Ok, so I've got the logs on my webservers on lockdown (for the most part), but there's this one thing that's killing my log analysis (I use
awstats). A good 80% of the lines in my access logs are logged as coming from the IP of my server itself.
I assure you they're not coming from the server, because I can hit my site while simultaneously
tail -f'ing my access log, and I'm sitting halfway across town SSHd into the server (not sitting at the machine itself). Anyone seen this?
I suppose what's next is to set up a few virtual hosts and see if one of the many directives in this particular sites is causing it to be flaky.