'rsyslogd' Process High CPU Usage Problem

%3CLINGO-SUB%20id%3D%22lingo-sub-1996299%22%20slang%3D%22en-US%22%3E'rsyslogd'%20Process%20High%20CPU%20Usage%20Problem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1996299%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Guys%2C%3C%2FP%3E%3CP%3EWe%20have%20recently%20setup%20RSyslog%20(On%20Ubuntu%2018.04.4%20LTS%26nbsp%3B%20VM)%20receiving%20logs%20from%20our%20Firewalls%20and%20then%20forwarding%20to%20Azure%20Sentinel.%20The%20problem%20with%20Syslog%20is%20after%20a%20few%20hours%20the%20CPU%20start%20reaching%20max%20100%25%20and%20connections%20to%20each%20Firewall%20slowly%20change%20from%20ESTABLISHED%20changes%20to%20CLOSE%20and%20it%20ultimately%20stops%20receiving%20the%20logs.%20Below%20is%20the%20sample%20output%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22gsingh_microsoft_1-1608178736127.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F241246i28C236F65AB9AEFF%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22gsingh_microsoft_1-1608178736127.png%22%20alt%3D%22gsingh_microsoft_1-1608178736127.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20saw%20below%20recommendation%20searching%20on%20Google%26nbsp%3B%3C%2FP%3E%3CPRE%3Eservice%20rsyslog%20stop%0Ased%20-i%20-e%20's%2F%5E%5C%24ModLoad%20imklog%2F%23%5C%24ModLoad%20imklog%2Fg'%20%2Fetc%2Frsyslog.conf%0Aservice%20rsyslog%20start%3C%2FPRE%3E%3CP%3EWondering%20if%20any%20one%20know%20root%20cause%20and%20how%20to%20fix%20it%3F%20Just%20in%20case%20if%20we%20use%20above%20solution%20commands%20what%20exactly%20the%20second%20command%20'sed'%20will%20do%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi Guys,

We have recently setup RSyslog (On Ubuntu 18.04.4 LTS  VM) receiving logs from our Firewalls and then forwarding to Azure Sentinel. The problem with Syslog is after a few hours the CPU start reaching max 100% and connections to each Firewall slowly change from ESTABLISHED changes to CLOSE and it ultimately stops receiving the logs. Below is the sample output:

 

gsingh_microsoft_1-1608178736127.png

 

I saw below recommendation searching on Google 

service rsyslog stop
sed -i -e 's/^\$ModLoad imklog/#\$ModLoad imklog/g' /etc/rsyslog.conf
service rsyslog start

Wondering if any one know root cause and how to fix it? Just in case if we use above solution commands what exactly the second command 'sed' will do?

 

Thanks

 

0 Replies