I have been hitting a problem where it look like a SAV scheduled scan is kicked off and very quickly causes a Linux reboot. I can look in var/log/messages and see several messages in the log from Symantec and then the messages stop and that is followed up by messages that the Linux kernel is booting. Sometimes the system comes back up and other times it does not boot and we have to go through a recovery console. I can readily create this on one of our systems by simply kicking off a scheduled scan. We have other systems that don't seem to be effected. They are all running a similar version of Symantec. Has anyone seen a similar problem and does anyone have an idea of what causes this and a possible resolution. A snippet from /var/log/messages shows messages from SAV and then the kernel starts to boot.
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:04/power/runtime_usage [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:04/power/runtime_suspended_time [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:04/uevent [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:04/resources [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:04/options [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:05/id [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:05/tpm/tpm0/dev [00000003]
Aug 8 16:04:03 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:05/tpm/tpm0/ppi/request [00000003]
Aug 8 16:04:33 whcs-mi-es-4 log-courier: 2018/08/08 16:04:23.677512 Transport error, will try again: Server did not respond within network timeout
Aug 8 16:04:33 whcs-mi-es-4 audispd: node=whcs-mi-es-4.watson-health.net type=AVC msg=audit(1533762273.976:2056): avc: denied { open } for pid=1425 comm="collectd" path="/var/log/collectd.log" dev="sda3" ino=1074791467 scontext=system_u:system_r:collectd_t:s0 tcontext=system_u:object_r:var_log_t:s0 tclass=file
Aug 8 16:04:33 whcs-mi-es-4 audispd: node=whcs-mi-es-4.watson-health.net type=SYSCALL msg=audit(1533762273.976:2056): arch=c000003e syscall=2 success=yes exit=8 a0=562985488830 a1=441 a2=1b6 a3=24 items=0 ppid=1 pid=1425 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="collectd" exe="/usr/sbin/collectd" subj=system_u:system_r:collectd_t:s0 key=(null)
Aug 8 16:04:33 whcs-mi-es-4 audispd: node=whcs-mi-es-4.watson-health.net type=PROCTITLE msg=audit(1533762273.976:2056): proctitle="/usr/sbin/collectd"
Aug 8 16:04:33 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:05/tpm/tpm0/ppi/response [00000003]
Aug 8 16:04:33 whcs-mi-es-4 rtvscand: Scan could not open file /sys/devices/pnp0/00:05/tpm/tpm0/ppi/transition_action [00000003]
Aug 8 16:13:30 whcs-mi-es-4 kernel: Initializing cgroup subsys cpuset
Aug 8 16:13:30 whcs-mi-es-4 kernel: Initializing cgroup subsys cpu
Aug 8 16:13:30 whcs-mi-es-4 kernel: Initializing cgroup subsys cpuacct
Aug 8 16:13:30 whcs-mi-es-4 kernel: Linux version 3.10.0-862.el7.x86_64 (mockbuild@x86-034.build.eng.bos.redhat.com) (gcc version 4.8.5 20150623 (Red Hat 4.8.5-28) (GCC) ) #1 SMP Wed Mar 21 18:14:51 EDT 2018
Aug 8 16:13:30 whcs-mi-es-4 kernel: Command line: BOOT_IMAGE=/vmlinuz-3.10.0-862.el7.x86_64 root=UUID=22fc43e8-7157-4aab-a649-3d745a772e90 ro crashkernel=auto nomodeset biosdevname=0 net.ifnames=0 LANG=en_US.UTF-8
Aug 8 16:13:30 whcs-mi-es-4 kernel: e820: BIOS-provided physical RAM map:
Aug 8 16:13:30 whcs-mi-es-4 kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009bfff] usable
Aug 8 16:13:30 whcs-mi-es-4 kernel: BIOS-e820: [mem 0x000000000009c000-0x000000000009ffff] reserved
Aug 8 16:13:30 whcs-mi-es-4 kernel: BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
Aug 8 16:13:30 whcs-mi-es-4 kernel: BIOS-e820: [mem 0x0000000000100000-0x000000004bfaffff] usable