Showing posts with label log. Show all posts
Showing posts with label log. Show all posts

Searching log for shutdown/reboot on Linux

To address problem, sometimes, we need to find log to know machine's shutdown/reboot time. However, how to do it?
last command
We use command, man last, to view the illustration(link). It lists login account, but reboot the machines use a pseudo account. Hence, we use the command, last reboot , to show the reboot time. For an instance, it shows last reboot time at 5/12 13:04.
[root@centos-6 ~]# last reboot
reboot   system boot  2.6.32-431.el6.x Thu May 12 13:04 - 12:29 (3+23:25)   
reboot   system boot  2.6.32-431.el6.x Mon May  9 09:55 - 13:01 (3+03:05)   
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 18:20 - 09:52 (24+15:31)  
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 15:00 - 18:19  (03:19)    
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 14:42 - 14:59  (00:16)    
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 14:31 - 14:42  (00:10)    
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 14:27 - 14:30  (00:03)    
reboot   system boot  2.6.32-431.el6.x Thu Apr 14 14:20 - 14:26  (00:05)     
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 14:12 - 14:28  (00:15)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 13:47 - 14:11  (00:24)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 13:35 - 13:46  (00:10)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 11:50 - 13:35  (01:45)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 11:18 - 11:49  (00:31)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 11:10 - 11:18  (00:07)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 10:48 - 11:10  (00:21)    
reboot   system boot  2.6.32-431.el6.x Tue Jan 26 10:10 - 10:48  (00:37)    

wtmp begins Tue Jan 26 09:57:17 2016

Then if you want to list logs of shutdown. Using the command, last -x shutdown, which is follows.
[root@centos-6 ~]# last -x shutdown
shutdown system down  2.6.32-431.el6.x Thu May 12 13:01 - 13:04  (00:02)    
shutdown system down  2.6.32-431.el6.x Mon May  9 09:52 - 09:55  (00:03)    
shutdown system down  2.6.32-431.el6.x Thu Apr 14 18:19 - 18:20  (00:00)    
shutdown system down  2.6.32-431.el6.x Thu Apr 14 14:59 - 15:00  (00:00)    
shutdown system down  2.6.32-431.el6.x Thu Apr 14 14:42 - 14:42  (00:00)    
shutdown system down  2.6.32-431.el6.x Thu Apr 14 14:31 - 14:31  (00:00)    
shutdown system down  2.6.32-431.el6.x Thu Apr 14 14:26 - 14:27  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 13:46 - 13:47  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 13:35 - 13:35  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 11:49 - 11:50  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 11:18 - 11:18  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 11:10 - 11:10  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 10:48 - 10:48  (00:00)    
shutdown system down  2.6.32-431.el6.x Tue Jan 26 10:09 - 10:10  (00:00) 

wtmp begins Tue Jan 26 09:57:17 2016

How to make a schedule to clean logs on Linux ?

In the software developing, we may make a lot of logs and stored on our developed systems. However, logs will increase by the time. To address increasable logs, we should make a schedule to clean it. In Linux system, we have a simple way to do it. This article will introduce two commands which are installed on Linux. First is crontab, that is a command which service for you to make a schedule to do something. Second, tmpwatch is a command which cleans tmp directory. This article illustrates how to use those two commands to achieve our work.

crontab
This command makes the work cycle to do it. The cycler time use minute, hour, week, month, and year. You can use crontab command to archive your work, and also edit /etc/crontab to do it. To security issues, /etc/cron.allow use to allow who can use this command. Vice versa, /etc/cron.deny use to deny who cannot use it.

The crontab content
[nick1811@centos-6 ~]$ cat /etc/crontab
SHELL=/bin/bash
PATH=/sbin:/bin:/usr/sbin:/usr/bin
MAILTO=root
HOME=/

# For details see man 4 crontabs

# Example of job definition:
# .---------------- minute (0 - 59)
# |  .------------- hour (0 - 23)
# |  |  .---------- day of month (1 - 31)
# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...
# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# |  |  |  |  |
# *  *  *  *  * user-name command to be executed



tmpwatch
Temporary files are almost placed in /tmp directory, and be deleted by the system. To assurance the /tmp directory is not full, the system automatically cleans it in each day. This because the system makes a schedule to execute tmpwatch to do it. This package is not installed in minimum installation.

Using yum to install package:
[root@centos-6 ~]# yum install tmpwatch.x86_64

After installing, the tmpwatch file will be placed on this location( /etc/cron.daily). We can use cat to view it. All files in the /tmp will be deleted when it be not accessed in 30 days. This file shows the system recursively detects /tmp directory and deletes files.
[nick1811@centos-6 ~]$ cat /etc/cron.daily/tmpwatch 
#! /bin/sh
flags=-umc
/usr/sbin/tmpwatch "$flags" -x /tmp/.X11-unix -x /tmp/.XIM-unix \
 -x /tmp/.font-unix -x /tmp/.ICE-unix -x /tmp/.Test-unix \
 -X '/tmp/hsperfdata_*' 10d /tmp
/usr/sbin/tmpwatch "$flags" 30d /var/tmp
for d in /var/{cache/man,catman}/{cat?,X11R6/cat?,local/cat?}; do
    if [ -d "$d" ]; then
 /usr/sbin/tmpwatch "$flags" -f 30d "$d"
    fi
done



How to make a schedule to clean logs?
Now, we can make our schedule to clean logs. For an instance, we clean a directory at 1:30 in every day, and delete files which be not accessed in a month.
[nick1811@centos-6 ~]$ crontab -e
# Example of job definition:
# .---------------- minute (0 - 59)
# |  .------------- hour (0 - 23)
# |  |  .---------- day of month (1 - 31)
# |  |  |  .------- month (1 - 12) OR jan,feb,mar,apr ...
# |  |  |  |  .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# |  |  |  |  |
# *  *  *  *  * user-name  command to be executed
 30  1  *  *  * /usr/sbin/tmpwatch -maf 30d /home/nick1811/logs