switch to direct mode [v8.14.0 try http://www.rsyslog.com/e/2040 ] Apr 17 16:12:04 m0058601 rsyslogd-2221: module 'imuxsock' already in this config, cannot be added [v8.14.0 try http://www.rsyslog.com/e/2221 ] Apr 17 16:12:04 m0058601 rsyslogd-2221: module 'imklog' already in this config, cannot be added [v8.14.0 try http://www.rsyslog.com/e/2221 ] Thanks, Alec _______________________________________________ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-services/ What's up with rsyslog? Follow https://twitter.com/rgerhards NOTE WELL: This is a PUBLIC mailing list, posts are ARCHIVED by a myriad of sites beyond our control. PLEASE UNSUBSCRIBE and DO NOT POST if you DON'T LIKE THAT.

