/var/log is 2.9 GB

Today I was amazed to find that my / partition had gone from 62% fullness
to 100% ?
turns out /var/log is 2.9 GB something that doesn't seem normal to me or at laist very suspicious can I just clear out this folder without hazard to my system or should I be careful ?
I have found both errors.log and everything.log are about 980 MB large ? I'm now looking for other possible culprits

Once you know that your system is alright, install logrotate and it will keep the log files down to a reasonable size. The default is one month long logs. But, you need to find out what's creating these huge logs first. I suggest that you start looking through those and see what the problem is.

Similar Messages

  • ICal doesn't show delegation, and generates date and time error messages in /var/log/system.log

    I have a problem with my iCal, when I use my caldav account, I can only see my own calendar on my MBA, on my co-workers MBP it works fine with both my account and his. My co-worker can't see other calendars than his own when he uses iCal on my laptop.
    We can reproduce this problem on his computer by setting Location to Automatic rather than Amsterdam, then after deleting iCal's cache files, the caldav account and setting the Location back to Amsterdam solves the problem for him.
    It does not solve the problem for me (or several other co-workers). We've been looking at this for a few weeks, and we can not find any clear pattern why certain machines have this problem and others don't.
    All machines (both affected and unaffected) are running Mac OS 10.7.2 with iCal 5.0.1
    I've spoken to Apple support over the phone (in the Netherlands), unfortunately, they couldn't help with this.
    So far we've tried numerous location and language settings, but on affected machines nothing appears to solve the delegation problem (which we assume to be connected to the error messages iCal generates)
    Starting iCal yeilds the following error messages in /var/log/system.log:
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=3
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=10
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 iCal[23884]: Unexpected EOF, returning last token as fallback
    Jan  5 11:31:05 dhcp-91 iCal[23884]: VTIMEZONE does not match System Time Zone (Europe/Amsterdam) for 20100105T000000 to 20120105T000000: (
                  "interval: 2001-01-01 01:00:00 +0100, offset: 3600"
              ) != (
                  "interval: 2010-03-28 03:00:00 +0200, offset: 7200",
                  "interval: 2010-10-31 02:00:00 +0100, offset: 3600",
                  "interval: 2011-03-27 03:00:00 +0200, offset: 7200",
                  "interval: 2011-10-30 02:00:00 +0100, offset: 3600"
              BEGIN:VTIMEZONE
              X-LIC-LOCATION:Europe/Amsterdam
              TZID:Europe/Amsterdam
              BEGIN:DAYLIGHT
              TZOFFSETFROM:+0100
              TZNAME:CEST
              TZOFFSETTO:+0200
              DTSTART:19700329T020000
              END:DAYLIGHT
              BEGIN:STANDARD
              TZOFFSETFROM:+0200
              TZNAME:CET
              TZOFFSETTO:+0100
              DTSTART:19701025T030000
              END:STANDARD
              END:VTIMEZONE
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=3
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 [0x0-0x58f58f].com.apple.iCal[23884]: line 1,1: expecting FREQUENCE, found 'BYDAY' as token type 5
    Jan  5 11:31:05 dhcp-91 iCal[23884]: iCalendar recurrence failure BYDAY=-1SU;FREQ=YEARLY;BYMONTH=10
              line 1,6: unexpected char: '='
    Jan  5 11:31:05 dhcp-91 iCal[23884]: Unexpected EOF, returning last token as fallback
    Jan  5 11:31:05 dhcp-91 iCal[23884]: VTIMEZONE does not match System Time Zone (Europe/Amsterdam) for 20100105T000000 to 20120105T000000: (
                  "interval: 2001-01-01 01:00:00 +0100, offset: 3600"
              ) != (
                  "interval: 2010-03-28 03:00:00 +0200, offset: 7200",
                  "interval: 2010-10-31 02:00:00 +0100, offset: 3600",
                  "interval: 2011-03-27 03:00:00 +0200, offset: 7200",
        "interval: 2011-10-30 02:00:00 +0100, offset: 3600"
              BEGIN:VTIMEZONE
              X-LIC-LOCATION:Europe/Amsterdam
              TZID:Europe/Amsterdam
              BEGIN:DAYLIGHT
              TZOFFSETFROM:+0100
              TZNAME:CEST
              TZOFFSETTO:+0200
              DTSTART:19700329T020000
              END:DAYLIGHT
              BEGIN:STANDARD
              TZOFFSETFROM:+0200
              TZNAME:CET
              TZOFFSETTO:+0100
              DTSTART:19701025T030000
              END:STANDARD
              END:VTIMEZONE
    And when I close iCal I get:
    Jan  5 11:33:25 dhcp-91 [0x0-0x592592].com.apple.iCal[23894]: token mismatch: 4 != 5

    I'm seeing the same thing, and I can't even find where OS X stores calendars on disk anymore...

  • Hard Drive filling up: SubmitDiagInfo, /private/var & log issues

    This topic is part question, part help for people I've seen having a similar problem in other threads. My issue is different enough from the other issues, that I wanted to post it as a separate topic.
    I've had about 24GB of available space for weeks now. I haven't downloaded any large files recently, nor created any myself.
    Suddenly I noticed the hard drive space decreasing. I went from 24GB, to 19GB, to 10GB, then 8, 5, 1.5... next thing I knew, it said I had 260MB available. This was within maybe two days, with a big ramp-down within a couple of hours this morning, while I was on a train, and not even connected to a network.
    I started getting error messages saying my hard drive was full; then, I got errors saying I didn't have enough application memory, and applications were being paused, and I would have to force quit them. Within about 5 minutes, I dropped from 1.5GB to 260MB.
    Thinking back, the last week or so, I remembered that sometimes when I came into my office in the morning, my Mac would be awake (I usually sleep it at the end of the day, and an error message would be displayed saying SubmitDiagInfo had crashed. I thought this might have something to do with it.
    I did some detective work in these forums. I checked Activity Monitor and the Console. Sure enough, SubmitDiagInfo was taking up a bunch of CPU time.
    The Console revealed I had a lot of Diagnostic Logs. I tried deleting them with the Console's Clear button, but it didn't seem to do anything. I checked with OmniDiskSweep, and sure enough, I had over 20GB of log files.
    At this point, my hard drive was so full, I had to force quit OmniDiskSweep. I used the Go To Folder command and entered /private/var/log - The Diagnostic Logs folder was nearly 20GB. I deleted it and emptied the trash immediately.
    I looked at the /private/var/vm folder and noticed it was also very large (10GB), but I had read elsewhere not to mess with this folder.
    From the console, I quit SubmitDiagInfo.
    I check my hard drive, and I'm suddenly back to 24GB free space.
    When I look again at /private/var/vm, and sure enough it is 5GB smaller.
    This is weird stuff, and I hope this description helps anyone else having this problem.
    What's interesting is, because the /private folder is invisible, you can't use it to calculate your disk space usage. For example, the folders on my drive had the following space usage:
    62.46GB34.53GB+22.96GB+4.78GB4.02GB = 128.75GB (plus a few "small" folders with maybe 300MB)
    Since the drive showed 159GB total space available, I couldn't figure out where the other 30GB was.
    Once I found /private/log, I could see it had 19.29GB:
    62.4634.53+22.96+4.78+4.0219.29 = 148.04 - ah, this makes more sense, but I'm still missing 10GB! So, I look at /private/vm, and boom, there is the extra 10.6GB hiding. All 159GB present and accounted for.
    The question I have is, of course, can anyone explain why this is happening, so I can prevent it from happening again?
    I hope someone finds this helpful.

    Thanks... that is helpful. I have Carbon Copy Cloner, not
    Super Duper, so I will keep that solution in mind.
    Do not, repeat do not, clone your current suspect hard drive
    to your CCC backup. That would defeat the purpose of having
    a good backup. I don't know if you can boot from you CCC
    backup. That would be a good test. I was able to boot from
    my SuperDuper backup and notice normal hard drive space.
    In the meantime, I ran the extended system test, and the
    computer passed.
    Mine with the growing hard drive passed every test I had plus
    the test Apple recommended. They were quick place the blame
    on a Virtual Windows XP Pro. I do not thing that was the
    problem. My normal Macintosh HD is usually about 52 GB
    and it was showing 110 GB used and I never could figure out
    what was hogging the hard drive.
    Good luck!

  • Var/log/mail.log file empty

    My var/log/mail.log isn't logging anything, the file seems to empty since 4th March 2010 3:15 AM
    Have tried the below mentioned troubleshooting steps, but no luck though
    1. Stopped and restarted mail service
    2. Repaired disk permissions through disk utility application
    3. Repaired permissions through terminal diskutil
    4. Restarted daemons as suggested in this forum http://discussions.info.apple.com/thread.jspa?threadID=2088823&tstart=60
    5. Changed permissions as suggested on this forum http://forums.macosxhints.com/archive/index.php/t-13985.html
    Any help please!!!

    Change the archive log to 3 days. Make sure all three log levels are set to information. Restart mail and see if any thing appears in the logs.
    Also how are you viewing the logs - using SA or Console?
    Thanks,
    Henry

  • ERROR messages in /var/log/messages

    Hi,
    I encountered a error messages in /var/log/messages please find below
    Dec 9 04:03:08 drs syslogd 1.4.1: restart (remote reception).
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:03:18 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:03:18 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    Dec 9 04:08:19 drs logger: Could not access /etc/oracle/scls_scr/drs/root/crsstart.
    Dec 9 04:08:19 drs init: Id "h1" respawning too fast: disabled for 5 minutes
    Dec 9 04:10:46 drs rpc.mountd: authenticated unmount request from 10.3.141.26:651 for /opt/backup_log/srv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:657 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated unmount request from 10.3.141.26:672 for /opt/backup_log/websrv (/opt/backup_log)
    Dec 9 04:10:47 drs rpc.mountd: authenticated mount request from 10.3.141.26:677 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:12:01 drs rpc.mountd: authenticated unmount request from 10.3.141.26:849 for /opt/backup_log/ws (/opt/backup_log)
    Dec 9 04:13:20 drs logger: Oracle Cluster Ready Services disabled by corrupt install
    and database (oracle 10g) is running fine, but i cant figure out what could be the problem, can anyone just help me out on this.
    Jafar

    Hi,
    #h1:35:respawn:/etc/init.d/init.cssd run >/dev/null 2>&1 </dev/null
    by commenting above line in initttab file would stop messaging, is this would have any adverse affect on the database. As its a production server, so i am really taking time to resolve it. Your suggestions are welcome. If there is no harm in commenting the above line then i would go forward to comment that line.
    Thanks
    Jafar>

  • Errors in a log file /var/log/system.log

    I'm getting these errors in a log file /var/log/system.log
    Shutdown:
    Sep 21 12:41:38 Mac-mini.local WindowServer[86]: CGXGetConnectionProperty: Invalid connection 42243
    Sep 21 12:41:38 Mac-mini.local coreservicesd[58]: SendFlattenedData, got error #268435459 (ipc/send) invalid destination port from ::mach_msg(), sending notification kLSNotifyApplicationDeath to notificationID=145
    Sep 21 12:41:38 Mac-mini.local WindowServer[86]: CGXGetConnectionProperty: Invalid connection 42243
    Sep 21 12:41:38 Mac-mini.local coreservicesd[58]: SendFlattenedData, got error #268435460 (ipc/send) timed out from ::mach_msg(), sending notification kLSNotifyApplicationDeath to Sep 21 12:41:38 Mac-mini.local loginwindow[41]: DEAD_PROCESS: 41 console
    Sep 21 12:41:38 Mac-mini.local WindowServer[86]: CGXGetConnectionProperty: Invalid connection 42243
    Sep 21 12:41:38 Mac-mini.local coreservicesd[58]: SendFlattenedData, got error #268435459 (ipc/send) invalid destination port from ::mach_msg(), sending notification kLSNotifyApplicationDeath to notificationID=142
    Sep 21 12:41:38 Mac-mini.local shutdown[300]: halt by andrei:
    Boot & Working:
    Sep 21 12:42:11 localhost com.apple.launchd[1] (com.apple.automountd): Unknown key for boolean: NSSupportsSuddenTermination
    Sep 21 12:42:22 Mac-mini.local apsd[56]: CGSLookupServerRootPort: Failed to look up the port for "com.apple.windowserver.active" (1102)
    Sep 21 12:42:26 Mac-mini.local authorizationhost[121]: in od_principal_for_user(): failed: 7
    Sep 21 12:42:26 Mac-mini.local authorizationhost[121]: in pam_sm_authenticate(): Failed to determine Kerberos principal name.
    Sep 21 12:42:27 Mac-mini.local loginwindow[41]: ERROR | ScreensharingLoginNotification | Failed sending message to screen sharing GetScreensharingPort, err: 1102
    Sep 21 12:42:31 Mac-mini.local XProtectUpdater[24]: Ignoring new signature plist: Not an increase in version
    Sep 21 12:42:32 Mac-mini com.apple.launchd[1] (com.apple.xprotectupdater[24]): Exited with code: 252
    Sep 21 12:43:04 Mac-mini.local com.apple.security.pboxd[290]: Bug: 12C54: liblaunch.dylib + 23849 [2F71CAF8-6524-329E-AC56-C506658B4C0C]: 0x25
    Sep 21 12:53:49 Mac-mini.local CVMServer[98]: Check-in to the service com.apple.cvmsCompAgent_x86_64 failed. This is likely because you have either unloaded the job or the MachService has the ResetAtClose attribute specified in the launchd.plist. If present, this attribute should be removed.
    Sep 21 12:59:48 Mac-mini.local com.apple.security.pboxd[290]: kCGErrorFailure: CGSSetHideOnDeact: error getting window tags
    Sep 21 13:00:07 Mac-mini.local com.apple.security.pboxd[290]: _NXTermWindow: error releasing window (1000)
    Sep 21 13:00:07 Mac-mini.local com.apple.security.pboxd[290]: __block_global_2: connection failed unexpectedly; terminating process; delegate was (
    system.log - https://docs.google.com/open?id=0Bz5zKwys0GTcSzI5UFJRUzFxZjQ

    File a bug report with Apple.

  • [SOLVED] warning: directory permissions differ on var/log/wicd/

    Hi,
    I've seen several posts about this but I couldn't really figure out what's the appropriate action. Well, anyway I get the following error message when doing a pacman -Syu
    warning: directory permissions differ on var/log/wicd/
    filesystem: 1363 package: 755
    Is it a bug? Should I change the filepermission of the directory, and if so to what?
    Last edited by OMGitsUGOD (2009-09-18 10:38:32)

    This is sort of related,
    http://bbs.archlinux.org/viewtopic.php?pid=432588
    or at least thats the post at the end has the same file permisions as I have in /var/log/wicd.
    $ ls -la /var/log/ | grep wicd
    d-wxrw--wt 2 root root 4096 2009-08-27 07:58 wicd
    I'm pretty bad at this stuff, but isn't this rather 1361 than 1363, or am I totally wrong? And why not allow theowner to read the file?
    Last edited by OMGitsUGOD (2009-09-17 08:43:32)

  • GDM update: directory permissions differ on /var/log/gdm/

    Hello,
    Running Arch 64Bits kernel 3.9.9-1 with systemd and i got the following warning during a gdm update today:
    (1/6) upgrading libgdm [######################] 100%
    (2/6) upgrading gdm [######################] 100%
    warning: directory permissions differ on /var/log/gdm/
    filesystem: 711 package: 1770
    Why would gdm need some 1770 permissions for log files? Looks pretty suspicious to me, especially the sticky bit thing. What did i miss?
    PS: BTW the update is successful (it's a warning afterall, not an error)
    Thanks
    EDIT:
    Looks like the opposite situation than 3 years ago:
    https://bbs.archlinux.org/viewtopic.php?id=94681
    https://bugs.archlinux.org/task/19294
    EDIT2: here's what i have in /var/log:
    msytux666 var # ls -la
    total 64
    drwxr-xr-x 14 root root 4096 Jul 6 15:34 .
    drwxr-xr-x 20 root root 4096 Jul 16 20:24 ..
    -rwxrwxrwx 1 root root 4192 Jun 19 11:27 .com.zerog.registry.xml
    drwxr-xr-x 7 root root 4096 Jul 7 00:07 abs
    drwxr-xr-x 8 root root 4096 Jun 16 17:28 cache
    drwxr-xr-x 3 root root 4096 Jun 17 19:07 db
    drwxr-xr-x 2 root root 4096 May 31 20:40 empty
    drwxrwxr-x 2 root games 4096 May 31 20:40 games
    drwx--x--x 2 gdm gdm 4096 Jun 15 14:23 gdm
    drwxr-xr-x 26 root root 4096 Jul 16 01:13 lib
    drwxr-xr-x 2 root root 4096 May 31 20:40 local
    lrwxrwxrwx 1 root root 11 May 31 20:40 lock -> ../run/lock
    drwxr-xr-x 6 root root 4096 Jul 18 00:33 log
    lrwxrwxrwx 1 root root 10 May 31 20:40 mail -> spool/mail
    drwxr-xr-x 2 root root 4096 May 31 20:40 opt
    lrwxrwxrwx 1 root root 6 May 31 20:40 run -> ../run
    drwxr-xr-x 6 root root 4096 Jun 16 17:28 spool
    drwxrwxrwt 8 root root 4096 Jul 18 00:33 tmp
    gdm is owned by gdm, so why would it needs 1770 permissions?
    EDIT3:
    After further research i appear the way gdm is installed may matter.
    Well i installed gdm through pacman and always update it with pacman as well. Never manually compiled/make_install'd it nor used abs for it.
    Last edited by BGK (2013-07-19 21:37:13)

    Okay I'm confused ...
    Commit:https://projects.archlinux.org/svntogit … 92c38d536d
    @@ -68,8 +68,7 @@ package_gdm() {
    cd $pkgbase-$pkgver
    make DESTDIR="$pkgdir" install
    - chmod 1770 "$pkgdir/var/log/gdm"
    - chmod 700 "$pkgdir/var/lib/gdm/.config/dconf"
    + chmod 711 "$pkgdir/var/log/gdm"
    rm -r "$pkgdir/var/run" "$pkgdir/var/gdm"
    ### Split libgdm
    so that takes away the 1770 permissions, and replaces them with 711. 
    @@ -5,6 +5,7 @@ post_install() {
    getent passwd gdm > /dev/null 2>&1 || usr/sbin/useradd -c 'Gnome Display Manager' -u 120 -g gdm -d /var/lib/gdm -s /sbin/nologin gdm
    passwd -l gdm > /dev/null
    chown -R gdm:gdm /var/lib/gdm > /dev/null
    + chown root:gdm /var/log/gdm > /dev/null
    glib-compile-schemas /usr/share/glib-2.0/schemas
    gtk-update-icon-cache -q -t -f /usr/share/icons/hicolor
    however:
    chown root:gdm /var/log/gdm > /dev/null
    .. is where I get confused.  This command makes root and the group gdm the new owners of /var/log/gdm, or did I go wrong somewhere?

  • Errors in /var/log/alf.log?

    When I look in /var/log/alf.log all I see is entries like this:
    SecCodeCreateWithPID error:: No such process
    What does it mean?
    socketfilterfw shows up in the Activity Monitor, so it appears that Apple's application firewall is not completely dead. How would I best test whether it is functioning properly?
    Glenn

    1) lxdm is in /usr/sbin
    [dean@PsyMadness ~]$ which lxdm
    /usr/sbin/lxdm
    2) AFAIK lxdm does not use .xinitrc
    edit: Maybe you are trying to run /usr/bin/lxdm (which doesn't exist) in inittab and the correct one in DAEMONS in rc.conf
    Last edited by Terminator (2012-05-30 09:05:54)

  • 2 TB MyCloud filesystems "/tmp" and "/var/log" both at 100%

    Now, this is just plain weird...  here's the output from "df -k": Filesystem 1K-blocks Used Available Use% Mounted on
    rootfs 1968336 685956 1182392 37% /
    /dev/root 1968336 685956 1182392 37% /
    tmpfs 40960 20992 19968 52% /run
    tmpfs 40960 64 40896 1% /run/lock
    tmpfs 10240 0 10240 0% /dev
    tmpfs 5120 0 5120 0% /run/shm
    tmpfs 102400 102400 0 100% /tmp                                           <<<<<<<<<<<<<---------------
    /dev/root 1968336 685956 1182392 37% /var/log.hdd
    ramlog-tmpfs 20480 20480 0 100% /var/log                             <<<<<<<<<<<<<---------------
    /dev/sda4 1918220368 26235484 1853008884 2% /DataVolume
    /dev/sda4 1918220368 26235484 1853008884 2% /CacheVolume
    /dev/sda4 1918220368 26235484 1853008884 2% /nfs/TimeMachineBackup
    /dev/sda4 1918220368 26235484 1853008884 2% /nfs/Public
    /dev/sda4 1918220368 26235484 1853008884 2% /nfs/SmartWare (pls. excuse the formatting but you can see at the arrows that /var/log and /tmp are at 100%) "/tmp" is filling up with *hundreds* of files with the form -rw------- 1 www-data www-data 0 Jul 14 00:43 sess_pdh5c9g907vqvusb3mdsvtlum3
    -rw------- 1 www-data www-data 0 Jul 14 00:43 sess_2a7v2di677ra43sh76lonm3de1
    -rw------- 1 www-data www-data 0 Jul 14 00:43 sess_o6kh3i4iggg78evs53kp6enpf6
    -rw------- 1 www-data www-data 0 Jul 14 00:43 sess_o0ahso52sef3h0if3ifpo4dno3
    -rw------- 1 www-data www-data 0 Jul 14 00:43 sess_bvn1o9v4b4ldgoq9uvtn2n24i0-rw------- 1 www-data www-data 0 Jul 14 00:43 sess_h01fbr9o1pte3ud2s9ainth7b6 all similarly named "sess_[somethingorother] And "/var/log" is filling up due to file "/var/log/user.log", with gazillions of error messages of the form Jul 14 00:02:06 WDMyCloud REST_API[6751]: 192.168.1.101 ORION_LOG /var/www/rest-api/api/Auth/src/Auth/User/UserSecurity.php ISAUTHENTICATED [ERROR] dbgvar0: Array\n(\n [_] => 1436857244438\n [RequestScope] => RequestScope Object\n (\n )\n\n)\n and file "/var/log/apache2/error.log", that has more gazillions of error messages in it of the form [Tue Jul 14 00:07:25.715561 2015] [:error] [pid 7107] [client 192.168.1.101:3844] PHP Fatal error: Uncaught exception 'Zend\\Log\\Exception\\RuntimeException' with message 'No log writer specified' in /var/www/rest-api/lib/Zend/Log/Logger.php:245\nStack trace:\n#0 /var/www/rest-api/lib/Zend/Log/Logger.php(396): Zend\\Log\\Logger->log(4, 'Unknown: open(/...', Array)\n#1 [internal function]: Zend\\Log\\Logger::Zend\\Log\\{closure}(2, 'Unknown: open(/...', 'Unknown', 0, Array)\n#2 {main}\n thrown in /var/www/rest-api/lib/Zend/Log/Logger.php on line 245 ooookay... something has clearly gone bezoomny...  Anybody seen this?  before I go off on Yet AnotherMad Debian Bug Hunt?  

    Hey WD...  Y'all's got a BUG... When I access the MyClod from my laptop running XP with FireFox, I get the thousands of  "sess_*" files written to /tmp, and I get groups of messages of the form Jul 14 22:36:26 WDMyCloud REST_API[23951]: 192.168.1.101 ORION_LOG /var/www/rest-api/api/Auth/src/Auth/User/UserSecurity.php ISAUTHENTICATED [ERROR] Authentication failure for /api/2.1/rest/mediacrawler_status?_=1436938574613
    Jul 14 22:36:26 WDMyCloud REST_API[23951]: 192.168.1.101 ORION_LOG /var/www/rest-api/api/Auth/src/Auth/User/UserSecurity.php ISAUTHENTICATED [ERROR] dbgvar0: Array\n(\n [_] => 1436938574613\n [RequestScope] => RequestScope Object\n (\n )\n\n)\n
    Jul 14 22:36:26 WDMyCloud REST_API[23951]: 192.168.1.101 ORION_LOG /var/www/rest-api/api/Auth/src/Auth/User/UserSecurity.php ISAUTHENTICATED [ERROR] dbgvar0: Array\n(\n [_] => 1436938574613\n [RequestScope] => RequestScope Object\n (\n )\n\n)\n written to /var/log/user.log. But when I access it similarly from the desktop machine, also running XP with FireFox, I just get *one* of the "sess_*" whatever files written to /tmp, and just one set of messages of the form Jul 14 22:40:26 WDMyCloud REST_API[24325]: 192.168.1.100 OUTPUT DlnaServer\Controller\Database GET SUCCESS
    Jul 14 22:40:29 WDMyCloud REST_API[23952]: 192.168.1.100 OUTPUT System\Configuration\Controller\FactoryRestore GET SUCCESS
    Jul 14 22:40:29 WDMyCloud Zend\Log[23877]: 8192
    Jul 14 22:40:51 WDMyCloud REST_API[23952]: 192.168.1.100 OUTPUT Alerts\Controller\Alerts GET SUCCESS written to /var/log/user.log. So the MyClod is playing nice with some computers and not others... My guess is this could be happening more than WD knows about and could be producing all manner of mysterious behavior, since not only does it only happen on some machines but it does *not* crash the MyClod - at least not right away.  The main effect is to fill /tmp and /var/log with garbage so nothing can write to them, which will probably affect some things and not others... https://www.youtube.com/embed/2Gwnmb6P-3k  

  • Why does the directory ~/var/log keep appearing?

    It doesn't matter how many times I delete it, every few hours the blank directory ~/var/log gets created on my computer.
    I think it may have something to do with my Brother HL2170W printer, which is connected to my wifi network. But that's just from the fruitless googling on this topic I've already done.
    Does anyone know why a blank ~/var/log directory would persistently appear?
    Thank you in advance.

    ~var/log/ is a directory that holds log files. If it actually has a ~ in the name, some software is trying to write to the hidden directory, but has been miss-configured and is creating the directory you see instead of writing to /Users/username/var/log. ~/ is short for your home folder, but the program is actually writing that as part of the path name instead of being a path.

  • Cannot find /var/log/httpd/error_log

    I've searched on the forum about the "Personal Web Sharing" not starting up and just showing "Web Sharing starting up...". In most cases you have to look up the error_log at /var/log/httpd/error_log.
    In my case there is no such file. Terminal shows this:
    -bash: /var/log/httpd/error_log: No such file or directory
    This problem started when I tried to enable php in Apache. I changed the +AddModule mod_php4.c & LoadModule php4_module libexec/httpd/libphp4.so+ by deleting the # in front the lines.

    Hi Matt,
    Yes, it worked before I started trying activating PHP. It doesn't work when I recomment those lines either. There're no documents in /var/log/httpd folder. The http.conf file that I modified earlier were in /etc/httpd/. This is how it looks like now in http.conf
    +#LoadModule php4_module libexec/httpd/libphp4.so+
    +#AddModule mod_php4.c+
    +<IfModule mod_php4.c>+
    +# If php is turned on, we repsect .php and .phps files.+
    +AddType application/x-httpd-php .php+
    +AddType application/x-httpd-php-source .phps+
    +# Since most users will want index.php to work we+
    +# also automatically enable index.php+
    +<IfModule mod_dir.c>+
    +DirectoryIndex index.html index.php+
    </IfModule>
    Message was edited by: Saffari

  • Restoration of /var/log/secure.log from Time Machine Backup

    I have a need to restore /var/log/secure.log from Time Machine Backup on Lion Server, but can not find any entries for this file in the Time Machine archives even when using the find command.   It seems like it is not backed up.   I'm hoping that this is not the case; if it is it represents a pretty large mistake from a security perspective.
    Is there something that I'm missing?
    Thanks

    gracoat wrote:
    ...sigh...
    Try time machine and see what happens...  I dare ya!
    I've helped several folks here who were using TM on Snow Leopard Server quite successfully.  In most cases, as in most cases of trouble with backups on client Macs, they were having hardware problems.
    Granted this is a 10.6 server page, but they haven't updated open LDAP in a way that would change it's database functionality, nor have they changed the way time machine backs up and what it backs up.
    Nowhere there does Apple say that "Time Machine is NOT a suitable backup solution for a server" or anything like that.
    The article clarifies what it does, and does not, back up.   So it may or may not be a suitable backup solution depending on individual situations.

  • Enormous size of /var/log

    Hello, this is my first post in the forums, and im fairly new to archlinux. I couldn't login to gnome today, due to
    /etc/gdm/Xsession: Beginning session setup...
    /etc/gdm/Xsession: Setup done, will execute: /usr/bin/ssh-agent -- /usr/bin/gnome-session
    mkdtemp: private socket dir: No space left on device
    On investigating i found out that my /var directory had grown to an enourmous 14G. ls -l confirmed that my 'daemon.log' , 'errors.log' , and 'everything.log' were about 4G+ each.
    [root@rogue log]# ls -l --human-readable | grep G
    total 14G
    -rw-r----- 1 root log 4.5G 2008-08-23 00:35 daemon.log
    -rw-r----- 1 root log 4.5G 2008-08-23 00:35 errors.log
    -rw-r----- 1 root log 4.6G 2008-08-23 00:47 everything.log
    [root@rogue log]#cat daemon.log | tail
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    [root@rogue log]#cat error.log | tail
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    Aug 22 17:35:36 rogue famd[2999]: fd 4 message length 1347375956 bytes exceeds max of 4136.
    [root@rogue log]#cat everything.log | tail
    Aug 19 03:18:49 rogue IN=ppp0 OUT= MAC= SRC=88.114.160.100 DST=59.93.241.85 LEN=52 TOS=0x00 PREC=0x00 TTL=111 ID=15603 DF PROTO=TCP SPT=57958 DPT=51573 WINDOW=8192 RES=0x00 SYN URGP=0
    Aug 19 03:18:52 rogue IN=ppp0 OUT= MAC= SRC=88.114.160.100 DST=59.93.241.85 LEN=52 TOS=0x00 PREC=0x00 TTL=111 ID=15791 DF PROTO=TCP SPT=57958 DPT=51573 WINDOW=8192 RES=0x00 SYN URGP=0
    Aug 19 03:18:54 rogue IN=ppp0 OUT= MAC= SRC=85.228.81.112 DST=59.93.241.85 LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=7510 DF PROTO=TCP SPT=56084 DPT=51573 WINDOW=8192 RES=0x00 SYN URGP=0
    Aug 19 03:18:58 rogue IN=ppp0 OUT= MAC= SRC=83.103.213.123 DST=59.93.241.85 LEN=48 TOS=0x00 PREC=0x00 TTL=109 ID=2381 DF PROTO=TCP SPT=3966 DPT=13003 WINDOW=65535 RES=0x00 SYN URGP=0
    Aug 19 03:18:58 rogue IN=ppp0 OUT= MAC= SRC=88.114.160.100 DST=59.93.241.85 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=16131 DF PROTO=TCP SPT=57958 DPT=51573 WINDOW=8192 RES=0x00 SYN URGP=0
    Aug 19 03:19:00 rogue IN=ppp0 OUT= MAC= SRC=85.230.172.235 DST=59.93.241.85 LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=1442 DF PROTO=TCP SPT=63282 DPT=51573 WINDOW=8192 RES=0x00 SYN URGP=0
    Aug 19 03:19:01 rogue IN=ppp0 OUT= MAC= SRC=83.103.213.123 DST=59.93.241.85 LEN=48 TOS=0x00 PREC=0x00 TTL=109 ID=3011 DF PROTO=TCP SPT=3966 DPT=13003 WINDOW=65535 RES=0x00 SYN URGP=0
    Aug 19 03:19:03 rogue IN=ppp0 OUT= MAC= SRC=85.230.172.23^C TOS=0x00 PREC=0x00 TTL
    Aug 19 03:19:03 rogue IN=ppp0 OUT= MAC= SRC=85.230.172.23^C TOS=0x00 PREC=0x00 TTL
    Aug 19 03:19:03 rogue IN=ppp0 OUT= MAC= SRC=85.230.172.23^C TOS=0x00 PREC=0x00 TTL
    These logfiles are filled with repetations of nearly the same messages.
    Any help on how to fix this issue, or the cause of this is appreciated.
    Thanks a lot in advance
    ~Briareos
    PS: Here's my dmesg output
    [root@rogue log]#dmesg | tail
    IN=ppp0 OUT= MAC= SRC=212.200.214.195 DST=59.93.192.245 LEN=52 TOS=0x00 PREC=0x00 TTL=49 ID=12101 DF PROTO=TCP SPT=53443 DPT=28662 WINDOW=65535 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=49586 DF PROTO=TCP SPT=4185 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=50044 DF PROTO=TCP SPT=4185 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=50967 DF PROTO=TCP SPT=4185 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=52909 DF PROTO=TCP SPT=1710 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=53364 DF PROTO=TCP SPT=1710 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=219.87.66.26 DST=59.93.192.245 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=54288 DF PROTO=TCP SPT=1710 DPT=1080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=222.216.28.125 DST=59.93.192.245 LEN=40 TOS=0x00 PREC=0x00 TTL=101 ID=256 PROTO=TCP SPT=6000 DPT=8080 WINDOW=16384 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=212.200.214.195 DST=59.93.192.245 LEN=52 TOS=0x00 PREC=0x00 TTL=49 ID=18268 DF PROTO=TCP SPT=53598 DPT=28662 WINDOW=65535 RES=0x00 SYN URGP=0
    IN=ppp0 OUT= MAC= SRC=212.200.214.195 DST=59.93.192.245 LEN=52 TOS=0x00 PREC=0x00 TTL=49 ID=18766 DF PROTO=TCP SPT=53598 DPT=28662 WINDOW=65535 RES=0x00 SYN URGP=0
    Last edited by briareos90 (2008-08-22 20:04:51)

    yeah im currently using firestarter. Btw do i need to be running fam ? because a reply in the archlinux mail archive, regarding the same famd error, said that fam is no longer needed due to gnome-vfs. i quote from http://www.archlinux.org/pipermail/arch … 11443.html:
    On Sun, 2006-07-09 at 11:31 +0200, Firmicus at gmx.net wrote:
    >
    > Today after upgrading a bunch of packages I noticed
    > that /var/log/errors.log was rapidly filling up to a monstrous 105MB,
    > with the following message repeated zillions of time:
    >
    > > Jul  9 11:04:09 samarqand famd[3423]: fd 4 message length 1347375956
    > bytes exceeds max of 4136.
    >
    > I killed the two running famd processes (why two?) and cleaned the
    > errors.log file of those lines.
    >
    > Now what? Any idea about a posssible cause for this? NB: I run a gnome
    > desktop from the current repo.
    With gnome, you don't need to have fam running anymore, as gnomevfs uses
    inotify to monitor files. KDE should do the same AFAIK.

  • Upgrading to osx 10.6.8 fails. I see errors in the /var/log/install.log of "An unexpected error occurred while moving files to the final destination." Underlying Error=(Error Domain=NSPOSIXErrorDomain Code=5 "The operation couldn't be completed. Input/out

    upgrading to osx 10.6.8 fails. I see errors in the /var/log/install.log of "An unexpected error occurred while moving files to the final destination." Underlying Error=(Error Domain=NSPOSIXErrorDomain Code=5 "The operation couldn’t be completed. Input/out. Any thoughts on what is causing these errors and the upgrade failure?
    Thanks

    I have no idea what the specific error code means but input/output errors can sometimes mean a disk is failing. Make a couple of backups of all important data before doing anything else.
    Verify your startup disk using the First Aid tab in Disk Utility. If the disk needs repair boot from your Leopard DVD and repair your disk from Disk Utility under Utilities on the screen after you choose your language. Repeat the repair process until Disk Utility reports all is well.
    If Disk Utility doesn't find any errors you might want to try a new download of the update and keep a sharp eye on your HD for anything else that might indicate all is not well. Take special care to back up important data.
    If Disk Utility finds errors it would probably be a good idea to pay a visit to the Apple Store to have them check out your hard drive even if Disk Utility is able to repair the errors.

  • Weird entry in /var/log/auth.log

    Hello!
    Well, I was looking through my logs and came across this just now in /var/log/auth.log. I have no idea what this means, so in case it is something to worry about I figured I'd make a post.
    Does anyone know what this means? I couldn't find anything of use regarding this entry.
    May 25 20:11:23 myhost firefox: getaddrinfo*.gaih_getanswer: got type "DNAME"
    May 26 18:48:03 myhost firefox: getaddrinfo*.gaih_getanswer: got type "DNAME"
    May 26 18:48:03 myhost firefox: getaddrinfo*.gaih_getanswer: got type "DNAME"
    May 26 18:48:03 myhost firefox: getaddrinfo*.gaih_getanswer: got type "DNAME"
    Last edited by eyescream (2010-05-30 18:39:02)

    It looks like a bug in one of the JavaScripts that get loaded and run when you surf the forums. It's part of the Omniture SiteCatalyst web analytics product. Apple must use it to analyze traffic on this site.
    There's nothing you can do about it, it's nothing to worry about, and only Apple (or Omniture) can fix it.
    charlie

Maybe you are looking for

  • How to reduce memory use on my iMac

    How to reduce memory use on my iMac, OS X Yosemite, 2.7 GHz Intel Core i5 8 GB memory Running very slowly, and the little spinning ball showing up. How do I clean up my IMac please? Should I use MacKeep or any clean up apps?

  • Programmat​ically changing the TCP/IP address of Windows Vista / 7 / 8

    Hi there! I'm pretty new to LabVIEW (started 2 months ago) and still have a long way ahead of me, so please forgive me if anything that I ask is too basic. I'm trying to change the IP properties of the PC via LabVIEW for some bigger software I'm work

  • Error starting weblogic server on CC&B2.2.0

    I have installed CC&B 2.2 on RHEL 5. I am getting this error while starting weblogic server. All the EARs are deployed. ####<Nov 11, 2011 12:52:22 PM GMT+05:30> <Warning> <HTTP> <localhost.localdomain> <myserver> <[ACTIVE] ExecuteThread: '0' for queu

  • Cannot print pdf files

    operating system vista, printer: all-in-one photosmart 2575 i have tried (i think) everything, re-loaded my drivers, went through all possible settings, such as Hit PRINT, then hit ADVANCED, and then check the box that says PRINT AS IMAGE. nothing wo

  • How to erase TM?

    I need to erase TM but don't know how. It doesn't appear in Disk Utility. I installed a new 1.5TB internal HD and made it my startup disk. I had no problems cloning the old startup disk(500GB) to the new one and everything works fine. The only proble