2008年1月17日木曜日

シスログ管理

20080117
システムログを別ホストのログ管理サーバに出力させるための手順。

■手順概要
1) ログ管理サーバ側でリモートホストから出力されるログを受け取れるようにする。
2) リモートホスト側でログ管理サーバにログを出力する。

_______________________________
1) ログ管理サーバの設定 192.168.24.17
 ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄
■/etc/init.d/syslog の設定
[root@RHEL4 ~]# vi /etc/init.d/syslog
--------------------vi syslog------------------------------------
SYSLOGD_OPTIONS="-m 0 -r" ← -r オプションを追記
-----------------------------------------------------------------

■設定を反映させる
[root@RHEL4 ~]# /etc/init.d/syslog restart
カーネルロガーを停止中: [ OK ]
システムロガーを停止中: [ OK ]
システムロガーを起動中: [ OK ]
カーネルロガーを起動中: [ OK ]

/var/log/messages には下記のように出力される
Jan 17 18:56:13 RHEL4 kernel: Kernel logging (proc) stopped.
Jan 17 18:56:13 RHEL4 kernel: Kernel log daemon terminating.
Jan 17 18:56:14 RHEL4 syslog: klogd 停止 succeeded
Jan 17 18:56:14 RHEL4 exiting on signal 15
Jan 17 18:56:14 RHEL4 syslogd 1.4.1: restart (remote reception).
Jan 17 18:56:15 RHEL4 syslog: syslogd 起動 succeeded
Jan 17 18:56:15 RHEL4 syslog: klogd 起動 succeeded
Jan 17 18:56:15 RHEL4 kernel: klogd 1.4.1, log source = /proc/kmsg started.
Jan 17 18:56:14 RHEL4 syslog: syslogd 停止 succeeded


_______________________________
2) リモートホストの設定 192.168.24.18
 ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄
■/etc/syslog.conf の設定
[root@hoge2 ~]# vi /etc/syslog.conf
--------------------vi syslog.conf-----------------------------------
*.info;mail.none;authpriv.none;cron.none @192.168.24.17
---------------------------------------------------------------------

■設定を反映させる
[root@hoge2 ~]# /etc/init.d/syslog restart
カーネルロガーを停止中: [ OK ]
システムロガーを停止中: [ OK ]
システムロガーを起動中: [ OK ]
カーネルロガーを起動中: [ OK ]

ログ管理サーバの /var/log/messages には下記のように出力された!
Jan 17 19:06:59 192.168.24.18 syslogd 1.4.1: restart.
Jan 17 19:06:59 192.168.24.18 syslog: syslogd 起動 succeeded
Jan 17 19:06:59 192.168.24.18 kernel: klogd 1.4.1, log source = /proc/kmsg started.
Jan 17 19:06:59 192.168.24.18 syslog: klogd 起動 succeeded
Jan 17 19:07:02 192.168.24.18 syslog: syslogd 停止 succeeded


■参考サイト
http://www.atmarkit.co.jp/flinux/rensai/root03/root03a.html

2007年10月14日日曜日

swap領域追加

■現状確認
[root@tanyao /]# cat /proc/swaps
Filename Type Size Used Priority
/dev/mapper/VolGroup00-LogVol01 partition 524280 37132 -1


■2GB(1024k x 2048byte = 2097152)のswap領域を/swap/swapに作成する
[root@tanyao /]# mkdir swap

[root@tanyao /]# dd if=/dev/zero of=/swap/swap bs=1024 count=2097152
2097152+0 records in
2097152+0 records out
2147483648 bytes (2.1 GB) copied, 58.53 seconds, 36.7 MB/s

[root@tanyao /]# mkswap /swap/swap
Setting up swapspace version 1, size = 2147479 kB

[root@tanyao /]# swapon /swap/swap
→完了

確認してみると、
[root@tanyao /]# cat /proc/swaps
Filename Type Size Used Priority
/dev/mapper/VolGroup00-LogVol01 partition 524280 37132 -1
/swap/swap file 2097144 0 -2

または、
[root@tanyao /]# swapon -s
Filename Type Size Used Priority
/dev/mapper/VolGroup00-LogVol01 partition 524280 37132 -1
/swap/swap file 2097144 0 -2

■起動時に確保されるように…。
/etc/fstab を vi で開いて、下記を追加。
/swap/swap swap swap defaults 0 0

2007年7月23日月曜日

時刻同期手順

■dateコマンドであらかじめ時刻を合わせておく
[root@tanyao ~]# date 072310312007
2007年 7月 23日 月曜日 10:31:00 JST

■/etc/ntp.conf を編集
# --- OUR TIMESERVERS -----
# server 0.pool.ntp.org
# server 1.pool.ntp.org
# server 2.pool.ntp.org
server 192.168.199.126
restrict 192.168.199.126 mask 255.255.255.255 nomodify notrap noquery

■ntpdを起動する
[root@tanyao ~]# /etc/init.d/ntpd start
ntpd 繧定オキ蜍穂クュ: [ OK ]

■少し時間をおいてから、ntpqコマンドを実行
[root@tanyao ~]# /usr/sbin/ntpq -p
remote refid st t when poll reach delay offset jitter
==============================================================================
192.168.199.126 202.232.0.1 4 u - 64 3 4.475 -33939. 3387.84
LOCAL(0) LOCAL(0) 10 l 62 64 1 0.000 0.000 0.002

■サービスとして登録しておく?(不要かも)
[root@tanyao ~]# echo "/etc/init.d/ntpd start" >> /etc/rc.d/rc.local


■手動で時刻を同期する(ntpdを停止してから)
[root@tanyao ~]# ntpdate 192.168.199.126
11 Oct 15:02:42 ntpdate[15326]: step time server 192.168.199.126 offset 4.384445 sec


■/etc/ntp.conf を置換えてみる
[root@tanyao ~]# cat /etc/ntp.conf
# デフォルトで全てのNTPアクセス拒否
restrict default ignore

# ローカルホストからはNTPアクセス許可
restrict 127.0.0.1

# 外部のNTPサーバへのNTPアクセス許可(下記serverで指定したサーバを全て指定。
# NICTやMFEEDはラウンドロビンでどのサーバになるか不定のため全て記述すること。)
restrict 192.168.199.126 mask 255.255.255.255 nomodify notrap noquery

# 外部のNTPサーバの指定
server 192.168.199.126

# 変動情報記録ファイルの指定(起動前にファイルがあることを確認。なければ作成しておく。)
driftfile /var/lib/ntp/drif

# 認証の指定(上位NTPサーバの認証キーがある場合は、yesとすることで認証可能)
authenticate no

→再起動
[root@tanyao ~]# /etc/init.d/ntpd start
ntpd: 譎る俣繧オ繝シ繝舌→蜷梧悄荳ュ: [ OK ]
ntpd 繧定オキ蜍穂クュ: [ OK ]

[root@tanyao ~]# /usr/sbin/ntpq -p
remote refid st t when poll reach delay offset jitter
==============================================================================
192.168.199.126 202.232.0.1 4 u 52 64 3 7.868 -652.73 4611.07

ラベルの意味:
 remote リモート・サーバーのホスト名
 refid 参照ID(不明の場合は、0.0.0.0)
 st stratum番号、サーバーが第何階層かを表します。
 t 階層タイプ(l:local,u:unicast,m:multicast,b:broadcast)
 when 最後のパケットを受け取ってからの時間(単位:秒)
 poll ポーリング間隔(単位:秒)
 reach 到達可能なレジスタを(8進数表現)
 delay ポーリングインターバルの遅延見積もり(単位:ミリ秒)
 offset 階層のオフセット(単位:ミリ秒)
 disp 階層の分散(単位:ミリ秒)


しばらくすると完全に合わせられる?!
[root@tanyao ~]# /usr/sbin/ntpq -p
remote refid st t when poll reach delay offset jitter
==============================================================================
192.168.199.126 .STEP. 16 u 149 64 0 0.000 0.000 4000.00