Apologies, I was on holiday, did not make a note of how much the space was retained. After I cleared the the / partition was 89%, I just returned from holiday it is showing 96% my VPS provider is saying we cannot extended the hard drive without moving to a new server. The education head has given downtime only in December. How do I solve this without causing major disruption?
This is the result when I do a df
99G /var
95G /var/lib
2.5G /var/www
1.7G /var/cache
325M /var/log
1.2M /var/backups
64K /var/snap
36K /var/tmp
24K /var/spool
4.0K /var/opt
4.0K /var/mail
4.0K /var/local
Under the log files, checked with files consuming max space, in ascending order. What is this 'btmp', did a query on ChatGPT, is giving an output that 'btmp
file is a log file that records failed login attempts on your system'
root@localhost:/var/log# sudo find /var/log -type f -exec du -h {} + | sort -rh | head -n 10
107M /var/log/btmp
84M /var/log/btmp.1
14M /var/log/auth.log.1
9.2M /var/log/Acronis/APL/active-protection.log
'The btmp
file is a log file that records failed login attempts on your system. It's part of the /var/log
directory and can grow large if there are repeated failed login attempts, which might indicate malicious activity like a brute-force attack.'
I see a number of enteries with SSH and names I don't recognize
root@localhost:/var/log# sudo lastb
sts ssh:notty 120.48.152.250 Mon Nov 25 11:57 - 11:57 (00:00)
sts ssh:notty 120.48.152.250 Mon Nov 25 11:57 - 11:57 (00:00)
teacher ssh:notty 95.173.191.84 Mon Nov 25 11:56 - 11:56 (00:00)
teacher ssh:notty 95.173.191.84 Mon Nov 25 11:56 - 11:56 (00:00)
admin1 ssh:notty 120.48.152.250 Mon Nov 25 11:55 - 11:55 (00:00)
admin1 ssh:notty 120.48.152.250 Mon Nov 25 11:55 - 11:55 (00:00)
root ssh:notty 92.255.85.107 Mon Nov 25 11:54 - 11:54 (00:00)
burak ssh:notty 95.173.191.84 Mon Nov 25 11:54 - 11:54 (00:00)
burak ssh:notty 95.173.191.84 Mon Nov 25 11:54 - 11:54 (00:00)
admin ssh:notty 120.48.152.250 Mon Nov 25 11:53 - 11:53 (00:00)
admin ssh:notty 120.48.152.250 Mon Nov 25 11:53 - 11:53 (00:00)
proxyuse ssh:notty 120.48.152.250 Mon Nov 25 11:52 - 11:52 (00:00)
proxyuse ssh:notty 120.48.152.250 Mon Nov 25 11:52 - 11:52 (00:00)
root ssh:notty 157.10.253.39 Mon Nov 25 11:52 - 11:52 (00:00)
testadmi ssh:notty 95.173.191.84 Mon Nov 25 11:51 - 11:51 (00:00)
testadmi ssh:notty 95.173.191.84 Mon Nov 25 11:51 - 11:51 (00:00)
user01 ssh:notty 120.48.152.250 Mon Nov 25 11:50 - 11:50 (00:00)
user01 ssh:notty 120.48.152.250 Mon Nov 25 11:50 - 11:50 (00:00)
root ssh:notty 157.10.253.39 Mon Nov 25 11:50 - 11:50 (00:00)
teamspea ssh:notty 95.173.191.84 Mon Nov 25 11:49 - 11:49 (00:00)
teamspea ssh:notty 95.173.191.84 Mon Nov 25 11:49 - 11:49 (00:00)
guest ssh:notty 54.38.190.246 Mon Nov 25 11:49 - 11:49 (00:00)
guest ssh:notty 54.38.190.246 Mon Nov 25 11:49 - 11:49 (00:00)
admin ssh:notty 92.255.57.132 Mon Nov 25 11:49 - 11:49 (00:00)
admin ssh:notty 92.255.57.132 Mon Nov 25 11:49 - 11:49 (00:00)
frappe ssh:notty 95.161.220.54 Mon Nov 25 11:49 - 11:49 (00:00)
frappe ssh:notty 95.161.220.54 Mon Nov 25 11:49 - 11:49 (00:00)
root ssh:notty 89.107.10.66 Mon Nov 25 11:49 - 11:49 (00:00)
root ssh:notty 92.255.85.253 Mon Nov 25 11:49 - 11:49 (00:00)
burak ssh:notty 34.142.110.144 Mon Nov 25 11:48 - 11:48 (00:00)
burak ssh:notty 34.142.110.144 Mon Nov 25 11:48 - 11:48 (00:00)
ubuntu ssh:notty 120.48.152.250 Mon Nov 25 11:48 - 11:48 (00:00)
ubuntu ssh:notty 120.48.152.250 Mon Nov 25 11:48 - 11:48 (00:00)
steam ssh:notty 54.38.190.246 Mon Nov 25 11:48 - 11:48 (00:00)
steam ssh:notty 54.38.190.246 Mon Nov 25 11:48 - 11:48 (00:00)
root ssh:notty 157.10.253.39 Mon Nov 25 11:48 - 11:48 (00:00)
root ssh:notty 80.94.95.81 Mon Nov 25 11:48 - 11:48 (00:00)
user ssh:notty 95.161.220.54 Mon Nov 25 11:48 - 11:48 (00:00)
root ssh:notty 80.94.95.81 Mon Nov 25 11:48 - 11:48 (00:00)
user ssh:notty 95.161.220.54 Mon Nov 25 11:48 - 11:48 (00:00)
root ssh:notty 80.94.95.81 Mon Nov 25 11:48 - 11:48 (00:00)
root ssh:notty 80.94.95.81 Mon Nov 25 11:47 - 11:47 (00:00)
root ssh:notty 80.94.95.81 Mon Nov 25 11:47 - 11:47 (00:00)
fa ssh:notty 95.173.191.84 Mon Nov 25 11:47 - 11:47 (00:00)
fa ssh:notty 95.173.191.84 Mon Nov 25 11:47 - 11:47 (00:00)
burak ssh:notty 188.132.232.122 Mon Nov 25 11:47 - 11:47 (00:00)
burak ssh:notty 188.132.232.122 Mon Nov 25 11:47 - 11:47 (00:00)
da ssh:notty 34.142.110.144 Mon Nov 25 11:47 - 11:47 (00:00)
da ssh:notty 34.142.110.144 Mon Nov 25 11:47 - 11:47 (00:00)
joao ssh:notty 95.85.47.10 Mon Nov 25 11:47 - 11:47 (00:00)
joao ssh:notty 95.85.47.10 Mon Nov 25 11:46 - 11:46 (00:00)
sysadmin ssh:notty 54.38.190.246 Mon Nov 25 11:46 - 11:46 (00:00)
sysadmin ssh:notty 54.38.190.246 Mon Nov 25 11:46 - 11:46 (00:00)
mbot ssh:notty 95.161.220.54 Mon Nov 25 11:46 - 11:46 (00:00)
mbot ssh:notty 95.161.220.54 Mon Nov 25 11:46 - 11:46 (00:00)
ubuntu ssh:notty 120.48.152.250 Mon Nov 25 11:46 - 11:46 (00:00)
ubuntu ssh:notty 120.48.152.250 Mon Nov 25 11:46 - 11:46 (00:00)
root ssh:notty 157.10.253.39 Mon Nov 25 11:46 - 11:46 (00:00)
fa ssh:notty 188.132.232.122 Mon Nov 25 11:46 - 11:46 (00:00)
fa ssh:notty 188.132.232.122 Mon Nov 25 11:46 - 11:46 (00:00)
joao ssh:notty 34.142.110.144 Mon Nov 25 11:46 - 11:46 (00:00)
joao ssh:notty 34.142.110.144 Mon Nov 25 11:46 - 11:46 (00:00)
oracle ssh:notty 54.38.190.246 Mon Nov 25 11:45 - 11:45 (00:00)
teacher ssh:notty 95.85.47.10 Mon Nov 25 11:45 - 11:45 (00:00)
user ssh:notty 95.161.220.54 Mon Nov 25 11:45 - 11:45 (00:00)
oracle ssh:notty 54.38.190.246 Mon Nov 25 11:45 - 11:45 (00:00)
user ssh:notty 95.161.220.54 Mon Nov 25 11:45 - 11:45 (00:00)
teacher ssh:notty 95.85.47.10 Mon Nov 25 11:45 - 11:45 (00:00)
caja ssh:notty 95.173.191.84 Mon Nov 25 11:45 - 11:45 (00:00)
caja ssh:notty 95.173.191.84 Mon Nov 25 11:45 - 11:45 (00:00)
user ssh:notty 120.48.152.250 Mon Nov 25 11:45 - 11:45 (00:00)
user ssh:notty 120.48.152.250 Mon Nov 25 11:45 - 11:45 (00:00)
teacher ssh:notty 188.132.232.122 Mon Nov 25 11:44 - 11:44 (00:00)
teacher ssh:notty 188.132.232.122 Mon Nov 25 11:44 - 11:44 (00:00)
eagle ssh:notty 34.142.110.144 Mon Nov 25 11:44 - 11:44 (00:00)
eagle ssh:notty 34.142.110.144 Mon Nov 25 11:44 - 11:44 (00:00)
oracle ssh:notty 95.161.220.54 Mon Nov 25 11:44 - 11:44 (00:00)