Hi. Ich finde nicht raus was die seit ein paar Tagen ungewöhnliche CPU und Connection Statistik bewirkt. Siehe Anhang. Wie man dort sieht ist der Prozess um "mysql" auch ungewöhnlich hoch. Normal ist mysql bei 10-25% CPU und PHP ist normal so zwischen 20-35% CPU.
# free –m
Das hier gibt mir nur "2" aus, daher kann das wohl kein DoS sein.
# netstat -n -p|grep SYN_REC | wc -l
Um sicherzugehen habe ich noch:
# netstat -plan|grep :80|awk {'print $5'}|cut -d: -f 1|sort|uniq -c|sort -nk 1
Die letzten Zeilen sind:
# netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
Hat jemand einen Vorschlag wie ich rausbekomme was hier die hohe CPU verursacht und auch die Zeitweise ungewöhnliche Connection?
Ich habe einen Plesk 11.5.30#34 Server mit centOS 6.5.
# free –m
total used free shared buffers cached
Mem: 32875488 29694640 3180848 0 1570836 23423748
-/+ buffers/cache: 4700056 28175432
Swap: 1023992 0 1023992
Das hier gibt mir nur "2" aus, daher kann das wohl kein DoS sein.
# netstat -n -p|grep SYN_REC | wc -l
Um sicherzugehen habe ich noch:
# netstat -plan|grep :80|awk {'print $5'}|cut -d: -f 1|sort|uniq -c|sort -nk 1
Show a list IP addresses and its number of connections that are connecting to port 80 on the server. Port 80 is used mainly by the HTTP protocol
Die letzten Zeilen sind:
15 66.249.64.*
16 2003
17 66.249.64.8
20 199.30.20.*
20 91.18.203.*
23 66.249.64.75
25 66.249.64.65
27 66.249.64.70
66 193.170.123.*
# netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
List the number of connections the IPs are making to the server using TCP or UDP protocol.
15 66.249.64.*
15 87.185.20.*
16 0.0.0.0
16 66.249.64.*
17 188.104.225.*
21 213.23.84.*
24 66.249.64.*
25 66.249.64.*
29 66.249.64.*
34 2003
36 2a02
202 127.0.0.1
2944 SERVER-IP
4195
Hat jemand einen Vorschlag wie ich rausbekomme was hier die hohe CPU verursacht und auch die Zeitweise ungewöhnliche Connection?
Ich habe einen Plesk 11.5.30#34 Server mit centOS 6.5.