Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-07-2009, 04:37 PM
Loyal Member
 
Posts: 84
Default Massive log files full of slapd messages

My /var filesystem run out of space earlier so I've grown it form 2Gb to 3Gb (I can grow it further if needed). Looking in /var/log the three logs debug, syslog and zimbra.log are massive (over 650Mb each) and full of slapd log line sequences like:
Code:
Feb  7 22:58:04 z5 slapd[2921]: conn=8004 op=5132 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15303 SRCH base="" scope=2 deref=0 filter="(&(zimbraDomainName=editeddomain.com.tw)(zimbraDomainType=alias)(zimbraMailStatus=enabled))"
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15303 SRCH attr=zimbraDomainName
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15303 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15304 SRCH base="" scope=2 deref=0 filter="(&(zimbraDomainName=editeddomain.com.tw)(zimbraDomainType=local)(zimbraMailStatus=enabled))"
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15304 SRCH attr=zimbraDomainName
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15304 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15305 SRCH base="" scope=2 deref=0 filter="(&(|(zimbraMailDeliveryAddress=linhr.tw@editeddomain.com.tw)(zimbraDomainName=linhr.tw@editeddomain.com.tw))(zimbraMailStatus=enabled))"
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15305 SRCH attr=zimbraMailTransport
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15305 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15306 SRCH base="" scope=2 deref=0 filter="(&(|(zimbraMailDeliveryAddress=editeddomain.com.tw)(zimbraDomainName=editeddomain.com.tw))(zimbraMailStatus=enabled))"
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15306 SRCH attr=zimbraMailTransport
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15306 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15307 SRCH base="" scope=2 deref=0 filter="(&(|(zimbraMailDeliveryAddress=.com.tw)(zimbraDomainName=.com.tw))(zimbraMailStatus=enabled))"
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15307 SRCH attr=zimbraMailTransport
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15307 SEARCH RESULT tag=101 err=0 nentries=0 text=
Feb  7 22:58:04 z5 slapd[2921]: conn=7975 op=15308 SRCH base="" scope=2 deref=0 filter="(&(|(zimbraMailDeliveryAddress=.tw)(zimbraDomainName=.tw))(zimbraMailStatus=enabled))"
(I've edited the domain name being referenced in those lines)

I'm guessing that these lines are emminiating from the processing that happens when mail, in this case junk as there is no reason I can think of for .tw addresses to be contacting this server, comes in.

The log file size isn't due to log rotation failing (which is usually the problem in such cases) as the content of the 650+Mb zimbra.log file only covers the last 18 hours.

Is there a safe/easy way to make slapd be less "chatty", or should I just find room to further grow the logical volume that holds /var? This may just be a "on off" anomaly due to an influx of junk, as the previous zimbra.log currently zimbra.log.0) is only 22M large.
Reply With Quote
  #2 (permalink)  
Old 02-07-2009, 06:23 PM
Outstanding Member
 
Posts: 684
Default Maybe your answer

http://www.zimbra.com/forums/adminis...-wildness.html
Reply With Quote
  #3 (permalink)  
Old 02-08-2009, 02:59 AM
Loyal Member
 
Posts: 84
Default

Thanks for the pointer, I'll give tweaking that setting that a try.

The original value was 16640 (16384+256 which the LDAP docs list as "print syncrepl (replica) logging" and "stats log connections/operations/results" - is that the normal value for a Zimbra install? The default stated in the LDAP docs is 256 (stats only).

I'll try the 32768 value suggested in the linked thread (which seems to be "log errors only"). Is there anything else that ou recommend having turned on in the logging options?
Reply With Quote
  #4 (permalink)  
Old 02-08-2009, 03:16 AM
Outstanding Member
 
Posts: 684
Default Pretty sure....

there is a way to reduce the amount of what gets logged - make it less chatty. There was a forum post regarding that issue but I can't find it. I never have much luck with the search. It's there somewhere though.
Reply With Quote
  #5 (permalink)  
Old 02-08-2009, 04:07 AM
Loyal Member
 
Posts: 84
Default

I've been poking around and I think I've found the original source of the problem. I had a large amount (over 6000 messages) of what looks like back-scatter in the deferrered mail queue.

I'll keep the LDAP logging options low (thanks to Bill for the pointer on that) as I don't think that is going to cause any problems, and keep an eye on the queues in case it occurs again and is something worse then back-scatter (i.e. someone has found a way to relay through me).
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.