Hi Patrick,
Please send the output of the following (redacting sensitive info as necessary):
sudo sostat
Thanks,
Doug
On Wed, Apr 17, 2013 at 11:52 AM, Patrick Gardella
<
patrick....@asburyseminary.edu> wrote:
> OK, more data now that the system is up again.
>
> Normally the console also froze up and I couldn't see any errors on the console monitor. This time it stayed up enough for me to see what was on the screen (but not log in).
>
> I saw a bunch of out of memory errors and processes being killed. The processes were tclsh, ruby, and prads.
>
> I am seeing one tclsh script taking huge amounts of memory and RAM:
>
> 2487 ? R 37:03 tclsh /usr/bin/sguild -c /etc/nsm/securityonion/sguild.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/sguild.queries -A /etc/nsm/securityonion/sguild.access -C /etc/nsm/securityonion/certs
>
> It is using 4GB of RAM and 99% of CPU. That doesn't seem normal.
>
> It is an HP DL380 G5:
> Dual Intel(R) Xeon(R) CPU E5440 @ 2.83GHz
> 16 GB RAM
>
> Patrick
>
> On Wednesday, April 17, 2013 9:44:29 AM UTC-4, Patrick Gardella wrote:
>> I was logging in to see if others were having the same problem, and to ask around.
>>
>> I've had the same problem for quite a while and have been trying to gather diagnostics, which has been tough, since I have to force a reboot to log back in. I also need to reconfigure the sensors (to exactly what they were before) for it to gather traffic again. After the last time, I started capturing some statistics to a log. As soon as I reboot the server, I'll see what I found in those logs.
>>
>> In my case, I can ping the server and it responds very quickly. But the web interface and ssh just hang.
>>
>> I am running the latest (except for this morning's update) on a stock Ubuntu 12.04 installation. It is running on an HP G5 server with a 1TB HW RAID cluster internally. We normally have around 80 MBPS of traffic during peaks.
>>
>> This freeze happens about once a week for me.
>>
>> So more to follow...
>>
>> Patrick
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to
security-onio...@googlegroups.com.
> To post to this group, send email to
securit...@googlegroups.com.
> Visit this group at
http://groups.google.com/group/security-onion?hl=en-US.
> For more options, visit
https://groups.google.com/groups/opt_out.
>
>
--
Doug Burks
http://securityonion.blogspot.com