New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Many ossec-maild
processes stuck at ep_poll
#1848
Comments
I've seen similar problems. PR #1842 is an attempt to fix some of the problems. Testing would be appreciated! |
I have similar issue with about 15 ossec-maild processes when running service started for 1 hour and about 350 after 1 day I only have:
OSSEC version: 1:3.6.0-12032.el7.art (also tested with 1:3.6.0-11279.el7.art) local mta: postfix-2.10.1-9.el7.x86_64 (also tested with remote smtp server) ossec-maild conf:
debug enabled with the following command: Is there a way to increase ossec-maild verbosity ? How can I test #1848 (comment) ? As workaround, I added the following content to /etc/logrotate.d/ossec-hids in /var/ossec/logs/ossec.log section
|
@sic-bordeaux I recommend testing #1891 instead. |
How can I test it ? |
|
Thank you, for the moment I just git pull https://github.com/ddpbsd/ossec-hids.git "revert_dns" && cd src && make TARGET=server && cp src/ossec-maild /var/ossec/bin/ossec-maild && /var/ossec/bin/ossec-control reload I'll test it for 2 hours before revert to previous version for the weekend and make more tests next week |
It does not work. Mail are not send at all. |
@sic-bordeaux Strange, works for me. Try changing |
Thanks, mails are sent when I use IP address istead of name and only copying ossec-maild compiled binary to ossec bin dir. |
Seems to be ok for now. only 1 ossec-maild process and mails still being delivered |
Everything is ok after one week with this ossec-maild binary. |
closed as resolved |
Many
ossec-maild
processes are stuck onep_poll
and eventually the system becomes unusable.OSSEC Version: 3.6.0 (also present in at least 3.4.0) installed from Atomic RPMs
OS: CentOS 7.7
OSSEC Maild config:
The local MTA is postfix
And there's nothing interesting in
/var/log/maillog
to indicate problems betweenossec-maild
andpostfix
itself.Process list
The following output is from a system where OSSEC has been running for ~ 40 minutes. Process ID 21540 is the "main"
ossec-maild
process and you can see many processes stuck in theS
leep state atep_poll
(I have removed most of these for brevity). You can also see that there are some processes in theR
unning state that have high system times. Occasionally I have been ending up with<defunct>
processes but there were none at the time of the output below."No socket." errors
I noticed something strange too. After
ossec-maild
getsSIG_TERM
/var/ossec/logs/ossec.log
is flooded with "ERROR: No socket." messages.Maybe something kicked off by
dispatch_event()
?ossec-hids/src/os_maild/sendmail.c
Lines 160 to 164 in a973a7e
The text was updated successfully, but these errors were encountered: