We've been suffering from the [129:20:1] stream5: TCP session without 3-way handshake events smashing Sguil. We have since ran the sudo sguil-db-purge so eventually managed to get Sguil back up and running. We then ran soup to get the latest updates but since updating we have been battling to get logstash started.
Logstash stays on "Logstash has started, but is still initializing" for around 10 minutes before the whole server gets stuck and only a reboot gets it started up again. At the moment I am only able to troubleshoot by stopping the logstash service.
I noticed that in the sostat-redacted it says Error: No such container: so-logstash and when I locate logstash.yml it comes up in 3 different directories, which I don't believe is correct, but not sure how to go about resolving it.
Any ideas on how I can get logstash back up and running or how to resolve what I believe to be a corrupted logstash container?
Thanks for the help.
sostat-redacted
ERROR 130 (HY000) at line 1: Incorrect file format 'event_ha148-ids-01-ens224-1_20190904'
ERROR 130 (HY000) at line 1: Incorrect file format 'event_ha148-ids-01-ens224-1_20190904'
ERROR 130 (HY000) at line 1: Incorrect file format 'event_ha148-ids-01-ens224-1_20190904'
ERROR 130 (HY000) at line 1: Incorrect file format 'event_ha148-ids-01-ens224-1_20190904'
ERROR 130 (HY000) at line 1: Incorrect file format 'event_ha148-ids-01-ens224-1_20190904'
Error: No such container: so-logstash
=========================================================================
Service Status
=========================================================================
Status: securityonion
* SO-user server[ OK ]
Status: HIDS
* ossec_agent (SO-user)[ OK ]
Status: Elastic stack
* so-elasticsearch OK ]
* so-logstash FAIL ]
* so-kibana FAIL ]
* so-domainstats OK ]
* so-curator OK ]
* so-elastalert OK ]
=========================================================================
Interface Status
=========================================================================
br-df93399bedb3 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4 errors:0 dropped:0 overruns:0 frame:0
TX packets:25 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:112 (112.0 B) TX bytes:1830 (1.8 KB)
docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:7215 errors:0 dropped:0 overruns:0 frame:0
TX packets:16214 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:1161872 (1.1 MB) TX bytes:79168334 (79.1 MB)
ens160 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4194775 errors:0 dropped:0 overruns:0 frame:0
TX packets:3682041 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:665671849 (665.6 MB) TX bytes:
9848548720 (9.8 GB)
lo Link encap:Local Loopback
inet addr:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:88239 errors:0 dropped:0 overruns:0 frame:0
TX packets:88239 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:418900646 (418.9 MB) TX bytes:418900646 (418.9 MB)
so-curator
-------------------------------------------------------------------------
(eth0)
veth18b5695 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:36 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:2632 (2.6 KB)
(eth1)
veth78b8098 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:14809 errors:0 dropped:0 overruns:0 frame:0
TX packets:15633 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:1597626 (1.5 MB) TX bytes:203101908 (203.1 MB)
so-elastalert
-------------------------------------------------------------------------
(eth0)
vethcf21480 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:6 errors:0 dropped:0 overruns:0 frame:0
TX packets:43 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:404 (404.0 B) TX bytes:3374 (3.3 KB)
(eth1)
vethf698c6c Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:7105 errors:0 dropped:0 overruns:0 frame:0
TX packets:5064 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:1912796 (1.9 MB) TX bytes:1464035 (1.4 MB)
so-elasticsearch
-------------------------------------------------------------------------
(eth0)
vetha1ca03b Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:31 errors:0 dropped:0 overruns:0 frame:0
TX packets:77 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:2428 (2.4 KB) TX bytes:5571 (5.5 KB)
(eth1)
vethb42341d Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:20950 errors:0 dropped:0 overruns:0 frame:0
TX packets:22357 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:206068303 (206.0 MB) TX bytes:3774751 (3.7 MB)
so-domainstats
-------------------------------------------------------------------------
(eth0)
veth349e149 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:50 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:3596 (3.5 KB)
(eth1)
veth3d86df7 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:53 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:3722 (3.7 KB)
=========================================================================
Link Statistics
=========================================================================
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
418901346 88253 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
418901346 88253 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 0
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
665687787 4194866 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
TX errors: aborted fifo window heartbeat transns
0 0 0 0 1
3: docker0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
1161872 7215 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
79168334 16214 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
4: br-df93399bedb3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
112 4 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
1830 25 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
6: veth349e149@if5: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 0
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3596 50 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
8: veth3d86df7@if7: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-df93399bedb3 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 0
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3722 53 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
10: vetha1ca03b@if9: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 1
RX: bytes packets errors dropped overrun mcast
2428 31 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
5571 77 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
12: vethb42341d@if11: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-df93399bedb3 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 1
RX: bytes packets errors dropped overrun mcast
206068303 20950 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3774751 22357 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
22: vethcf21480@if21: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 4
RX: bytes packets errors dropped overrun mcast
404 6 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3374 43 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
24: vethf698c6c@if23: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-df93399bedb3 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 4
RX: bytes packets errors dropped overrun mcast
1912796 7105 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
1464035 5064 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
26: veth18b5695@if25: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 5
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
2632 36 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
28: veth78b8098@if27: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-df93399bedb3 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 5
RX: bytes packets errors dropped overrun mcast
1609122 14917 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
204532679 15748 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
=========================================================================
Disk Usage
=========================================================================
Filesystem Size Used Avail Use% Mounted on
udev 9.8G 0 9.8G 0% /dev
tmpfs 2.0G 11M 2.0G 1% /run
/dev/sda1 674G 399G 241G 63% /
tmpfs 9.9G 180K 9.9G 1% /dev/shm
tmpfs 5.0M 0 5.0M 0% /run/lock
tmpfs 9.9G 0 9.9G 0% /sys/fs/cgroup
tmpfs 2.0G 8.0K 2.0G 1% /run/user/1000
overlay 674G 399G 241G 63% /var/lib/docker/overlay2/886008fdedca289c5c0e1053a51f61a5872c07d00f96c18165044d4e5b7370e9/merged
overlay 674G 399G 241G 63% /var/lib/docker/overlay2/b9acbc453fea090b97d086c4b9a75a320d4c3eb784316257de011d14e844d8f9/merged
overlay 674G 399G 241G 63% /var/lib/docker/overlay2/899639b2d36fba61bb06d61a6346265e66e5a904cd1ccc73b3848771a4a73775/merged
overlay 674G 399G 241G 63% /var/lib/docker/overlay2/57b66642fec6841356abd24fc7a448c039afafea2ef69d4004753747f66aca86/merged
tmpfs 2.0G 0 2.0G 0% /run/user/1001
=========================================================================
Network Sockets
=========================================================================
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
syslog-ng 916 root 7u IPv4 20079 0t0 TCP *:514 (LISTEN)
syslog-ng 916 root 8u IPv4 20080 0t0 UDP *:514
mysqld 1473 mysql 19u IPv4 27982 0t0 TCP X.X.X.X:3306 (LISTEN)
sshd 1494 root 3u IPv4 30815 0t0 TCP *:ssh_port (LISTEN)
sshd 1494 root 4u IPv6 30817 0t0 TCP *:ssh_port (LISTEN)
sshd 1624 root 3u IPv4 23714 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:33010 (ESTABLISHED)
sshd 1816 root 3u IPv4 24720 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:52848 (ESTABLISHED)
sshd 1823 root 3u IPv4 23925 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42566 (ESTABLISHED)
sshd 1826 root 3u IPv4 23932 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34076 (ESTABLISHED)
sshd 1835 root 3u IPv4 27734 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:43778 (ESTABLISHED)
ntpd 1844 ntp 16u IPv6 23199 0t0 UDP *:123
ntpd 1844 ntp 17u IPv4 23202 0t0 UDP *:123
ntpd 1844 ntp 18u IPv4 23207 0t0 UDP X.X.X.X:123
ntpd 1844 ntp 19u IPv4 23209 0t0 UDP X.X.X.X:123
ntpd 1844 ntp 20u IPv6 23211 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 21u IPv6 23213 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 23u IPv4 33971 0t0 UDP X.X.X.X:123
ntpd 1844 ntp 24u IPv4 33973 0t0 UDP X.X.X.X:123
ntpd 1844 ntp 25u IPv6 33977 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 26u IPv6 33981 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 27u IPv6 34104 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 28u IPv6 34107 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 29u IPv6 34354 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 30u IPv6 34371 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 35u IPv6 37732 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 36u IPv6 37734 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 37u IPv6 46172 0t0 UDP [X.X.X.X]:123
ntpd 1844 ntp 38u IPv6 46402 0t0 UDP [X.X.X.X]:123
xrdp 1850 xrdp 6u IPv4 26766 0t0 TCP *:3389 (LISTEN)
xrdp-sesm 1890 root 6u IPv4 27821 0t0 TCP X.X.X.X:3350 (LISTEN)
sshd 1940 root 3u IPv4 27771 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:59330 (ESTABLISHED)
sshd 1959 root 3u IPv4 27791 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42632 (ESTABLISHED)
sshd 1961 root 3u IPv4 28825 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:54260 (ESTABLISHED)
sshd 1981 root 3u IPv4 28836 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:41002 (ESTABLISHED)
xinetd 2005 root 5u IPv4 24803 0t0 TCP *:6556 (LISTEN)
sshd 2014 root 3u IPv4 28849 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:39078 (ESTABLISHED)
sshd 2037 root 3u IPv4 28891 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:44120 (ESTABLISHED)
sshd 2073 root 3u IPv4 24838 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:12118 (ESTABLISHED)
sshd 2080 root 3u IPv4 24842 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:49850 (ESTABLISHED)
sshd 2084 root 3u IPv4 27857 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:58220 (ESTABLISHED)
sshd 2235 SO-user 3u IPv4 28836 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:41002 (ESTABLISHED)
sshd 2236 SO-user 3u IPv4 27857 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:58220 (ESTABLISHED)
sshd 2237 SO-user 3u IPv4 24720 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:52848 (ESTABLISHED)
sshd 2238 SO-user 3u IPv4 23932 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34076 (ESTABLISHED)
sshd 2239 SO-user 3u IPv4 23714 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:33010 (ESTABLISHED)
sshd 2240 SO-user 3u IPv4 28849 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:39078 (ESTABLISHED)
sshd 2241 SO-user 3u IPv4 24842 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:49850 (ESTABLISHED)
sshd 2242 SO-user 3u IPv4 28825 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:54260 (ESTABLISHED)
sshd 2243 SO-user 3u IPv4 23925 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42566 (ESTABLISHED)
sshd 2244 SO-user 3u IPv4 28891 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:44120 (ESTABLISHED)
sshd 2245 SO-user 3u IPv4 27791 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42632 (ESTABLISHED)
sshd 2246 SO-user 3u IPv4 27734 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:43778 (ESTABLISHED)
sshd 2247 SO-user 3u IPv4 27771 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:59330 (ESTABLISHED)
sshd 2250 root 3u IPv4 27895 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:38322 (ESTABLISHED)
sshd 2263 SO-user 3u IPv4 27895 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:38322 (ESTABLISHED)
sshd 2264 root 3u IPv4 27901 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:44642 (ESTABLISHED)
sshd 2282 SO-user 3u IPv4 27901 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:44642 (ESTABLISHED)
apache2 2319 root 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
sshd 2324 root 3u IPv4 25952 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:46306 (ESTABLISHED)
sshd 2326 root 3u IPv4 25959 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:55116 (ESTABLISHED)
sshd 2339 SO-user 3u IPv4 25952 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:46306 (ESTABLISHED)
sshd 2351 SO-user 3u IPv4 25959 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:55116 (ESTABLISHED)
apache2 2353 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 2354 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 2356 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 2357 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 2358 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
sshd 2365 root 3u IPv4 29013 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:53018 (ESTABLISHED)
sshd 2380 SO-user 3u IPv4 29013 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:53018 (ESTABLISHED)
sshd 2385 root 3u IPv4 22472 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:57699 (ESTABLISHED)
sshd 2401 SO-user 3u IPv4 24838 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:12118 (ESTABLISHED)
sshd 2585 SO-user 3u IPv4 22472 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:57699 (ESTABLISHED)
apache2 2601 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
sshd 2605 root 3u IPv4 24381 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:36532 (ESTABLISHED)
sshd 2623 SO-user 3u IPv4 24381 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:36532 (ESTABLISHED)
sshd 2660 root 3u IPv4 27163 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:48880 (ESTABLISHED)
sshd 2683 SO-user 3u IPv4 27163 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:48880 (ESTABLISHED)
sshd 2684 root 3u IPv4 23505 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:57676 (ESTABLISHED)
sshd 2700 SO-user 3u IPv4 23505 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:57676 (ESTABLISHED)
sshd 2705 root 3u IPv4 23515 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42734 (ESTABLISHED)
sshd 2718 SO-user 3u IPv4 23515 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:42734 (ESTABLISHED)
sshd 2730 root 3u IPv4 26189 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:54788 (ESTABLISHED)
sshd 2747 SO-user 3u IPv4 26189 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:54788 (ESTABLISHED)
ossec-aut 3157 root 3u IPv4 26579 0t0 TCP *:1515 (LISTEN)
salt-mini 3783 root 26u IPv4 33373 0t0 TCP X.X.X.X:42560->X.X.X.X:4505 (ESTABLISHED)
docker-pr 3904 root 4u IPv4 30241 0t0 TCP X.X.X.X:20000 (LISTEN)
sshd 3955 root 3u IPv4 31105 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34364 (ESTABLISHED)
sshd 3985 SO-user 3u IPv4 31105 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34364 (ESTABLISHED)
salt-mast 4156 root 14u IPv4 34962 0t0 TCP *:4505 (LISTEN)
salt-mast 4156 root 16u IPv4 32241 0t0 TCP X.X.X.X:4505->X.X.X.X:40712 (ESTABLISHED)
salt-mast 4156 root 17u IPv4 31250 0t0 TCP X.X.X.X:4505->X.X.X.X:42050 (ESTABLISHED)
salt-mast 4156 root 18u IPv4 31273 0t0 TCP X.X.X.X:4505->X.X.X.X:50386 (ESTABLISHED)
salt-mast 4156 root 19u IPv4 30520 0t0 TCP X.X.X.X:4505->X.X.X.X:38778 (ESTABLISHED)
salt-mast 4156 root 20u IPv4 35148 0t0 TCP X.X.X.X:4505->X.X.X.X:35990 (ESTABLISHED)
salt-mast 4156 root 21u IPv4 35150 0t0 TCP X.X.X.X:4505->X.X.X.X:57102 (ESTABLISHED)
salt-mast 4156 root 22u IPv4 35151 0t0 TCP X.X.X.X:4505->X.X.X.X:42560 (ESTABLISHED)
salt-mast 4156 root 23u IPv4 35153 0t0 TCP X.X.X.X:4505->X.X.X.X:60846 (ESTABLISHED)
salt-mast 4156 root 24u IPv4 35161 0t0 TCP X.X.X.X:4505->X.X.X.X:46162 (ESTABLISHED)
salt-mast 4156 root 25u IPv4 35175 0t0 TCP X.X.X.X:4505->X.X.X.X:33396 (ESTABLISHED)
salt-mast 4156 root 26u IPv4 35176 0t0 TCP X.X.X.X:4505->X.X.X.X:47056 (ESTABLISHED)
salt-mast 4156 root 27u IPv4 35210 0t0 TCP X.X.X.X:4505->X.X.X.X:36116 (ESTABLISHED)
salt-mast 4156 root 28u IPv4 35223 0t0 TCP X.X.X.X:4505->X.X.X.X:46770 (ESTABLISHED)
salt-mast 4156 root 29u IPv4 35270 0t0 TCP X.X.X.X:4505->X.X.X.X:49222 (ESTABLISHED)
salt-mast 4156 root 30u IPv4 35271 0t0 TCP X.X.X.X:4505->X.X.X.X:43818 (ESTABLISHED)
salt-mast 4156 root 31u IPv4 35272 0t0 TCP X.X.X.X:4505->X.X.X.X:58250 (ESTABLISHED)
salt-mast 4156 root 32u IPv4 35298 0t0 TCP X.X.X.X:4505->X.X.X.X:54306 (ESTABLISHED)
salt-mast 4156 root 33u IPv4 35325 0t0 TCP X.X.X.X:4505->X.X.X.X:35012 (ESTABLISHED)
salt-mast 4156 root 34u IPv4 35329 0t0 TCP X.X.X.X:4505->X.X.X.X:55462 (ESTABLISHED)
salt-mast 4156 root 35u IPv4 30711 0t0 TCP X.X.X.X:4505->X.X.X.X:55784 (ESTABLISHED)
salt-mast 4156 root 36u IPv4 30712 0t0 TCP X.X.X.X:4505->X.X.X.X:45632 (ESTABLISHED)
salt-mast 4156 root 37u IPv4 38922 0t0 TCP X.X.X.X:4505->X.X.X.X:51962 (ESTABLISHED)
salt-mast 4156 root 38u IPv4 38979 0t0 TCP X.X.X.X:4505->X.X.X.X:60842 (ESTABLISHED)
salt-mast 4156 root 39u IPv4 38983 0t0 TCP X.X.X.X:4505->X.X.X.X:60938 (ESTABLISHED)
salt-mast 4156 root 40u IPv4 38984 0t0 TCP X.X.X.X:4505->X.X.X.X:47898 (ESTABLISHED)
salt-mast 4156 root 41u IPv4 39008 0t0 TCP X.X.X.X:4505->X.X.X.X:53638 (ESTABLISHED)
salt-mast 4156 root 42u IPv4 39009 0t0 TCP X.X.X.X:4505->X.X.X.X:45098 (ESTABLISHED)
salt-mast 4156 root 43u IPv4 39173 0t0 TCP X.X.X.X:4505->X.X.X.X:34266 (ESTABLISHED)
salt-mast 4195 root 22u IPv4 27617 0t0 TCP *:4506 (LISTEN)
salt-mast 4195 root 24u IPv4 29560 0t0 TCP X.X.X.X:4506->X.X.X.X:54062 (ESTABLISHED)
salt-mast 4195 root 25u IPv4 29587 0t0 TCP X.X.X.X:4506->X.X.X.X:43024 (ESTABLISHED)
salt-mast 4195 root 26u IPv4 30710 0t0 TCP X.X.X.X:4506->X.X.X.X:56548 (ESTABLISHED)
salt-mast 4195 root 27u IPv4 29606 0t0 TCP X.X.X.X:4506->X.X.X.X:55836 (ESTABLISHED)
salt-mast 4195 root 28u IPv4 29607 0t0 TCP X.X.X.X:4506->X.X.X.X:32952 (ESTABLISHED)
salt-mast 4195 root 29u IPv4 30482 0t0 TCP X.X.X.X:4506->X.X.X.X:32954 (ESTABLISHED)
docker-pr 5019 root 4u IPv4 30555 0t0 TCP X.X.X.X:9300 (LISTEN)
docker-pr 5032 root 4u IPv4 31601 0t0 TCP X.X.X.X:9200 (LISTEN)
sshd 5517 root 3u IPv4 32715 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34112 (ESTABLISHED)
sshd 5550 SO-user 3u IPv4 32715 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:34112 (ESTABLISHED)
apache2 7072 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 7161 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
apache2 7162 www-data 4u IPv6 28987 0t0 TCP *:443 (LISTEN)
=========================================================================
IDS Rules Update
=========================================================================
Wed Sep 4 07:01:01 UTC 2019
Backing up current local_rules.xml file.
Cleaning up local_rules.xml backup files older than 30 days.
Backing up current downloaded.rules file before it gets overwritten.
Cleaning up downloaded.rules backup files older than 30 days.
Backing up current local.rules file before it gets overwritten.
Cleaning up local.rules backup files older than 30 days.
Sleeping for 48 minutes to avoid overwhelming rule sites.
=========================================================================
CPU Usage
=========================================================================
Load average for the last 1, 5, and 15 minutes:
0.17 0.12 0.10
Processing units: 8
If load average is higher than processing units,
then tune until load average is lower than processing units.
top - 13:06:05 up 2:25, 3 users, load average: 0.17, 0.12, 0.10
Tasks: 303 total, 1 running, 235 sleeping, 0 stopped, 0 zombie
%Cpu(s): 2.1 us, 0.4 sy, 0.0 ni, 95.8 id, 1.7 wa, 0.0 hi, 0.1 si, 0.0 st
KiB Mem : 20554068 total, 9812168 free, 7246420 used, 3495480 buff/cache
KiB Swap: 16774140 total, 16774140 free, 0 used. 12581012 avail Mem
%CPU %MEM COMMAND
1.7 29.5 /opt/jdk-12.0.1/bin/java -Xms4106m -Xmx4106m -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -XX:-OmitStackTraceInFastThrow -Dio.netty.noUnsafe=true -Dio.netty.noKeySetOptimization=true -Dio.netty.recycler.maxCapacityPerThread=0 -Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true -Djava.io.tmpdir=/tmp/elasticsearch-10262170435228982621 -XX:+HeapDumpOnOutOfMemoryError -Xlog:gc*,gc+age=trace,safepoint:file=logs/gc.log:utctime,pid,tags:filecount=32,filesize=64m -Djava.locale.providers=COMPAT -Des.cgroups.hierarchy.override=/ -Des.path.home=/usr/share/elasticsearch -Des.path.conf=/usr/share/elasticsearch/config -Des.distribution.flavor=oss -Des.distribution.type=docker -cp /usr/share/elasticsearch/lib/* org.elasticsearch.bootstrap.Elasticsearch -Ebootstrap.memory_lock=true -Etransport.host=X.X.X.X -Ehttp.host=X.X.X.X
1.6 0.4 /usr/bin/python /usr/bin/salt-master
1.5 0.4 /usr/bin/python /usr/bin/salt-master
1.5 0.5 /usr/bin/python /usr/bin/salt-master
1.4 0.4 /usr/bin/python /usr/bin/salt-master
1.4 0.4 /usr/bin/python /usr/bin/salt-master
0.4 2.1 /usr/sbin/mysqld
0.3 0.3 /usr/bin/python /usr/bin/salt-master
0.2 0.3 /usr/bin/python /usr/bin/salt-master
0.1 0.4 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
0.1 1.3 /usr/bin/python /opt/domain_stats/domain_stats.py -ip X.X.X.X 20000 -a /opt/domain_stats/top-1m.csv --preload 0
0.1 0.0 /bin/bash /usr/sbin/sostat
0.1 0.2 python -m elastalert.elastalert --config /etc/elastalert/conf/elastalert_config.yaml --verbose
0.0 0.0 /sbin/init splash
0.0 0.0 [kthreadd]
0.0 0.0 [kworker/0:0H]
0.0 0.0 [mm_percpu_wq]
0.0 0.0 [ksoftirqd/0]
0.0 0.0 [rcu_sched]
0.0 0.0 [rcu_bh]
0.0 0.0 [migration/0]
0.0 0.0 [watchdog/0]
0.0 0.0 [cpuhp/0]
0.0 0.0 [cpuhp/1]
0.0 0.0 [watchdog/1]
0.0 0.0 [migration/1]
0.0 0.0 [ksoftirqd/1]
0.0 0.0 [kworker/1:0H]
0.0 0.0 [cpuhp/2]
0.0 0.0 [watchdog/2]
0.0 0.0 [migration/2]
0.0 0.0 [ksoftirqd/2]
0.0 0.0 [kworker/2:0H]
0.0 0.0 [cpuhp/3]
0.0 0.0 [watchdog/3]
0.0 0.0 [migration/3]
0.0 0.0 [ksoftirqd/3]
0.0 0.0 [kworker/3:0H]
0.0 0.0 [cpuhp/4]
0.0 0.0 [watchdog/4]
0.0 0.0 [migration/4]
0.0 0.0 [ksoftirqd/4]
0.0 0.0 [kworker/4:0H]
0.0 0.0 [cpuhp/5]
0.0 0.0 [watchdog/5]
0.0 0.0 [migration/5]
0.0 0.0 [ksoftirqd/5]
0.0 0.0 [kworker/5:0H]
0.0 0.0 [cpuhp/6]
0.0 0.0 [watchdog/6]
0.0 0.0 [migration/6]
0.0 0.0 [ksoftirqd/6]
0.0 0.0 [kworker/6:0H]
0.0 0.0 [cpuhp/7]
0.0 0.0 [watchdog/7]
0.0 0.0 [migration/7]
0.0 0.0 [ksoftirqd/7]
0.0 0.0 [kworker/7:0H]
0.0 0.0 [kdevtmpfs]
0.0 0.0 [netns]
0.0 0.0 [rcu_tasks_kthre]
0.0 0.0 [kauditd]
0.0 0.0 [khungtaskd]
0.0 0.0 [oom_reaper]
0.0 0.0 [writeback]
0.0 0.0 [kcompactd0]
0.0 0.0 [ksmd]
0.0 0.0 [khugepaged]
0.0 0.0 [crypto]
0.0 0.0 [kintegrityd]
0.0 0.0 [kblockd]
0.0 0.0 [ata_sff]
0.0 0.0 [md]
0.0 0.0 [edac-poller]
0.0 0.0 [devfreq_wq]
0.0 0.0 [watchdogd]
0.0 0.0 [kswapd0]
0.0 0.0 [kworker/u17:0]
0.0 0.0 [ecryptfs-kthrea]
0.0 0.0 [kthrotld]
0.0 0.0 [acpi_thermal_pm]
0.0 0.0 [scsi_eh_0]
0.0 0.0 [scsi_tmf_0]
0.0 0.0 [scsi_eh_1]
0.0 0.0 [scsi_tmf_1]
0.0 0.0 [ipv6_addrconf]
0.0 0.0 [kstrp]
0.0 0.0 [charger_manager]
0.0 0.0 [mpt_poll_0]
0.0 0.0 [mpt/0]
0.0 0.0 [kworker/6:1H]
0.0 0.0 [scsi_eh_2]
0.0 0.0 [scsi_tmf_2]
0.0 0.0 [ttm_swap]
0.0 0.0 [irq/16-vmwgfx]
0.0 0.0 [kworker/2:1H]
0.0 0.0 [kworker/3:1H]
0.0 0.0 [kworker/5:1H]
0.0 0.0 [raid5wq]
0.0 0.0 [kworker/7:1H]
0.0 0.0 [kworker/0:1H]
0.0 0.0 [kworker/4:1H]
0.0 0.0 [jbd2/sda1-8]
0.0 0.0 [ext4-rsv-conver]
0.0 0.0 /lib/systemd/systemd-journald
0.0 0.0 [iscsi_eh]
0.0 0.0 [ib-comp-wq]
0.0 0.0 [ib_mcast]
0.0 0.0 [ib_nl_sa_wq]
0.0 0.0 [rdma_cm]
0.0 0.0 /sbin/lvmetad -f
0.0 0.0 /lib/systemd/systemd-udevd
0.0 0.0 /usr/bin/vmtoolsd
0.0 0.0 [kworker/1:1H]
0.0 0.0 /usr/bin/VGAuthService
0.0 0.0 /usr/lib/accountsservice/accounts-daemon
0.0 0.0 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation
0.0 0.0 /usr/sbin/atd -f
0.0 0.0 /lib/systemd/systemd-logind
0.0 0.0 /usr/sbin/cron -f
0.0 0.0 /usr/sbin/syslog-ng -F
0.0 0.0 /usr/sbin/NetworkManager --no-daemon
0.0 0.0 /usr/sbin/acpid
0.0 0.0 /sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan --syslog
0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
0.0 0.0 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal
0.0 0.3 /usr/bin/python /usr/bin/salt-master
0.0 0.2 /usr/bin/python /usr/bin/salt-minion
0.0 0.2 /usr/bin/containerd
0.0 0.0 /usr/sbin/sshd -D
0.0 0.0 /sbin/iscsid
0.0 0.0 /sbin/iscsid
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 [kworker/4:0]
0.0 0.0 /usr/sbin/irqbalance --pid=/var/run/irqbalance.pid
0.0 0.0 /usr/sbin/lightdm
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 111:118
0.0 0.0 /usr/sbin/xrdp
0.0 0.2 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
0.0 0.0 /usr/sbin/xrdp-sesman
0.0 0.0 /sbin/agetty --noclear tty1 linux
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 /usr/sbin/xinetd -pidfile /run/xinetd.pid -stayalive -inetd_compat -inetd_ipv6
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 /lib/systemd/systemd --user
0.0 0.0 (sd-pam)
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.1 php-fpm: master process (/etc/php/7.0/fpm/php-fpm.conf)
0.0 0.0 php-fpm: pool www
0.0 0.0 php-fpm: pool www
0.0 0.1 /usr/sbin/apache2 -k start
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user@pts/0
0.0 0.0 -bash
0.0 0.0 sudo su
0.0 0.0 su
0.0 0.0 bash
0.0 0.0 sshd: SO-user@pts/1
0.0 0.0 -bash
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 /var/ossec/bin/ossec-authd
0.0 0.0 /var/ossec/bin/wazuh-db
0.0 0.0 /var/ossec/bin/ossec-execd
0.0 0.0 /var/ossec/bin/wazuh-modulesd
0.0 0.0 [kworker/u16:2]
0.0 0.3 /usr/bin/python /usr/bin/salt-minion
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 20000 -container-ip X.X.X.X -container-port 20000
0.0 0.0 containerd-shim -namespace moby -workdir /var/lib/containerd/io.containerd.runtime.v1.linux/moby/8ec42bd5b03f1bf6d8ef3a0a4174164a44570c321c33bee0d7bcf3c03fe2f7c7 -address /run/containerd/containerd.sock -containerd-binary /usr/bin/containerd -runtime-root /var/run/docker/runtime-runc
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
0.0 0.2 /usr/bin/python /usr/bin/salt-master
0.0 0.2 /usr/bin/python /usr/bin/salt-master
0.0 0.2 /usr/bin/python /usr/bin/salt-master
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9300 -container-ip X.X.X.X -container-port 9300
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9200 -container-ip X.X.X.X -container-port 9200
0.0 0.0 containerd-shim -namespace moby -workdir /var/lib/containerd/io.containerd.runtime.v1.linux/moby/cf5f14969f82bcfe32ec5136b8c601fb59b1f19307468ec6e512434892a730ad -address /run/containerd/containerd.sock -containerd-binary /usr/bin/containerd -runtime-root /var/run/docker/runtime-runc
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 sshd: SO-user
0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 containerd-shim -namespace moby -workdir /var/lib/containerd/io.containerd.runtime.v1.linux/moby/f2711c1c806311215827fb4b45ca0909dd4665513f5c32a271cc020d423ecac8 -address /run/containerd/containerd.sock -containerd-binary /usr/bin/containerd -runtime-root /var/run/docker/runtime-runc
0.0 0.1 /usr/bin/python /usr/bin/supervisord -c /etc/elastalert/conf/elastalert_supervisord.conf -n
0.0 0.0 lightdm --session-child 12 19
0.0 0.0 /usr/bin/gnome-keyring-daemon --daemonize --login
0.0 0.0 /bin/sh /usr/bin/gnome-session-classic
0.0 0.0 containerd-shim -namespace moby -workdir /var/lib/containerd/io.containerd.runtime.v1.linux/moby/ca54ad3e828ecb413beefa05b2a44ab4a045aecc0256c745d7d91f83ff97ec97 -address /run/containerd/containerd.sock -containerd-binary /usr/bin/containerd -runtime-root /var/run/docker/runtime-runc
0.0 0.0 /usr/bin/ssh-agent /usr/bin/dbus-launch --exit-with-session /usr/bin/im-launch gnome-session-classic
0.0 0.0 /usr/bin/dbus-launch --exit-with-session /usr/bin/im-launch gnome-session-classic
0.0 0.0 /bin/bash
0.0 0.0 /usr/bin/dbus-daemon --fork --print-pid 5 --print-address 7 --session
0.0 0.0 /usr/bin/ibus-daemon --daemonize --xim --address unix:tmpdir=/tmp/ibus
0.0 0.0 /usr/lib/gnome-session/gnome-session-binary --session gnome-classic
0.0 0.0 /usr/lib/gvfs/gvfsd
0.0 0.0 /usr/lib/ibus/ibus-dconf
0.0 0.1 /usr/lib/ibus/ibus-ui-gtk3
0.0 0.0 [kworker/2:1]
0.0 0.1 /usr/lib/ibus/ibus-x11 --kill-daemon
0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
0.0 0.0 /usr/bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
0.0 0.0 /usr/lib/ibus/ibus-engine-simple
0.0 0.1 /usr/bin/gnome-screensaver --no-daemon
0.0 0.1 /usr/lib/gnome-settings-daemon/gnome-settings-daemon
0.0 0.0 /usr/lib/upower/upowerd
0.0 0.0 /usr/bin/pulseaudio --start --log-target=syslog
0.0 0.0 /usr/lib/rtkit/rtkit-daemon
0.0 0.0 /usr/lib/colord/colord
0.0 0.8 /usr/bin/gnome-shell
0.0 0.0 /usr/lib/gnome-shell/gnome-shell-calendar-server
0.0 0.1 /usr/lib/evolution/evolution-source-registry
0.0 0.0 /usr/lib/telepathy/mission-control-5
0.0 0.0 /usr/lib/gvfs/gvfs-udisks2-volume-monitor
0.0 0.0 /usr/lib/udisks2/udisksd --no-debug
0.0 0.0 /usr/lib/gvfs/gvfs-mtp-volume-monitor
0.0 0.0 /usr/lib/gvfs/gvfs-afc-volume-monitor
0.0 0.0 /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
0.0 0.0 /usr/lib/gvfs/gvfs-goa-volume-monitor
0.0 0.1 nautilus -n
0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
0.0 0.0 /usr/lib/gvfs/gvfsd-trash --spawner :1.1 /org/gtk/gvfs/exec_spaw/0
0.0 0.2 /usr/lib/evolution/evolution-calendar-factory
0.0 0.0 /usr/lib/gvfs/gvfsd-metadata
0.0 0.2 /usr/lib/evolution/evolution-calendar-factory-subprocess --factory contacts --bus-name org.gnome.evolution.dataserver.Subprocess.Backend.Calendarx8590x2 --own-path /org/gnome/evolution/dataserver/Subprocess/Backend/Calendar/8590/2
0.0 0.0 /usr/lib/evolution/evolution-addressbook-factory
0.0 0.2 /usr/lib/evolution/evolution-calendar-factory-subprocess --factory local --bus-name org.gnome.evolution.dataserver.Subprocess.Backend.Calendarx8590x3 --own-path /org/gnome/evolution/dataserver/Subprocess/Backend/Calendar/8590/3
0.0 0.0 /usr/lib/evolution/evolution-addressbook-factory-subprocess --factory local --bus-name org.gnome.evolution.dataserver.Subprocess.Backend.AddressBookx8630x2 --own-path /org/gnome/evolution/dataserver/Subprocess/Backend/AddressBook/8630/2
0.0 0.1 /usr/bin/gnome-disks --gapplication-service
0.0 0.0 [kworker/1:2]
0.0 0.0 [kworker/6:0]
0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
0.0 0.0 /lib/systemd/systemd --user
0.0 0.0 (sd-pam)
0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
0.0 0.0 sudo su
0.0 0.0 su
0.0 0.0 bash
0.0 0.0 [kworker/7:0]
0.0 0.0 [kworker/1:0]
0.0 0.0 [kworker/4:2]
0.0 0.0 [kworker/0:1]
0.0 0.0 [kworker/u16:1]
0.0 0.0 [kworker/3:1]
0.0 0.0 [kworker/2:2]
0.0 0.0 [kworker/5:1]
0.0 0.0 [kworker/u16:0]
0.0 0.0 [kworker/7:2]
0.0 0.0 [kworker/6:2]
0.0 0.0 [kworker/0:2]
0.0 0.0 [kworker/3:0]
0.0 0.0 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
0.0 0.0 [kworker/5:0]
=========================================================================
Sguil Uncategorized Events
=========================================================================
=========================================================================
Sguil events summary for yesterday
=========================================================================
=========================================================================
Top 50 All time Sguil Events
=========================================================================
=========================================================================
Last update
=========================================================================
Commandline: apt-get install -y docker-ce docker-ce-cli
containerd.ioRequested-By: SO-user (1000)
Upgrade: docker-ce:amd64 (5:19.03.1~3-0~ubuntu-xenial, 5:19.03.2~3-0~ubuntu-xenial), docker-ce-cli:amd64 (5:19.03.1~3-0~ubuntu-xenial, 5:19.03.2~3-0~ubuntu-xenial)
End-Date: 2019-09-04 09:52:35
Start-Date: 2019-09-04 09:53:06
Commandline: apt-get -y dist-upgrade
Requested-By: SO-user (1000)
Upgrade: securityonion-bro-scripts:amd64 (20121004-0ubuntu0securityonion72, 20121004-0ubuntu0securityonion73), securityonion-bro-afpacket:amd64 (1.3.0-1ubuntu1securityonion12, 1.3.0-1ubuntu1securityonion13), securityonion-bro:amd64 (2.6.3-1ubuntu1securityonion1, 2.6.4-1ubuntu1securityonion1)
End-Date: 2019-09-04 09:53:14
=========================================================================
Elasticsearch
=========================================================================
Elasticsearch is running.
Cluster Name: "uk-pro-son-01"
Cluster Status: "green"
Total Nodes: 1
Failed Nodes: 0
Total Indices: 29
Total Shards: 45
Total Documents: 352808402
Total Size: 408387MB
Free Memory: 48%
Total Number of Events: 352808402
Avg. Event Size (In Bytes): 1157
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
cf5f14969f82 so-elasticsearch 0.32% 4.92GiB / 19.6GiB 25.10% 3.79MB / 206MB 3.21GB / 22.9MB 101
=========================================================================
Logstash
=========================================================================
Logstash is not running.
Try starting it with:
'sudo so-elastic-start'
OR
'sudo docker start so-logstash'
If that does not work, try checking /var/log/logstash/logstash.log for clues.
=========================================================================
Kibana
=========================================================================
Kibana is not running.
Try starting it with:
'sudo so-elastic-start'
OR
'sudo docker start so-kibana'
If that does not work, try checking /var/log/kibana/kibana.log for clues.
=========================================================================
ElastAlert
=========================================================================
ElastAlert is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
f2711c1c8063 so-elastalert 0.01% 68.56MiB / 19.6GiB 0.34% 1.47MB / 1.91MB 38.2MB / 24.6kB 2
=========================================================================
Curator
=========================================================================
Curator is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
ca54ad3e828e so-curator 0.00% 7.246MiB / 19.6GiB 0.04% 205MB / 1.61MB 6.95MB / 0B 1
=========================================================================
Domain Stats
=========================================================================
Domain_stats is running.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
8ec42bd5b03f so-domainstats 0.10% 267.2MiB / 19.6GiB 1.33% 7.39kB / 0B 80.4MB / 0B 2
Testing domain_stats now...
Domain_stats is working.
=========================================================================
Version Information
=========================================================================
Ubuntu 16.04.6 LTS
securityonion-sostat 20120722-0ubuntu0securityonion129