<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Troubleshooting on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/troubleshooting/</link><description>Recent content in Troubleshooting on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/troubleshooting/index.xml" rel="self" type="application/rss+xml"/><item><title>journalctl: Filtering and Formatting systemd Logs</title><link>https://lead-devops.blackdevhub.online/en/posts/journalctl-filtering-formatting/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/journalctl-filtering-formatting/</guid><description>&lt;p&gt;Logs disappeared. Server rebooted, and the familiar &lt;code&gt;less /var/log/syslog&lt;/code&gt; returns nothing. On modern distros with systemd, logs are collected by journald and read with &lt;code&gt;journalctl&lt;/code&gt;. Without knowing its filters, system debugging turns into guesswork.&lt;/p&gt;&#10;&lt;h2 id="why-logs-disappear-after-reboot"&gt;Why Logs Disappear After Reboot&#10;&lt;/h2&gt;&#10;&lt;p&gt;By default, journal stores data in &lt;code&gt;/run/log/journal/&lt;/code&gt; — a tmpfs that wipes on reboot. To make logs survive reboots, create the directory:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-eaf2b1d9-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="2"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-eaf2b1d9-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo mkdir -p /var/log/journal&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo systemd-tmpfiles --create --prefix /var/log/journal&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Then restart systemd-journald:&lt;/p&gt;</description></item><item><title>lsof: which processes listen on port and hold file</title><link>https://lead-devops.blackdevhub.online/en/posts/lsof-port-file-processes/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/lsof-port-file-processes/</guid><description>&lt;p&gt;Service won&amp;rsquo;t start — port 8080 is already bound. You dig into who&amp;rsquo;s holding it, and discover the same process has your config file open while you&amp;rsquo;re trying to edit it. lsof answers both questions: which processes opened which files and sockets.&lt;/p&gt;&#10;&lt;h2 id="listening-ports"&gt;Listening Ports&#10;&lt;/h2&gt;&#10;&lt;p&gt;The classic task — find who is listening on a specific port.&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-9cff1145-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-9cff1145-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;lsof -i -n -P&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;div class="td-table-scroll td-table-scroll--static"&gt;&#10;&lt;table&gt;&#10; &lt;thead&gt;&#10; &lt;tr&gt;&#10; &lt;th scope="col"&gt;Flag&lt;/th&gt;&#10; &lt;th scope="col"&gt;Effect&lt;/th&gt;&#10; &lt;/tr&gt;&#10; &lt;/thead&gt;&#10; &lt;tbody&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-i&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Show internet sockets&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-n&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Skip DNS resolution (show IP instead of hostname)&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-P&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Skip port-to-service conversion (show 80 instead of http)&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;/div&gt;&#10;&#10;&lt;p&gt;Without &lt;code&gt;-n -P&lt;/code&gt;, lsof wastes time on DNS lookups and resolves ports through /etc/services. On production hosts that&amp;rsquo;s unnecessary seconds.&lt;/p&gt;</description></item><item><title>ss: socket statistics instead of deprecated netstat</title><link>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</guid><description>&lt;p&gt;When &lt;code&gt;netstat&lt;/code&gt; hangs on a server with tens of thousands of connections, it&amp;rsquo;s time to switch to &lt;code&gt;ss&lt;/code&gt;. Part of the &lt;code&gt;iproute2&lt;/code&gt; package, &lt;code&gt;ss&lt;/code&gt; queries the kernel directly via netlink instead of parsing &lt;code&gt;/proc/net/*&lt;/code&gt;. The result is instant output with minimal overhead.&lt;/p&gt;&#10;&lt;h2 id="why-switch-from-netstat"&gt;Why switch from netstat&#10;&lt;/h2&gt;&#10;&lt;p&gt;&lt;code&gt;netstat&lt;/code&gt; from &lt;code&gt;net-tools&lt;/code&gt; relies on a deprecated approach: it reads from &lt;code&gt;/proc/net/tcp&lt;/code&gt;, &lt;code&gt;/proc/net/unix&lt;/code&gt; and converts numeric IDs to symbolic names. On a server with active connections, this takes seconds and spikes CPU usage.&lt;/p&gt;</description></item><item><title>strace: System Call Tracing for Diagnosing Hangs and Leaks</title><link>https://lead-devops.blackdevhub.online/en/posts/strace-syscall-troubleshooting/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/strace-syscall-troubleshooting/</guid><description>&lt;p&gt;When a service hangs, standard tools like top, htop, and ps show the state but not the cause. If a process is in state D (uninterruptible sleep), it&amp;rsquo;s waiting on a syscall. strace attaches to a live process and outputs every system call in real time. This turns a mysterious hang into a specific syscall, its arguments, and return code.&lt;/p&gt;&#10;&lt;div class="td-callout td-callout--note" role="note"&gt;&#10; &lt;div class="td-callout__title"&gt;&lt;i class="td-callout__icon fa-solid fa-circle-info" aria-hidden="true"&gt;&lt;/i&gt;&lt;span class="td-callout__label"&gt;Note&lt;/span&gt;&lt;/div&gt;&#10; &lt;div class="td-callout__body"&gt;&#10;&lt;p&gt;strace uses ptrace, the kernel&amp;rsquo;s debugging mechanism. On production, tracing slows a process by 2–10x. Use it sparingly, targeting a single PID.&lt;/p&gt;</description></item><item><title>SSH Escape Sequences: Reviving a Frozen Terminal</title><link>https://lead-devops.blackdevhub.online/en/posts/ssh-escape-sequences-frozen-terminal/</link><pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ssh-escape-sequences-frozen-terminal/</guid><description>&lt;p&gt;SSH session froze, &lt;code&gt;Ctrl+C&lt;/code&gt; does nothing, &lt;code&gt;Ctrl+D&lt;/code&gt; spits out garbage — familiar situation. Before closing the terminal and losing the session, try built-in escape sequences. They operate at the SSH client level before data reaches the remote host.&lt;/p&gt;&#10;&lt;h2 id="how-to-invoke-escape-sequences"&gt;How to invoke escape sequences&#10;&lt;/h2&gt;&#10;&lt;p&gt;The default escape character is tilde (&lt;code&gt;~&lt;/code&gt;). The combination works only at the beginning of a line. Press Enter, then &lt;code&gt;~&lt;/code&gt;, then the desired symbol. For example, &lt;code&gt;~.&lt;/code&gt; terminates the connection.&lt;/p&gt;</description></item></channel></rss>