Daily Usenet report

Jul 17 03:00:06 -- Jul 18 03:00:05

Unknown entries from news log file:

First 50 / 95 lines (52.6%)

Jul 17 03:01:27 twilightnode innd: message repeated 2 times: [ ctlinnd command s]
Jul 17 06:03:37 twilightnode nnrpd[86547]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 06:03:37 twilightnode nnrpd[86547]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 06:03:37 twilightnode nnrpd[86547]: 69.5.169.232 res <anonymous>
Jul 17 06:03:37 twilightnode nnrpd[86547]: 69.5.169.232 no_match_user <anonymous> <localhost>
Jul 17 06:03:37 twilightnode nnrpd[86547]: 69.5.169.232 no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 06:03:37 twilightnode nnrpd[86547]: 69.5.169.232 match_user <anonymous> <anonymous>
Jul 17 06:03:37 twilightnode nnrpd[86547]: 69.5.169.232 no_post anonymous-read
Jul 17 06:03:47 twilightnode nnrpd[86548]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 06:03:47 twilightnode nnrpd[86548]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 06:03:47 twilightnode nnrpd[86548]: 188.240.59.60 res <anonymous>
Jul 17 06:03:47 twilightnode nnrpd[86548]: 188.240.59.60 no_match_user <anonymous> <localhost>
Jul 17 06:03:47 twilightnode nnrpd[86548]: 188.240.59.60 no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 06:03:47 twilightnode nnrpd[86548]: 188.240.59.60 match_user <anonymous> <anonymous>
Jul 17 06:03:47 twilightnode nnrpd[86548]: 188.240.59.60 no_post anonymous-read
Jul 17 07:08:06 twilightnode nnrpd[101084]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 07:08:06 twilightnode nnrpd[101084]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 07:08:06 twilightnode nnrpd[101084]: minsk.scan.bufferover.run res <anonymous>
Jul 17 07:08:06 twilightnode nnrpd[101084]: minsk.scan.bufferover.run no_match_user <anonymous> <localhost>
Jul 17 07:08:06 twilightnode nnrpd[101084]: minsk.scan.bufferover.run no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 07:08:06 twilightnode nnrpd[101084]: minsk.scan.bufferover.run match_user <anonymous> <anonymous>
Jul 17 07:08:06 twilightnode nnrpd[101084]: minsk.scan.bufferover.run no_post anonymous-read
Jul 17 07:08:06 twilightnode nnrpd[101085]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 07:08:06 twilightnode nnrpd[101085]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 07:08:06 twilightnode nnrpd[101085]: minsk.scan.bufferover.run res <anonymous>
Jul 17 07:08:06 twilightnode nnrpd[101085]: minsk.scan.bufferover.run no_match_user <anonymous> <localhost>
Jul 17 07:08:06 twilightnode nnrpd[101085]: minsk.scan.bufferover.run no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 07:08:06 twilightnode nnrpd[101085]: minsk.scan.bufferover.run match_user <anonymous> <anonymous>
Jul 17 07:08:06 twilightnode nnrpd[101085]: minsk.scan.bufferover.run no_post anonymous-read
Jul 17 10:53:03 twilightnode nnrpd[111184]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 10:53:03 twilightnode nnrpd[111184]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 10:53:03 twilightnode nnrpd[111184]: 80.94.92.12 res <anonymous>
Jul 17 10:53:03 twilightnode nnrpd[111184]: 80.94.92.12 no_match_user <anonymous> <localhost>
Jul 17 10:53:03 twilightnode nnrpd[111184]: 80.94.92.12 no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 10:53:03 twilightnode nnrpd[111184]: 80.94.92.12 match_user <anonymous> <anonymous>
Jul 17 10:53:03 twilightnode nnrpd[111184]: 80.94.92.12 no_post anonymous-read
Jul 17 14:31:14 twilightnode nnrpd[121047]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 14:31:14 twilightnode nnrpd[121047]: Auth strategy 'localhost' does not match client. Removing.
Jul 17 14:31:14 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com res <anonymous>
Jul 17 14:31:14 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_match_user <anonymous> <localhost>
Jul 17 14:31:14 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 14:31:14 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com match_user <anonymous> <anonymous>
Jul 17 14:31:14 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_post anonymous-read
Jul 17 14:31:15 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com res <anonymous>
Jul 17 14:31:15 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_match_user <anonymous> <localhost>
Jul 17 14:31:15 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_match_user <anonymous> *,!<anonymous>,!<localhost>
Jul 17 14:31:15 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com match_user <anonymous> <anonymous>
Jul 17 14:31:15 twilightnode nnrpd[121047]: 173.186.132.66.censys-scanner.com no_post anonymous-read
Jul 17 17:11:40 twilightnode nnrpd[128066]: Reading access from /usr/local/news/etc/readers.conf
Jul 17 17:11:40 twilightnode nnrpd[128066]: Auth strategy 'localhost' does not match client. Removing.

Log entries by program:

Program nameLines%LinesSize%Size
inn 6825 69.8%1.0 MB 70.6%
innd 1525 15.6%227.6 KB 15.7%
innfeed 1261 12.9%180.8 KB 12.4%
nnrpd 163 1.7%17.4 KB 1.2%
controlchan 8 0.1%1.2 KB 0.1%
TOTAL: 5 9782 100.0%1.4 MB100.0%

History cache:

ReasonCount%Count
Positive hits 15091 47.7%
Negative hits 9737 30.8%
Do not exist 6778 21.4%
Cache misses 2 0.0%
TOTAL: 4 31608 100.0%

innd timer:

Code regionTimePctInvokedMin(ms)Avg(ms)Max(ms)
article cancel00:00:00.004 0.0%2 2.000 2.000 2.000
article cleanup00:00:00.100 0.0%6792 0.000 0.015 0.111
article logging00:00:00.298 0.0%6808 0.000 0.044 0.154
article parse00:00:00.133 0.0%9299 0.000 0.014 0.167
article write00:00:05.354 0.0%4734 0.522 1.131 4.087
data move00:00:00.077 0.0%34719 0.000 0.002 0.032
hisgrep/artcncl00:00:00.001 0.0%2 0.000 0.500 1.000
history grep00:00:00.000 0.0%0 0.000 0.000 0.000
history lookup00:00:05.546 0.0%31667 0.099 0.175 1.144
history sync00:00:00.068 0.0%398 0.000 0.171 1.000
history write00:00:04.291 0.0%6792 0.278 0.632 2.500
idle23:50:17.248 99.9%33950 799.688 2527.754 8697.348
nntp read00:00:00.895 0.0%33620 0.000 0.027 0.094
overview write00:00:02.926 0.0%4734 0.185 0.618 2.182
perl filter00:00:14.328 0.0%6792 1.029 2.110 17.692
python filter00:00:01.286 0.0%6792 0.000 0.189 2.038
site send00:00:00.149 0.0%4727 0.000 0.032 0.143
TOTAL: 1723:50:52.704100.0%----

innfeed timer:

Code regionTimePctInvokedMin(ms)Avg(ms)Max(ms)
article new00:00:00.021 0.0%4921 0.000 0.004 0.111
article prepare00:00:00.000 0.0%12652 0.000 0.000 0.000
article read00:00:00.630 0.0%2405 0.000 0.262 2.600
backlog stats00:00:00.068 0.0%51657 0.000 0.001 0.013
callbacks00:00:00.000 0.0%0 0.000 0.000 0.000
data read00:00:00.482 0.0%27786 0.000 0.017 0.106
data write00:00:00.696 0.0%22939 0.000 0.030 0.076
idle23:50:20.324100.0%51657 385.522 1661.349 4966.793
status file00:00:00.194 0.0%244 0.000 0.795 22.000
TOTAL: 923:50:22.415100.0%----

nnrpd timer:

Code regionTimePctInvokedMin(ms)Avg(ms)Max(ms)
idle00:00:24.458100.0%23 44.000 1063.391 4438.000
newnews00:00:00.000 0.0%0 0.000 0.000 0.000
nntpwrite00:00:00.000 0.0%137 0.000 0.000 0.000
TOTAL: 300:00:24.458100.0%----

Control commands to innd:

CommandNumber
flush 2
flushlogs 2
go 2
logmode 2
lowmark 1
mode 146
name 2
pause 2
paused 2
reload 2
reserve 2
TOTAL: 11 165

Control channel:

SendernewgrouprmgroupOtherBad PGPDoItOK
news@hispagatos.org700007
TOTAL700007

Incoming feeds (innd):

ServerConnectsOfferedTakenRefusedReject%AccptElapsed
1twilightnode-out.news.weretis.net 3 11624 4360 5921 1343 37%51:08:03
2newsfeed.endofthelinebbs.com 1 5728 449 4499 780 7%27:13:17
3news.tebibyte.org 7 8325 118 8183 24 1%35:54:19
4news.sklaffkom.se 35 60 4 24 32 6%07:09:07
5localhost 25 0 0 0 0 0%00:00:00
TOTAL: 5 71 25737 4931 18627 2179 19%121:24:46
Articles received by server

Incoming volume (innd):

ServerAcceptVolDupVolRejVolTotalVol%AccVol/Art
1twilightnode-out.news.weretis.net12.4 MB0.0 KB3.9 MB16.2 MB 76%2.9 KB
2newsfeed.endofthelinebbs.com4.4 MB0.0 KB3.1 MB7.5 MB 58%6.3 KB
3news.tebibyte.org471.8 KB0.0 KB76.1 KB547.9 KB 86%3.9 KB
4news.sklaffkom.se7.2 KB0.0 KB73.0 KB80.3 KB 9%2.2 KB
5localhost0.0 KB0.0 KB0.0 KB0.0 KB 0%0
TOTAL: 517.2 MB0.0 KB7.2 MB24.4 MB 70%3.5 KB
Incoming volume received by server

Incoming articles (innd):

DateArticles%ArtsArt/secSize%SizeKB/sec
Jul 17 03:00:06 - 03:59:59 78 1.6% 0.02263.5 KB 1.5% 0.07
Jul 17 04:00:00 - 04:59:59 121 2.5% 0.03399.1 KB 2.3% 0.11
Jul 17 05:00:00 - 05:59:59 90 1.9% 0.03374.8 KB 2.2% 0.10
Jul 17 06:00:00 - 06:59:59 99 2.1% 0.03311.2 KB 1.8% 0.09
Jul 17 07:00:00 - 07:59:59 165 3.5% 0.05549.6 KB 3.2% 0.15
Jul 17 08:00:00 - 08:59:59 256 5.4% 0.071.2 MB 7.2% 0.34
Jul 17 09:00:00 - 09:59:59 236 5.0% 0.07706.9 KB 4.1% 0.20
Jul 17 10:00:00 - 10:59:59 221 4.7% 0.06727.8 KB 4.3% 0.20
Jul 17 11:00:00 - 11:59:59 225 4.7% 0.06747.0 KB 4.4% 0.21
Jul 17 12:00:00 - 12:59:59 253 5.3% 0.07863.0 KB 5.1% 0.24
Jul 17 13:00:00 - 13:59:59 223 4.7% 0.06623.9 KB 3.7% 0.17
Jul 17 14:00:00 - 14:59:59 229 4.8% 0.06684.2 KB 4.0% 0.19
Jul 17 15:00:00 - 15:59:59 292 6.1% 0.081.1 MB 6.8% 0.32
Jul 17 16:00:00 - 16:59:59 208 4.4% 0.06777.8 KB 4.6% 0.22
Jul 17 17:00:00 - 17:59:59 267 5.6% 0.071.0 MB 6.1% 0.29
Jul 17 18:00:00 - 18:59:59 215 4.5% 0.06739.4 KB 4.3% 0.21
Jul 17 19:00:00 - 19:59:59 219 4.6% 0.06632.5 KB 3.7% 0.18
Jul 17 20:00:00 - 20:59:59 217 4.6% 0.06820.9 KB 4.8% 0.23
Jul 17 21:00:00 - 21:59:59 251 5.3% 0.07860.6 KB 5.0% 0.24
Jul 17 22:00:00 - 22:59:59 223 4.7% 0.06873.9 KB 5.1% 0.24
Jul 17 23:00:00 - 23:59:59 197 4.1% 0.05645.5 KB 3.8% 0.18
Jul 18 00:00:00 - 00:59:59 171 3.6% 0.05586.6 KB 3.4% 0.16
Jul 18 01:00:00 - 01:59:59 153 3.2% 0.041018.6 KB 6.0% 0.28
Jul 18 02:00:00 - 02:59:59 130 2.7% 0.04429.5 KB 2.5% 0.12
Jul 18 03:00:00 - 03:00:05 10 0.2% 2.0010.1 KB 0.1% 2.03
TOTAL: 23:59:59 4749 100.0% 0.0516.7 MB 100.0% 0.20
Incoming articles
Incoming articles (size)

Sites sending bad articles:

ServerTotalGroupDistDuplicUnappTooOldSiteLineOther
1twilightnode-out.news.weretis.net 1299 1159 0 0 0 0 0 0 140
2newsfeed.endofthelinebbs.com 716 82 0 0 0 0 0 0 634
3news.sklaffkom.se 32 32 0 0 0 0 0 0 0
4news.tebibyte.org 29 25 0 0 0 0 0 0 4
TOTAL: 4 2076 1298 0 0 0 0 0 0 778

Unwanted newsgroups [Top 20]:

NewsgroupCount
de.etc.haushalt 105
pl.misc.samochody 44
alt.recovery.aa 41
pl.soc.prawo 38
alt.usage.english 37
alt.checkmate 36
lada.talk 34
uk.legal.moderated 32
de.soc.umwelt 28
hfx.general 24
alt.prophecies.nostradamus 23
pl.soc.polityka 23
uk.media.radio.archers 22
alt.slack 21
eternal-september.talk 21
it.sport.calcio.inter-fc 21
pl.pregierz 21
cn.comp 20
it.hobby.cucina 20
uk.net.news.moderation 19
TOTAL: 201 1298

Perl filter (innd) [Top 20]:

ReasonCount
EMP (md5) 625
EMP (phl) 86
User-issued cancel 47
HTML Multipart 2
Too many newsgroups 2
TOTAL: 5 762

Miscellaneous innd statistics [Top 10]:

EventServerNumber
Including strange strings
twilightnode-out.news.weretis.net 16
TOTAL: 1 16
TOTAL: 1 16

Outgoing feeds (innfeed) by articles:

ServerOfferedTakenRefusedRejectMissSpool%TookElapsed
1sklaffkom.se 5301 1030 2406 1299 0 2 19%23:59:55
2news.tebibyte.org 7050 830 3899 3 0 34 11%23:59:54
3newsfeed.endofthelinebbs.com 7835 7 4323 3 0 179 0%23:59:46
4weretis.net 500 0 498 0 0 0 0%21:20:06
TOTAL: 4 20686 1867 11126 1305 0 215 9%93:19:41
Outgoing feeds (innfeed) by articles

Outgoing feeds (innfeed) by volume:

ServerAcceptVolRejectVolTotalVolVolume/secVol/ArtElapsed
1news.tebibyte.org2.4 MB203.8 KB2.6 MB0.0 KB/s3.2 KB23:59:54
2sklaffkom.se1.6 MB7.3 MB8.9 MB0.1 KB/s3.9 KB23:59:55
3newsfeed.endofthelinebbs.com27.8 KB3.0 KB30.8 KB0.0 KB/s3.1 KB23:59:46
4weretis.net0.0 KB0.0 KB0.0 KB0.0 KB/s021:20:06
TOTAL: 44.0 MB7.5 MB11.5 MB0.0 KB/s3.7 KB93:19:41
Outgoing feeds (innfeed) by volume

NNRP readership statistics [Top 100]:

SystemConnArtsSizeGroupsPostRejElapsed
1210.172.132.66.censys-scanner.com 3 00.0 KB 0 0 000:00:04
2minsk.scan.bufferover.run 2 00.0 KB 0 0 000:00:00
3173.186.132.66.censys-scanner.com 1 00.0 KB 0 0 000:00:01
4188.240.59.60 1 00.0 KB 0 0 000:00:00
5207.211.203.35.bc.googleusercontent.com 1 00.0 KB 0 0 000:00:00
669.5.169.232 1 00.0 KB 0 0 000:00:00
780.94.92.12 1 00.0 KB 0 0 000:00:13
8keelanu.probe.onyphe.net 1 00.0 KB 0 0 000:00:03
9leblanc.probe.onyphe.net 1 00.0 KB 0 0 000:00:00
TOTAL: 9 12 00.0 KB 0 0 000:00:24

NNRP connection statistics (by domain) [Top 100]:

SystemConnArtsSizeGroupsPostRejElapsed
1*.66.censys-scanner.com 4 00.0 KB 0 0 000:00:05
2unresolved 3 00.0 KB 0 0 000:00:14
3*.probe.onyphe.net 2 00.0 KB 0 0 000:00:03
4*.scan.bufferover.run 2 00.0 KB 0 0 000:00:00
5*.bc.googleusercontent.com 1 00.0 KB 0 0 000:00:00
TOTAL: 5 12 00.0 KB 0 0 000:00:24

NNRP total resource statistics [Top 20]:

SystemUser(ms)System(ms)Idle(ms)Elapsed
80.94.92.12 0.008 0.010 0.00000:00:13
210.172.132.66.censys-scanner.com 0.037 0.029 0.00000:00:04
keelanu.probe.onyphe.net 0.007 0.003 0.00000:00:03
173.186.132.66.censys-scanner.com 0.029 0.015 0.00000:00:01
leblanc.probe.onyphe.net 0.005 0.009 0.00000:00:00
207.211.203.35.bc.googleusercontent.com 0.003 0.011 0.00000:00:00
69.5.169.232 0.005 0.013 0.00000:00:00
minsk.scan.bufferover.run 0.005 0.019 0.00000:00:00
188.240.59.60 0.004 0.005 0.00000:00:00
TOTAL: 9 0.103 0.114 0.00000:00:24

NNRP unrecognized commands (by host) [Top 20]:

SystemConn
minsk.scan.bufferover.run 9
207.211.203.35.bc.googleusercontent.com 4
leblanc.probe.onyphe.net 3
80.94.92.12 2
173.186.132.66.censys-scanner.com 1
210.172.132.66.censys-scanner.com 1
TOTAL: 6 20

NNRP unrecognized commands (by command) [Top 20]:

CommandCount
#001 3
#026#003#001#001 2
?#024 2
?$?(?#?' 2
EHLO www.censys.io 2
#026#003#001 1
#026#003#003#002c#001 1
?$?,?r?s?#023#002#023#001?#024?#007?#022?#023?'?/?#024?(?0?`?a... 1
?;?#005=?#?=.m?q#031 A?J+x?H?K?8?l... 1
Accept-Encoding: gzip 1
GET / HTTP/1.1 1
Host: 172.234.115.63:119 1
User-Agent: Hello from Palo Alto Network... 1
qv?3?5#013?v#034<? <k:#034?r*?k?#002#016?{#034?nj?$?=?... 1
TOTAL: 14 20

NNRP client timeouts [Top 20]:

SystemConnPeer
188.240.59.60 1 1
210.172.132.66.censys-scanner.com 1 2
80.94.92.12 1 1
TOTAL: 3 3 5