从 /var/log/message 我们看到以下内容
Jan 08 06:01:01 kafka1 systemd: Started Session 37735 of user root.
Jan 08 06:01:01 kafka1 systemd: Starting Session 37735 of user root.
如何知道它是哪个服务?
从日志中我们可以看到服务每隔一分钟重新启动一次
答案1
每次用户登录时,这些消息都会自动创建;如果您想删除它们,您可以在 Red Hat 支持页面中查看如何操作:
https://access.redhat.com/solutions/1564823
即:
要抑制 /var/log/messages 中的这些日志条目,请使用 rsyslog 创建丢弃过滤器,例如,运行以下命令:
echo 'if $programname == "systemd" and ($msg contains "Starting Session" or $msg contains "Started Session" or $msg contains "Created slice" or $msg contains "Starting user-" or $msg contains "Starting User Slice of" or $msg contains "Removed session" or $msg contains "Removed slice User Slice of" or $msg contains "Stopping User Slice of") then stop' >/etc/rsyslog.d/ignore-systemd-session-slice.conf
然后重启rsyslog服务:
systemctl restart rsyslog