expomeeting
New Pleskian
- Server operating system version
- Ubuntu 18.04.6 LTS
- Plesk version and microupdate number
- Plesk Obsidian v18.0.58_build1800240123.22 os_Ubuntu 18.04
Hello, I have this strange problem from several months now and I'm not able to solve it.
We occasionally see strange CPU behavior on this server.
This is the current situation, for example. For what I know, that should be a high I/O usage.
Sometimes it happens that the problem also triggers the crash of Apache (not this morning), when it happens all the hosted sites show a 504 gateway timeout. Most of the time stopping Apache causes the CPU to go back to normal and restarting Apache fixes the problem, so I'd say Apache is the suspect. But sometimes even restarting Apache, the CPU consumption quickly increased and Apache crashed again.
I can't figure out where the problem comes from, we have other servers configured the exact same way that never do anything similar. I don't see anything abnormal in the sites log, but it is hard to check them, the server hosts hundreds of domains.
A problem that I don't know if it can be related: a few months ago a WordPress site on this server was hacked, and it infected all the WordPress sites in the same subscription. The hack was to create and execute php files for spam, but it didn't work well because they also created htaccess files not working with my server configuration. They just took down the sites.
We cleaned up all these sites, and it never happened again. Maybe cleaning them up wasn't enough?
Another thing that seems related but I don't know how: this strange behavior always starts around midnight (in my local time). That's about the time for backups, scheduled for midnight. But maybe it's just a coincidence.
Can anyone give me an idea of what to look for?
Thank you
We occasionally see strange CPU behavior on this server.
This is the current situation, for example. For what I know, that should be a high I/O usage.
Sometimes it happens that the problem also triggers the crash of Apache (not this morning), when it happens all the hosted sites show a 504 gateway timeout. Most of the time stopping Apache causes the CPU to go back to normal and restarting Apache fixes the problem, so I'd say Apache is the suspect. But sometimes even restarting Apache, the CPU consumption quickly increased and Apache crashed again.
I can't figure out where the problem comes from, we have other servers configured the exact same way that never do anything similar. I don't see anything abnormal in the sites log, but it is hard to check them, the server hosts hundreds of domains.
A problem that I don't know if it can be related: a few months ago a WordPress site on this server was hacked, and it infected all the WordPress sites in the same subscription. The hack was to create and execute php files for spam, but it didn't work well because they also created htaccess files not working with my server configuration. They just took down the sites.
We cleaned up all these sites, and it never happened again. Maybe cleaning them up wasn't enough?
Another thing that seems related but I don't know how: this strange behavior always starts around midnight (in my local time). That's about the time for backups, scheduled for midnight. But maybe it's just a coincidence.
Can anyone give me an idea of what to look for?
Thank you