We were discussing core files at the blackops meeting. To the best of my knowledge we have not had any core dumps cause a tripwire on our production servers running UMCE linux. I'd like to believe that nothing has ever crashed, but with wonderfully gnarly stuff like bind, sendmail, and openldap running I suspect that we have had a thing or two die since we first started deploying last summer (I also have strace output of our virus milter which shows threads segfaulting repeatedly). Of course, everything could be crashing and coring in negative directories and not causing tripwire. However, I know that slapd died on serpico.dir last week and find does not reveal a core file:

serpico-root# find . -name core

So... my question to you all is this: have you seen core files left over on your servers, and if so what left them behind? I'm wondering if we have some kind of systemic problem which is preventing them from being written out.

Please discuss.