does it normal?

evgeni22 nginx-forum at
Thu Jul 30 20:11:52 UTC 2015

nginx version: nginx/1.8.0
built by gcc 4.8.3 20140911 (Red Hat 4.8.3-9) (GCC)
built with OpenSSL 1.0.1e-fips 11 Feb 2013
TLS SNI support enabled
configure arguments:
--add-module=../modsecurity_nginx-2.8.0/nginx/modsecurity --user=nginx
--group=nginx --prefix=/usr --sbin-path=/usr/sbin
--conf-path=/etc/nginx/nginx.conf --pid-path=/var/run/
--error-log-path=/var/log/nginx/error_log --with-ipv6
--without-mail_imap_module --without-mail_smtp_module --with-http_ssl_module
--with-http_realip_module --with-http_stub_status_module
--with-http_gzip_static_module --with-http_dav_module --with-cc-opt=''-D

CentOS Linux release 7.1.1503

2015/07/30 09:34:28 [notice] 12683#0: ModSecurity for nginx (STABLE)/2.8.0
( configured.
2015/07/30 09:34:28 [notice] 12683#0: ModSecurity: APR compiled
version="1.5.1"; loaded version="1.5.1"
2015/07/30 09:34:28 [notice] 12683#0: ModSecurity: PCRE compiled
version="8.20 "; loaded version="8.20 2011-10-21"
2015/07/30 09:34:28 [notice] 12683#0: ModSecurity: LIBXML compiled
2015/07/30 09:34:28 [notice] 12683#0: Original server signature: ModSecurity
2015/07/30 09:34:28 [notice] 12683#0: Status engine is currently disabled,
enable it by set SecStatusEngine to On.

other errors from time to time:
kernel: grsec: From  x.x.x.x: Segmentation fault occurred at 
00000000000000e0 in /usr/sbin/nginx[nginx:8031]  uid/euid:993/993


at the moment:
 - Memory used.........:  13761 MB / 32067 MB
 - Swap in use.........:  2333 MB

service nginx reload =  it doubles the ram usage.
over a few days it use all 32gb of ram, and start with swap.

#user  nginx;

# The number of worker processes is changed automatically by CustomBuild,
according to the number of CPU cores, if it's set to "1"
worker_processes  4;
pid /var/run/;
error_log  /var/logs//nginx/error.log;

#error_log  logs/error.log  notice;
#error_log  logs/error.log  info;

events {
    include /etc/nginx/nginx-events.conf;

http {
    include       /etc/nginx/mime.types;

#    access_log  /var/log/nginx/access.log  main;

    # For user configurations not maintained by DirectAdmin. Empty by
    include /etc/nginx/nginx-includes.conf;

    # Supplemental configuration
    include /etc/nginx/nginx-modsecurity-enable.conf;
    include /etc/nginx/nginx-defaults.conf;
    include /etc/nginx/nginx-gzip.conf;
    include /etc/nginx/directadmin-ips.conf;
    include /etc/nginx/directadmin-settings.conf;
    include /etc/nginx/nginx-vhosts.conf;
    include /etc/nginx/directadmin-vhosts.conf;

Average total traffic out from server is 41.1 kb/s.
on 12 vhosts/domains.

So what do i start with to find the problem?

