Hello

How many Postfix servers?  Do you know that your clamd server is
capable of sustaining the load from the many Postfix servers?

now I have four postfix servers. The load on clamav servers is low... this is an instance:

top - 15:24:36 up 31 days, 19:17,  1 user,  load average: 0.14, 0.08, 0.02
Tasks: 116 total,   1 running, 115 sleeping,   0 stopped,   0 zombie
Cpu0  :  1.7%us,  1.0%sy,  0.0%ni, 97.0%id,  0.0%wa,  0.0%hi,  0.3%si,  0.0%st
Cpu1  : 15.0%us,  0.7%sy,  0.0%ni, 84.3%id,  0.0%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:   3925152k total,  2742588k used,  1182564k free,   203704k buffers
Swap:  2097144k total,    17964k used,  2079180k free,   713052k cached

  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND
10142 clamav    20   0 1453m 421m 2132 S 17.3 11.0 139:56.99 clamd
30560 clamav    20   0 1918m 889m  940 S  0.7 23.2  10:56.87 clamav-milter

procs -----------memory---------- ---swap-- -----io---- --system-- -----cpu----- r b swpd free buff cache si so bi bo in cs us sy id wa st 0 0 17964 1183096 203704 713056 0 0 4 12 6 1 2 0 98 0 0

  ClamdTOP version 0.98.1   Mon Mar 17 15:40:19 2014
NO CONNTIME LIV IDL QUEUE  MAXQ   MEM HOST           ENGINE DBVER DBTIME
1 00:00:04 18 17 0 0 356M local 0.98.1 18614 2014-03-17 14h
Details for Clamd version:  ClamAV 0.98.1/18614/Mon Mar 17 14:43:12 2014
Primary threads: live 18 idle 17 max 50 ????????????????????????????????????????? [||||||||||||| ] ?Mem: heap 10M mmap 0M unused 8M? Queue: 0 items 0 max ?Libc: used 0M free 9M total 10M? [ ] ?Pool: count 1 used 346M total 346M? ?[||||||||||||||||||||||||||||||||||| ] ? ?????????????????????????????????????????
 COMMAND        QUEUEDSINCE   FILE
 IDLE               3.800s
[...]

You could use syslog-ng, and tell it to send them to /dev/null. :)

I'll try with rsyslog ;)

You could try increasing the Postfix timeout (if that is in fact the
cause of the issue) but I wonder if you might need a more powerful
clamd server.  Scanning for viruses can be processor intensive.

I don't see log on Postfix correlated to these warning.
Just two or three error a day like this, really:

2014-03-17T12:47:34.538025+01:00 postfix2 postfix/smtpd[17215]: warning: milter inet:example.com:7357: can't read SMFIC_MAIL reply packet header: Connection reset by peer

Postfix milter timeout are:

milter_command_timeout = 30s
milter_connect_timeout = 30s
milter_content_timeout = 300s

that are greater than clamav timeout (I have a doubt on command_timeout...).

Thank you for all hints
Marco

_______________________________________________
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/support/ml

Reply via email to