Ad Widget

Collapse

Zabbix Server Spamt mir das audit.log voll

Collapse
This topic has been answered.
X
X
 
  • Time
  • Show
Clear All
new posts
  • fireboyff
    Junior Member
    • Jun 2023
    • 6

    #1

    Zabbix Server Spamt mir das audit.log voll

    Hallo

    ich habe nun einige Tage damit verbracht eine Lösung zu finden, leider ohne erfolg.
    Mein Problem besteht darin das mein Zabbix Server sehr viel Rechenleistung aufbringt da Zabbix anscheinend jeden Ping an einen Host auch unter /var/log/audit/audit.log sichert. Dies Bremst mittlerweile mein System sehr aus und hat nun auch schon knapp 400GB an daten erzeugt. Daher meine Frage, kann ich das irgendwo abschalten??? Ich brauche diese eintragungen nicht.

    Ein auszug aus der audit.log:

    Code:
    type=PROCTITLE msg=audit(1686153484.066:1397351524): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233136205B676F742033207661 6C75657320696E20342E363934303837207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351525): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=5653a86d3560 a2=10 a3=0 items=0 ppid=3543 pid=4157 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351525): saddr=020000000A85D4210000000000000000^]SADDR={ saddr_fam=inet laddr=10.133.212.33 lport=0 }
    type=PROCTITLE msg=audit(1686153484.066:1397351525): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233131205B676F742033207661 6C75657320696E20342E363934313538207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351526): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=5653a86323a0 a2=10 a3=0 items=0 ppid=3543 pid=4162 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351526): saddr=020000000A85D4810000000000000000^]SADDR={ saddr_fam=inet laddr=10.133.212.129 lport=0 }
    type=PROCTITLE msg=audit(1686153484.066:1397351526): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233136205B676F742033207661 6C75657320696E20342E363934303837207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351527): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=7ffdd5802f00 a2=10 a3=0 items=0 ppid=3543 pid=4157 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351527): saddr=00000000000000000000000000000000^]SADDR=unknown-family(0)
    type=PROCTITLE msg=audit(1686153484.066:1397351527): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233131205B676F742033207661 6C75657320696E20342E363934313538207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351528): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=7ffdd5802f00 a2=10 a3=0 items=0 ppid=3543 pid=4162 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351528): saddr=00000000000000000000000000000000^]SADDR=unknown-family(0)
    type=PROCTITLE msg=audit(1686153484.066:1397351528): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233136205B676F742033207661 6C75657320696E20342E363934303837207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351529): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=5653a858f2a0 a2=10 a3=0 items=0 ppid=3543 pid=4157 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351529): saddr=020000000A85D7010000000000000000^]SADDR={ saddr_fam=inet laddr=10.133.215.1 lport=0 }
    type=PROCTITLE msg=audit(1686153484.066:1397351529): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233131205B676F742033207661 6C75657320696E20342E363934313538207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351530): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=5653a85db8b0 a2=10 a3=0 items=0 ppid=3543 pid=4162 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351530): saddr=020000000A85D4410000000000000000^]SADDR={ saddr_fam=inet laddr=10.133.212.65 lport=0 }
    type=PROCTITLE msg=audit(1686153484.066:1397351530): proctitle=2F7573722F7362696E2F7A61626269785F736572 7665723A20706F6C6C657220233136205B676F742033207661 6C75657320696E20342E363934303837207365632C20676574 74696E672076616C7565735D
    type=SYSCALL msg=audit(1686153484.066:1397351531): arch=c000003e syscall=42 success=yes exit=0 a0=12 a1=7ffdd5802f00 a2=10 a3=0 items=0 ppid=3543 pid=4157 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm="zabbix_serve$
    type=SOCKADDR msg=audit(1686153484.066:1397351531): saddr=00000000000000000000000000000000^]SADDR=unknown-family(0)
    evt kann mir ja jemand Helfen danke.​
  • Answer selected by fireboyff at 29-06-2023, 14:45.
    fireboyff
    Junior Member
    • Jun 2023
    • 6

    Zur Info falls dieses Thema mal jemand anderen treffen sollte, ich konnte die Ursache finden.

    In meinem Fall war der Windows Defender Dienst auch auf diesem System Installiert. Dieser hat jede Netzwerk Connection im Audit.log geloggt.
    Da bei Zabbix dies einige sind, war dies eine extreme zusätzliche Last.

    lg Olli

    Comment

    • Toormser
      Junior Member
      • Feb 2023
      • 5

      #2
      • Zabbix Server Log
      • Zabbix Server Config
      • Zabbix Agent Version
      • Zabbix Server Version

      Comment

      • fireboyff
        Junior Member
        • Jun 2023
        • 6

        #3

        Zabbix Server Version:
        zabbix_server (Zabbix) 6.2.6
        Revision 6981d8b729a 5 December 2022, compilation time: Dec 5 2022 10:20:52​

        Zabbix Agent Version:
        zabbix_agentd (daemon) (Zabbix) 6.2.6
        Revision 6981d8b729a 5 December 2022, compilation time: Dec 5 2022 10:20:52

        Config:
        Code:
        ############ GENERAL PARAMETERS #################
        
        ### Option: LogFile
        #       Log file name for LogType 'file' parameter.
        #
        # Mandatory: yes, if LogType is set to file, otherwise no
        # Default:
        # LogFile=
        
        LogFile=/pkgmnt/zabbix/log/zabbix_server.log
        
        ### Option: LogFileSize
        #       Maximum size of log file in MB.
        #       0 - disable automatic log rotation.
        #
        # Mandatory: no
        # Range: 0-1024
        # Default:
        # LogFileSize=1
        
        LogFileSize=0
        
        ### Option: PidFile
        #       Name of PID file.
        #
        # Mandatory: no
        # Default:
        # PidFile=/tmp/zabbix_server.pid
        
        PidFile=/run/zabbix/zabbix_server.pid
        
        ### Option: SocketDir
        #       IPC socket directory.
        #               Directory to store IPC sockets used by internal Zabbix services.
        #
        # Mandatory: no
        # Default:
        # SocketDir=/tmp
        
        SocketDir=/run/zabbix
        
        ############ ADVANCED PARAMETERS ################
        
        ### Option: StartPollers
        #       Number of pre-forked instances of pollers.
        #
        # Mandatory: no
        # Range: 0-1000
        # Default:
        # StartPollers=5
        StartPollers=50
        
        ### Option: StartPollersUnreachable
        #       Number of pre-forked instances of pollers for unreachable hosts (including IPMI and Java).
        #       At least one poller for unreachable hosts must be running if regular, IPMI or Java pollers
        #       are started.
        #
        # Mandatory: no
        # Range: 0-1000
        # Default:
        # StartPollersUnreachable=1
        StartPollersUnreachable=50
        
        ### Option: StartHistoryPollers
        #       Number of pre-forked instances of history pollers.
        #       Only required for calculated checks.
        #       A database connection is required for each history poller instance.
        #
        # Mandatory: no
        # Range: 0-1000
        # Default:
        # StartHistoryPollers=5
        
        ### Option: StartPingers
        #       Number of pre-forked instances of ICMP pingers.
        #
        # Mandatory: no
        # Range: 0-1000
        # Default:
        StartPingers=500
        
        ### Option: StartDiscoverers
        #       Number of pre-forked instances of discoverers.
        #
        # Mandatory: no
        # Range: 0-250
        # Default:
        StartDiscoverers=100
        
        ### Option: SNMPTrapperFile
        #       Temporary file used for passing data from SNMP trap daemon to the server.
        #       Must be the same as in zabbix_trap_receiver.pl or SNMPTT configuration file.
        #
        # Mandatory: no
        # Default:
        # SNMPTrapperFile=/tmp/zabbix_traps.tmp
        
        SNMPTrapperFile=/var/log/snmptrap/snmptrap.log
        
        ### Option: CacheSize
        #       Size of configuration cache, in bytes.
        #       Shared memory size for storing host, item and trigger data.
        #
        # Mandatory: no
        # Range: 128K-64G
        # Default:
        CacheSize=3G
        
        ### Option: StartDBSyncers
        #       Number of pre-forked instances of DB Syncers.
        #
        # Mandatory: no
        # Range: 1-100
        # Default:
        # StartDBSyncers=4
        StartDBSyncers=24
        
        ### Option: HistoryCacheSize
        #       Size of history cache, in bytes.
        #       Shared memory size for storing history data.
        #
        # Mandatory: no
        # Range: 128K-2G
        # Default:
        HistoryCacheSize=32M
        
        ### Option: HistoryIndexCacheSize
        #       Size of history index cache, in bytes.
        #       Shared memory size for indexing history cache.
        #
        # Mandatory: no
        # Range: 128K-2G
        # Default:
        # HistoryIndexCacheSize=4M
        HistoryIndexCacheSize= 56M
        
        ### Option: TrendCacheSize
        #       Size of trend write cache, in bytes.
        #       Shared memory size for storing trends data.
        #
        # Mandatory: no
        # Range: 128K-2G
        # Default:
        TrendCacheSize=128M
        
        ### Option: TrendFunctionCacheSize
        #       Size of trend function cache, in bytes.
        #       Shared memory size for caching calculated trend function data.
        #
        # Mandatory: no
        # Range: 128K-2G
        # Default:
        # TrendFunctionCacheSize=4M
        
        ### Option: ValueCacheSize
        #       Size of history value cache, in bytes.
        #       Shared memory size for caching item history data requests.
        #       Setting to 0 disables value cache.
        #
        # Mandatory: no
        # Range: 0,128K-64G
        # Default:
        ValueCacheSize=1G
        
        ### Option: Timeout
        #       Specifies how long we wait for agent, SNMP device or external check (in seconds).
        #
        # Mandatory: no
        # Range: 1-30
        # Default:
        # Timeout=3
        
        Timeout=4
        
        ### Option: LogSlowQueries
        #       How long a database query may take before being logged (in milliseconds).
        #       Only works if DebugLevel set to 3, 4 or 5.
        #       0 - don't log slow queries.
        #
        # Mandatory: no
        # Range: 1-3600000
        # Default:
        # LogSlowQueries=0
        
        LogSlowQueries=3000
        
        ####### LOADABLE MODULES #######
        
        ####### TLS-RELATED PARAMETERS #######
        
        ####### For advanced users - TLS ciphersuite selection criteria #######
        
        ####### For advanced users - TCP-related fine-tuning parameters #######
        
        ####### High availability cluster parameters #######
        zz0.dd7c95mi4pkzz​
        ​Zabbix Log: (Ich habe die Values weg gelassen da es sonst zu unleserlich wäre, es kommen jedenfalls nur diese einträge)
        Code:
        1742035:20230612:133559.898 slow query: 3.486733 sec, "insert into history_uint (itemid,clock,ns,value) values 
        1742017:20230612:133559.921 slow query: 3.757828 sec, "insert into history_uint (itemid,clock,ns,value) values 
        1742038:20230612:133600.188 slow query: 5.576199 sec, "insert into history_uint (itemid,clock,ns,value) values
        1742033:20230612:133601.020 slow query: 5.000073 sec, "insert into history_uint (itemid,clock,ns,value) values
        1742034:20230612:133601.283 slow query: 6.342942 sec, "insert into history_uint (itemid,clock,ns,value) values 
        1742044:20230612:133601.331 slow query: 6.477346 sec, "insert into history_uint (itemid,clock,ns,value) values
        ​

        Comment

        • Toormser
          Junior Member
          • Feb 2023
          • 5

          #4
          Auf was für einer Hardware läuft der Zabbix Server (oder ggf. Virtualisiert) (OS, RAM, Storage, CPU, NIC, Umgebung) was für ein Network Interface und was für ein Value/Sec (Zabbix server: Number of processed values per secons) Ratio hast du aktuell? Sind restliche Systemlogs auffällig, dass mit deinem Base-OS etwas nicht stimmt? Sind es nur bestimmte Hosts bzw. was wird abgefragt? Wird auf den Hosts zufällig Postgres abgefragt?
          Last edited by Toormser; 12-06-2023, 14:26.

          Comment

          • fireboyff
            Junior Member
            • Jun 2023
            • 6

            #5
            Aktuell läuft Zabbix in einer VM (Red Hat Enterprise 8.7, 8 Corse, 16GB Ram, 1TB Storage) es gibt nur eine All in One Installation.

            Zabbix server: Zabbix server: Number of processed character values per second: 19.4789
            Zabbix server: Zabbix server: Number of processed log values per second: 11.7678
            Zabbix server: Zabbix server: Number of processed not supported values per second: 119.086
            Zabbix server: Zabbix server: Number of processed numeric (float) values per second: 155.708
            Zabbix server: Zabbix server: Number of processed numeric (unsigned) values per second: 2606.6946
            Zabbix server: Zabbix server: Number of processed text values per second: 0.06633
            Zabbix server: Zabbix server: Number of processed values per second: 2774.5525

            Im Log finde ich nur die Zabbix Einträge, also sollte eigentlich alles passen.

            Comment

            • fireboyff
              Junior Member
              • Jun 2023
              • 6

              #6
              Zur Info falls dieses Thema mal jemand anderen treffen sollte, ich konnte die Ursache finden.

              In meinem Fall war der Windows Defender Dienst auch auf diesem System Installiert. Dieser hat jede Netzwerk Connection im Audit.log geloggt.
              Da bei Zabbix dies einige sind, war dies eine extreme zusätzliche Last.

              lg Olli

              Comment

              Working...