I'm seeing the same problems with lots of perl scripts nailed at full CPU hogging all resources.
Currently I am at 73 pairs of this and a system load approaching 50. My 24 cores are getting overwhelmed.
root 31905 0.0 0.0 4396 608 ? Ss 14:10 0:00 /bin/sh -c perl /opt/elsa/web/
cron.pl -c /etc/elsa_web.conf > /dev/null 2>&1
root 31908 65.7 0.1 298388 95748 ? R 14:10 18:12 perl /opt/elsa/web/
cron.pl -c /etc/elsa_web.conf
I tried manually running one of these without piping output to /dev/null and it just hung there.
I have no active archive queries.
mysql -uroot -Delsa_web -e 'select * from query_log where archive=1;'
give me 27 lines of output:
qid uid query system timestamp num_results milliseconds archive
125 3 {"query_string":"site:csd-k1000 class=BRO_HTTP bro_http.status_code=\\"302\\" archive:1","query_meta_params":{"limit":100,"archive":1,"timezone_offset":240,"start":"2014-03-13 16:41:26"}} 02014-03-25 13:44:37 100 337 1
126 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "1394743286"\n },\n "query_string" : "site:csd-k1000 class=BRO_HTTP bro_http.status_code=\\"302\\" archive:1"\n}\n 0 2014-03-25 13:44:37 100 4294967295 1
219 3 {"query_string":"10.255.4.206 class=BRO_HTTP BRO_HTTP.method=POST archive:1","query_meta_params":{"limit":100,"archive":1,"timezone_offset":240,"start":"2014-03-24 11:44:22"}} 0 2014-03-26 15:47:35 77 1491 1
220 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "1395675862"\n },\n "query_string" : "10.255.4.206 class=BRO_HTTP BRO_HTTP.method=POST archive:1"\n}\n 0 2014-03-26 15:47:36 77 2165927000 1
5807 3 {"query_string":"10.176.13.244 class=\\"BRO_HTTP\\" groupby:site limit:250 archive:1","query_meta_params":{"limit":100,"archive":1,"timezone_offset":240,"start":"2014-07-01 00:00:00"}} 02014-10-20 13:55:24 261 807 1
5808 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "1404187200"\n },\n "query_string" : "10.176.13.244 class=\\"BRO_HTTP\\" groupby:site limit:250 archive:1"\n}\n 0 2014-10-20 13:55:24 11 4294967295 1
5809 3 {"query_string":"10.176.13.244 class=\\"BRO_HTTP\\" groupby:site limit:250 archive:1","query_meta_params":{"limit":100,"archive":1,"groupby":[],"timezone_offset":240,"start":"NaN-NaN-NaN NaN:NaN:NaN"}} 0 2014-10-20 13:56:35 257 1112 1
5810 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "14400"\n },\n "query_string" : "10.176.13.244 class=\\"BRO_HTTP\\" groupby:site limit:250 archive:1"\n}\n 0 2014-10-20 13:56:36 7 4294967295 1
5915 3 {"query_string":"10.32.8.201 class=BRO_HTTP limit:250 \\"
www.elf.cz\\" archive:1","query_meta_params":{"limit":100,"archive":1,"timezone_offset":240,"start":"2014-07-01 00:00:00"}} 0 2014-10-21 13:58:16 250 482 1
5916 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "1404187200"\n },\n "query_string" : "10.32.8.201 class=BRO_HTTP limit:250 \\"
www.elf.cz\\" archive:1"\n}\n 0 2014-10-21 13:58:16 0 4294967295 1
5975 3 {"query_string":"10.176.13.244 class=\\"BRO_HTTP\\"
ts1.explicit.bing.net limit:11000","query_meta_params":{"archive":1,"limit":100,"timezone_offset":240,"start":"2014-07-01 00:00:00"}} 02014-10-24 15:34:18 10718 231 1
5976 1 {\n "query_meta_params" : {\n "timezone_offset" : 240,\n "limit" : 100,\n "start" : "1404187200"\n },\n "query_string" : "10.176.13.244 class=\\"BRO_HTTP\\"
ts1.explicit.bing.net limit:11000"\n}\n 0 2014-10-24 15:34:18 0 320000 1
6779 3 {"query_string":"10.248.17.204 -class=BRO_HTTP fxz101 class=BRO_SYSLOG limit:20000","query_meta_params":{"limit":100,"timezone_offset":240,"start":"2014-10-26 00:00:00","end":"2014-10-27 00:00:00"}} 0 2014-11-05 21:58:13 19032 369 1
6780 1 {\n "query_meta_params" : {\n "timezone_offset" : 240,\n "limit" : 100,\n "end" : 1414382400,\n "start" : "1414296000"\n },\n "query_string" : "10.248.17.204 -class=BRO_HTTP fxz101 class=BRO_SYSLOG limit:20000"\n}\n 0 2014-11-05 21:58:13 0 28993000 1
7499 3 {"query_string":"10.32.8.153 class=\\"BRO_HTTP\\" limit::200","query_meta_params":{"limit":100,"timezone_offset":300,"start":"2014-12-05 00:45:10"}} 0 2014-12-05 19:13:53 200 231 1
7500 1 {\n "query_meta_params" : {\n "timezone_offset" : 300,\n "limit" : 100,\n "start" : "1417758310"\n },\n "query_string" : "10.32.8.153 class=\\"BRO_HTTP\\" limit::200"\n}\n 0 2014-12-05 19:13:54 80 171000 1
9551 3 {"query_string":"10.176.13.244 class=BRO_HTTP groupby:site archive:1","query_meta_params":{"limit":100,"archive":1,"timezone_offset":300,"start":"2014-90-15 00:00:00","end":"2014-09-15 23:59:59"}} 0 2015-02-24 21:30:36 100 890 1
9552 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 300,\n "limit" : 100,\n "end" : 1410843599,\n "start" : "18000"\n },\n "query_string" : "10.176.13.244 class=BRO_HTTP groupby:site archive:1"\n}\n 0 2015-02-24 21:30:36 -1 NULL 1
9553 3 {"query_string":"10.176.13.244 class=BRO_HTTP groupby:site archive:1","query_meta_params":{"limit":100,"archive":1,"groupby":[],"timezone_offset":300,"start":"2014-09-15 00:00:00","end":"2014-09-15 12:00:00"}} 0 2015-02-24 21:38:46 0 296311000 1
9554 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 300,\n "limit" : 100,\n "end" : 1410800400,\n "start" : "1410757200"\n },\n "query_string" : "10.176.13.244 class=BRO_HTTP groupby:site archive:1"\n}\n 0 2015-02-24 21:38:46 0 189761000 1
9559 3 {"query_string":"10.176.13.244 class=BRO_HTTP groupby:site limit:250 archive:1","query_meta_params":{"archive":1,"limit":100,"groupby":[],"timezone_offset":300,"start":"2014-09-15 00:00:00","end":"2014-09-15 23:59:59"}} 0 2015-02-24 22:03:25 0 465 1
9560 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 300,\n "limit" : 100,\n "end" : 1410843599,\n "start" : "1410757200"\n },\n "query_string" : "10.176.13.244 class=BRO_HTTP groupby:site limit:250 archive:1"\n}\n 0 2015-02-24 22:03:25 0 398102000 1
9571 3 {"query_string":" 10.176.14.122 class=BRO_HTTP groupby:site archive:1","query_meta_params":{"limit":100,"timezone_offset":300,"start":"2014-11-01 00:00:00","end":"2014-11-04 00:00:00"}} 02015-02-25 14:44:27 106 436 1
9572 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 300,\n "limit" : 100,\n "end" : 1415077200,\n "start" : "1414818000"\n },\n "query_string" : " 10.176.14.122 class=BRO_HTTP groupby:site archive:1"\n}\n 0 2015-02-25 14:44:27 6 629510000 1
9573 3 {"query_string":" 10.176.14.122 class=BRO_HTTP groupby:site archive:1","query_meta_params":{"limit":100,"groupby":[],"archive":1,"timezone_offset":300,"start":"2014-11-01 00:00:00","end":"2014-11-03 00:00:00"}} 0 2015-02-25 14:46:16 12 315 1
9574 1 {\n "query_meta_params" : {\n "archive" : 1,\n "timezone_offset" : 300,\n "limit" : 100,\n "end" : 1414990800,\n "start" : "1414818000"\n },\n "query_string" : " 10.176.14.122 class=BRO_HTTP groupby:site archive:1"\n}\n 0 2015-02-25 14:46:17 4 292866000 1
I don't think these are active scans.
mysqld is up to 100%, likely working on the backlog of events stacked up since the SSL issue took pcap_agent and snort_agent offline for the past 18 hours.
It does not look like I am seeing these issues onthe sensor nodes, just the master.
Frustrated that a routine update has caused major havoc on my work schedule. As Sir Toppam Hat used to say "You are causing confusion and delay!"