I'm running a server on Ubuntu 18.04 with Tomcat and I saw the following in the access log.
<my.ip> - - [13/Sep/2020:19:33:40 +0000] "POST /path/path HTTP/1.1" 200 53
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 82080
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 21
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 21
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 16
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 18
<my.ip> - - [13/Sep/2020:19:33:41 +0000] "POST /path/path HTTP/1.1" 200 262
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 174
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 140863
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 254
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 162
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "-" 400 -
<my.ip> - - [13/Sep/2020:19:33:42 +0000] "POST /path/path HTTP/1.1" 200 459
<my.ip> - - [13/Sep/2020:19:33:58 +0000] "POST /path/path HTTP/1.1" 200 53
<my.ip> - - [13/Sep/2020:19:33:58 +0000] "POST /path/path HTTP/1.1" 200 21
<my.ip> - - [13/Sep/2020:19:33:58 +0000] "POST /path/path HTTP/1.1" 200 82080
<my.ip> - - [13/Sep/2020:19:33:58 +0000] "POST /path/path HTTP/1.1" 200 21
<my.ip> - - [13/Sep/2020:19:33:58 +0000] "POST /path/path HTTP/1.1" 200 16
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 18
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 262
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 162
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 19
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 174
<my.ip> - - [13/Sep/2020:19:33:59 +0000] "POST /path/path HTTP/1.1" 200 459
<my.ip> - - [13/Sep/2020:19:34:00 +0000] "POST /path/path HTTP/1.1" 200 193
<my.ip> - - [13/Sep/2020:19:34:00 +0000] "POST /path/path HTTP/1.1" 200 254
<my.ip> - - [13/Sep/2020:19:34:00 +0000] "POST /path/path HTTP/1.1" 200 140863
As you can see, before and after the 400 response, everything is ok, it looks as if from time to time, for no apparent reason, it responses with 400 and the client receives it as "network error". There is no certain scenario for this to happen but it does happen several times a day (grep) to different IPs/users. Are there any other logs I can search, to find more info about this? Thanks
0 Answers