Topic: troubleshooting
-
Triaging a full Linux disk: df, du, deleted-but-open files and the journal
A full filesystem can be full on space or on inodes, and space held by a deleted-but-still-open file will not show up in du. This methodology walks the checks in order — df -h, df -i, du -x, lsof +L1, and journald vacuuming — before anything is deleted.
-
Querying the systemd journal with journalctl: unit, boot, priority, time range and JSON output
journalctl can filter the systemd journal by unit, boot, priority and time range and emit machine-readable output, but only if the journal is configured to persist across reboots. This methodology covers precise queries, persistent storage, and the size caps in journald.conf.
-
Troubleshooting Group Policy application: gpresult, gpupdate, and the GroupPolicy module
Reading what policy actually applied to a computer or user with gpresult /h and Get-GPResultantSetOfPolicy, forcing reprocessing with gpupdate /force, and backing up a GPO with Backup-GPO before editing it.
-
Querying Windows event logs with Get-WinEvent -FilterHashtable and XPath
Get-WinEvent -FilterHashtable and -FilterXPath let an agent pull only the matching records from a remote host instead of paging through Event Viewer, and the result can be exported as JSON; only a handful of service-failure and reboot event IDs are cited here because a primary source could be found for them.
-
Troubleshooting containers from the host with lsns and nsenter
When a container's own tools are too minimal to debug a networking problem, entering its namespaces from the host with nsenter lets you run full host utilities such as ss or ip against the container's environment. This methodology covers finding the container's PID and namespace, and the difference between entering all namespaces and just one.
-
Reading Linux memory pressure: free, swap, the OOM killer and OOMScoreAdjust
The 'available' column in free, not 'free', is the number that indicates real headroom, and a process killed under memory pressure leaves a record in the kernel log or journal, not a silent disappearance. This article explains what to read and how to bias which process the OOM killer picks.
Machine-readable: JSON