Hello ,
Please metsniff-ng not starting.
Please see below.
=========================================================================
Service Status
=========================================================================
Status: securityonion
* SO-user server[ OK ]
Status: HIDS
* ossec_agent (SO-user)[ OK ]
Status: Bro
Name Type Host Status Pid Started
manager manager localhost running 2917 22 Oct 14:13:43
proxy proxy localhost running 3706 22 Oct 14:13:47
41-184-204-74-eth2-1 worker localhost running 5114 22 Oct
14:13:49
41-184-204-74-eth2-2 worker localhost running 5121 22 Oct
14:13:49
41-184-204-74-eth2-3 worker localhost running 5134 22 Oct
14:13:49
41-184-204-74-eth2-4 worker localhost running 5125 22 Oct
14:13:49
41-184-204-74-eth2-5 worker localhost running 5135 22 Oct
14:13:49
41-184-204-74-eth2-6 worker localhost running 5132 22 Oct
14:13:49
41-184-204-74-eth2-7 worker localhost running 5130 22 Oct
14:13:49
Status: 41-184-204-74-eth2
* netsniff-ng (full packet data)[ FAIL ]
* pcap_agent (SO-user)[ OK ]
* snort_agent-1 (SO-user)[ OK ]
* snort_agent-2 (SO-user)[ OK ]
* snort_agent-3 (SO-user)[ OK ]
* snort_agent-4 (SO-user)[ OK ]
* snort_agent-5 (SO-user)[ OK ]
* snort_agent-6 (SO-user)[ OK ]
* snort_agent-7 (SO-user)[ OK ]
* snort-1 (alert data)[ OK ]
* snort-2 (alert data)[ OK ]
* snort-3 (alert data)[ OK ]
* snort-4 (alert data)[ OK ]
* snort-5 (alert data)[ OK ]
* snort-6 (alert data)[ OK ]
* snort-7 (alert data)[ OK ]
* barnyard2-1 (spooler, unified2 format)[ OK ]
* barnyard2-2 (spooler, unified2 format)[ OK ]
* barnyard2-3 (spooler, unified2 format)[ OK ]
* barnyard2-4 (spooler, unified2 format)[ OK ]
* barnyard2-5 (spooler, unified2 format)[ OK ]
* barnyard2-6 (spooler, unified2 format)[ OK ]
* barnyard2-7 (spooler, unified2 format)[ OK ]
Status: Elastic stack
* so-elasticsearch[ OK ]
* so-logstash -- Logstash has started, but is still initializing...[
WARN ]
* so-kibana[ OK ]
* so-curator[ OK ]
* so-elastalert[ OK ]
=========================================================================
Interface Status
=========================================================================
br-caf319787969 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:3 errors:0 dropped:0 overruns:0 frame:0
TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:84 (84.0 B) TX bytes:648 (648.0 B)
docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1000 errors:0 dropped:0 overruns:0 frame:0
TX packets:1039 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:4840700 (4.8 MB) TX bytes:134786 (134.7 KB)
enp0s29f1u2 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:270 errors:0 dropped:0 overruns:0 frame:0
TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:17567 (17.5 KB) TX bytes:648 (648.0 B)
eth0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
eth1 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:387184 errors:0 dropped:0 overruns:0 frame:0
TX packets:5186 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:551825553 (551.8 MB) TX bytes:3949825 (3.9 MB)
Memory:92d60000-92d7ffff
eth2 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
UP BROADCAST RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
RX packets:21034152 errors:0 dropped:1026 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:
7082780459 (7.0 GB) TX bytes:0 (0.0 B)
eth3 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
Memory:92d20000-92d3ffff
lo Link encap:Local Loopback
inet addr:X.X.X.X Mask:X.X.X.X
inet6 addr: X.X.X.X/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:508170 errors:0 dropped:0 overruns:0 frame:0
TX packets:508170 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1
RX bytes:3008884812 (3.0 GB) TX bytes:3008884812 (3.0 GB)
so-curator
-------------------------------------------------------------------------
(eth0)
veth717901c Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:9 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:690 (690.0 B)
(eth1)
veth57c384b Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1459 errors:0 dropped:0 overruns:0 frame:0
TX packets:1789 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:190674 (190.6 KB) TX bytes:38016833 (38.0 MB)
so-elastalert
-------------------------------------------------------------------------
(eth0)
vetha0f3346 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:9 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:690 (690.0 B)
(eth1)
vethdeba8ab Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:556 errors:0 dropped:0 overruns:0 frame:0
TX packets:441 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:142641 (142.6 KB) TX bytes:145410 (145.4 KB)
so-kibana
-------------------------------------------------------------------------
(eth0)
veth6a2b3a5 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:617 errors:0 dropped:0 overruns:0 frame:0
TX packets:586 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:3228754 (3.2 MB) TX bytes:101046 (101.0 KB)
(eth1)
vethc83ac4e Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1238 errors:0 dropped:0 overruns:0 frame:0
TX packets:1118 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:179848 (179.8 KB) TX bytes:1048385 (1.0 MB)
so-logstash
-------------------------------------------------------------------------
(eth0)
veth7c4454a Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:55 errors:0 dropped:0 overruns:0 frame:0
TX packets:67 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:2730 (2.7 KB) TX bytes:4302 (4.3 KB)
(eth1)
vethc098e8d Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:13 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:914 (914.0 B)
so-elasticsearch
-------------------------------------------------------------------------
(eth0)
veth3fd2127 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:330 errors:0 dropped:0 overruns:0 frame:0
TX packets:418 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:1623300 (1.6 MB) TX bytes:31774 (31.7 KB)
(eth1)
veth3fe5650 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
inet6 addr: X.X.X.X/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:3324 errors:0 dropped:0 overruns:0 frame:0
TX packets:3275 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:39211842 (39.2 MB) TX bytes:515346 (515.3 KB)
=========================================================================
Link Statistics
=========================================================================
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode
DEFAULT group default qlen 1
link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
3060239409 523619 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3060239409 523619 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 0
2: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP
mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
551827315 387194 0 0 0 4
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
3952939 5201 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
3: eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc mq state
DOWN mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 1
4: eth3: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc mq state
DOWN mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 1
5: eth2: <BROADCAST,MULTICAST,NOARP,PROMISC,UP,LOWER_UP> mtu 1500 qdisc
mq state UP mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
7121289138 21238598 0 1026 0 1459
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
0 0 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 4
6: enp0s29f1u2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
pfifo_fast state UNKNOWN mode DEFAULT group default qlen 1000
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
17697 272 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
648 8 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 0
7: docker0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue
state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
4840756 1002 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
134870 1041 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
8: br-caf319787969: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
RX: bytes packets errors dropped overrun mcast
84 3 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
648 8 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
10: veth3fd2127@if9: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 0
RX: bytes packets errors dropped overrun mcast
1623300 330 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
31774 418 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
12: veth3fe5650@if11: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master br-caf319787969 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 0
RX: bytes packets errors dropped overrun mcast
39211842 3324 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
515346 3275 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
14: veth7c4454a@if13: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 1
RX: bytes packets errors dropped overrun mcast
2730 55 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
4302 67 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
16: vethc098e8d@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master br-caf319787969 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 1
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
914 13 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
18: veth6a2b3a5@if17: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 2
RX: bytes packets errors dropped overrun mcast
3228754 617 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
101046 586 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
20: vethc83ac4e@if19: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master br-caf319787969 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 2
RX: bytes packets errors dropped overrun mcast
180735 1244 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
1051753 1123 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
22: vetha0f3346@if21: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 3
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
690 9 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
24: vethdeba8ab@if23: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master br-caf319787969 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 3
RX: bytes packets errors dropped overrun mcast
142641 556 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
145410 441 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
26: veth717901c@if25: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master docker0 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 4
RX: bytes packets errors dropped overrun mcast
0 0 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
690 9 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
28: veth57c384b@if27: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc
noqueue master br-caf319787969 state UP mode DEFAULT group default
link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM link-netnsid 4
RX: bytes packets errors dropped overrun mcast
190674 1459 0 0 0 0
RX errors: length crc frame fifo missed
0 0 0 0 0
TX: bytes packets errors dropped carrier collsns
38016833 1789 0 0 0 0
TX errors: aborted fifo window heartbeat transns
0 0 0 0 2
=========================================================================
Disk Usage
=========================================================================
Filesystem Size Used Avail Use% Mounted on
udev 14G 0 14G 0% /dev
tmpfs 2.8G 9.8M 2.8G 1% /run
/dev/sda2 3.6T 410G 3.0T 12% /
tmpfs 14G 0 14G 0% /dev/shm
tmpfs 5.0M 0 5.0M 0% /run/lock
tmpfs 14G 0 14G 0% /sys/fs/cgroup
/dev/sda1 511M 3.4M 508M 1% /boot/efi
cgmfs 100K 0 100K 0% /run/cgmanager/fs
tmpfs 2.8G 0 2.8G 0% /run/user/1001
overlay 3.6T 410G 3.0T 12%
/var/lib/docker/overlay2/714b37fc60d1c6a6a6090528374073c4c84743a42b5287063f06ef3f9dd1bed5/merged
shm 64M 0 64M 0%
/var/lib/docker/containers/dedab55550d6725f146f0bcb44707f2e95b6c1498c39f23e59ce6425341e720c/mounts/shm
overlay 3.6T 410G 3.0T 12%
/var/lib/docker/overlay2/35af56fd7b0e2acbbf194f57e61c24d97325c726ed06fe9853c6ac5645342a6d/merged
shm 64M 0 64M 0%
/var/lib/docker/containers/aa36a4df37f24c70474c9513a760f4f9c56281751dc548d794ee4ca30457ae19/mounts/shm
tmpfs 2.8G 0 2.8G 0% /run/user/1000
overlay 3.6T 410G 3.0T 12%
/var/lib/docker/overlay2/9b194d23c7900a1862d1c8af1a55ff26d00b2c8cc6bd71bf3f6fc11ca737457f/merged
shm 64M 0 64M 0%
/var/lib/docker/containers/de692ea276b0fe332ebde3909b069245e61abb3c048c3de4050a03c8094b92d6/mounts/shm
overlay 3.6T 410G 3.0T 12%
/var/lib/docker/overlay2/0d11537739a88abb4aced9ebb33ecb01396e58fa5c72a77ed3bd87482fb8773b/merged
shm 64M 0 64M 0%
/var/lib/docker/containers/6d3d8f5e3f29d6c3fc014cad7022dc697e283840eeb66fe3a031f8901aa46f80/mounts/shm
overlay 3.6T 410G 3.0T 12%
/var/lib/docker/overlay2/e635efe4a34c0925f21512794269af0778a1bfd6dee69f4fba214589606cef01/merged
shm 64M 0 64M 0%
/var/lib/docker/containers/11370449dde1a1a60fbc5a9367b737aba2fafdd5901e9a345030668f0e28778d/mounts/shm
=========================================================================
Network Sockets
=========================================================================
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
mongod 1390 mongodb 8u IPv4 10024 0t0 TCP
X.X.X.X:27017 (LISTEN)
mongod 1390 mongodb 15u IPv4 22854 0t0 TCP
X.X.X.X:27017->X.X.X.X:35472 (ESTABLISHED)
mongod 1390 mongodb 16u IPv4 10222 0t0 TCP
X.X.X.X:27017->X.X.X.X:35474 (ESTABLISHED)
mongod 1390 mongodb 17u IPv4 29796 0t0 TCP
X.X.X.X:27017->X.X.X.X:35658 (ESTABLISHED)
mongod 1390 mongodb 18u IPv4 28341 0t0 TCP
X.X.X.X:27017->X.X.X.X:35660 (ESTABLISHED)
syslog-ng 1394 root 8u IPv4 24712 0t0 TCP *:514 (LISTEN)
syslog-ng 1394 root 9u IPv4 24713 0t0 UDP *:514
node 1549 SO-user 10u IPv4 26421 0t0 TCP
X.X.X.X:35658->X.X.X.X:27017 (ESTABLISHED)
node 1549 SO-user 11u IPv4 26468 0t0 TCP
X.X.X.X:35660->X.X.X.X:27017 (ESTABLISHED)
node 1549 SO-user 12u IPv4 29306 0t0 TCP *:1800 (LISTEN)
nfcapd 1668 root 4u IPv4 19696 0t0 UDP *:2055
mysqld 1785 mysql 18u IPv4 24852 0t0 TCP X.X.X.X:3306
(LISTEN)
rwflowpac 1830 root 6u IPv4 20620 0t0 UDP X.X.X.X:2056
sshd 1860 root 3u IPv4 23640 0t0 TCP *:ssh_port
(LISTEN)
sshd 1860 root 4u IPv6 23642 0t0 TCP *:ssh_port
(LISTEN)
ossec-rem 1961 ossecr 4u IPv4 22769 0t0 UDP *:1514
ntop 1966 ntop 2u IPv4 19804 0t0 TCP *:3000 (LISTEN)
apache2 1972 root 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2027 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2027 www-data 17u IPv4 95412 0t0 TCP
X.X.X.X:59568->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2027 www-data 18u IPv4 92709 0t0 TCP
X.X.X.X:59636->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2027 www-data 19u IPv4 241686 0t0 TCP
X.X.X.X:59656->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2027 www-data 20u IPv4 232027 0t0 TCP
X.X.X.X:59704->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2028 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2028 www-data 17u IPv4 231952 0t0 TCP
X.X.X.X:59434->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2028 www-data 18u IPv4 235660 0t0 TCP
X.X.X.X:59606->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2029 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2029 www-data 17u IPv4 49034 0t0 TCP
X.X.X.X:59372->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2029 www-data 18u IPv4 92690 0t0 TCP
X.X.X.X:59618->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2029 www-data 19u IPv4 92739 0t0 TCP
X.X.X.X:59692->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2030 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2030 www-data 17u IPv4 144739 0t0 TCP
X.X.X.X:59414->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2030 www-data 18u IPv4 95420 0t0 TCP
X.X.X.X:59580->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2030 www-data 19u IPv4 95426 0t0 TCP
X.X.X.X:59588->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2030 www-data 20u IPv4 233118 0t0 TCP
X.X.X.X:59660->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2031 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 2031 www-data 17u IPv4 95439 0t0 TCP
X.X.X.X:59612->X.X.X.X:5601 (CLOSE_WAIT)
apache2 2031 www-data 18u IPv4 92759 0t0 TCP
X.X.X.X:59720->X.X.X.X:5601 (CLOSE_WAIT)
netdata 2422 netdata 3u IPv4 14232 0t0 TCP *:19999 (LISTEN)
netdata 2422 netdata 4u IPv6 14233 0t0 TCP *:19999 (LISTEN)
netdata 2422 netdata 10u IPv6 10098 0t0 UDP [X.X.X.X]:8125
netdata 2422 netdata 15u IPv4 10099 0t0 UDP X.X.X.X:8125
netdata 2422 netdata 16u IPv6 10103 0t0 TCP
[X.X.X.X]:8125 (LISTEN)
netdata 2422 netdata 17u IPv4 10104 0t0 TCP X.X.X.X:8125
(LISTEN)
python 2469 netdata 3u IPv4 21785 0t0 TCP
X.X.X.X:35472->X.X.X.X:27017 (ESTABLISHED)
python 2469 netdata 4u IPv4 28282 0t0 TCP
X.X.X.X:35474->X.X.X.X:27017 (ESTABLISHED)
bro 2917 SO-user 4u IPv4 21804 0t0 UDP
X.X.X.X:39378->X.X.X.X:53
bro 3259 SO-user 0u IPv4 23039 0t0 TCP *:47761
(LISTEN)
bro 3259 SO-user 1u IPv6 23040 0t0 TCP *:47761
(LISTEN)
bro 3259 SO-user 2u IPv4 23329 0t0 TCP
X.X.X.X:47761->X.X.X.X:44372 (ESTABLISHED)
bro 3259 SO-user 4u IPv4 21804 0t0 UDP
X.X.X.X:39378->X.X.X.X:53
bro 3259 SO-user 14u IPv4 24422 0t0 TCP
X.X.X.X:47761->X.X.X.X:44376 (ESTABLISHED)
bro 3259 SO-user 19u IPv4 24425 0t0 TCP
X.X.X.X:47761->X.X.X.X:44378 (ESTABLISHED)
bro 3259 SO-user 24u IPv4 21194 0t0 TCP
X.X.X.X:47761->X.X.X.X:44384 (ESTABLISHED)
bro 3259 SO-user 29u IPv4 21197 0t0 TCP
X.X.X.X:47761->X.X.X.X:44386 (ESTABLISHED)
bro 3259 SO-user 34u IPv4 31962 0t0 TCP
X.X.X.X:47761->X.X.X.X:44392 (ESTABLISHED)
bro 3259 SO-user 39u IPv4 33925 0t0 TCP
X.X.X.X:47761->X.X.X.X:44396 (ESTABLISHED)
bro 3259 SO-user 44u IPv4 24429 0t0 TCP
X.X.X.X:47761->X.X.X.X:44398 (ESTABLISHED)
bro 3706 SO-user 4u IPv4 24125 0t0 UDP
X.X.X.X:36667->X.X.X.X:53
bro 3782 SO-user 0u IPv4 20095 0t0 TCP
X.X.X.X:44372->X.X.X.X:47761 (ESTABLISHED)
bro 3782 SO-user 4u IPv4 24125 0t0 UDP
X.X.X.X:36667->X.X.X.X:53
bro 3782 SO-user 12u IPv4 20100 0t0 TCP *:47762
(LISTEN)
bro 3782 SO-user 13u IPv6 20101 0t0 TCP *:47762
(LISTEN)
bro 3782 SO-user 14u IPv4 24419 0t0 TCP
X.X.X.X:47762->X.X.X.X:47246 (ESTABLISHED)
bro 3782 SO-user 19u IPv4 29538 0t0 TCP
X.X.X.X:47762->X.X.X.X:47252 (ESTABLISHED)
bro 3782 SO-user 24u IPv4 30209 0t0 TCP
X.X.X.X:47762->X.X.X.X:47254 (ESTABLISHED)
bro 3782 SO-user 29u IPv4 31072 0t0 TCP
X.X.X.X:47762->X.X.X.X:47260 (ESTABLISHED)
bro 3782 SO-user 34u IPv4 31971 0t0 TCP
X.X.X.X:47762->X.X.X.X:47262 (ESTABLISHED)
bro 3782 SO-user 39u IPv4 18374 0t0 TCP
X.X.X.X:47762->X.X.X.X:47266 (ESTABLISHED)
bro 3782 SO-user 44u IPv4 24432 0t0 TCP
X.X.X.X:47762->X.X.X.X:47272 (ESTABLISHED)
bro 5114 SO-user 4u IPv4 31058 0t0 UDP
X.X.X.X:33578->X.X.X.X:53
bro 5121 SO-user 4u IPv4 32909 0t0 UDP
X.X.X.X:59409->X.X.X.X:53
bro 5125 SO-user 4u IPv4 28597 0t0 UDP
X.X.X.X:49472->X.X.X.X:53
bro 5130 SO-user 4u IPv4 27169 0t0 UDP
X.X.X.X:47745->X.X.X.X:53
bro 5132 SO-user 4u IPv4 18366 0t0 UDP
X.X.X.X:53591->X.X.X.X:53
bro 5134 SO-user 4u IPv4 30185 0t0 UDP
X.X.X.X:34461->X.X.X.X:53
bro 5135 SO-user 4u IPv4 28601 0t0 UDP
X.X.X.X:59658->X.X.X.X:53
bro 5232 SO-user 0u IPv4 21184 0t0 TCP
X.X.X.X:47246->X.X.X.X:47762 (ESTABLISHED)
bro 5232 SO-user 4u IPv4 28597 0t0 UDP
X.X.X.X:49472->X.X.X.X:53
bro 5232 SO-user 12u IPv4 21187 0t0 TCP
X.X.X.X:44376->X.X.X.X:47761 (ESTABLISHED)
bro 5232 SO-user 17u IPv4 21192 0t0 TCP *:47766
(LISTEN)
bro 5232 SO-user 18u IPv6 21193 0t0 TCP *:47766
(LISTEN)
bro 5233 SO-user 0u IPv4 16354 0t0 TCP
X.X.X.X:44378->X.X.X.X:47761 (ESTABLISHED)
bro 5233 SO-user 4u IPv4 30185 0t0 UDP
X.X.X.X:34461->X.X.X.X:53
bro 5233 SO-user 12u IPv4 16357 0t0 TCP
X.X.X.X:47252->X.X.X.X:47762 (ESTABLISHED)
bro 5233 SO-user 17u IPv4 16362 0t0 TCP *:47765
(LISTEN)
bro 5233 SO-user 18u IPv6 16363 0t0 TCP *:47765
(LISTEN)
bro 5251 SO-user 0u IPv4 27177 0t0 TCP
X.X.X.X:47254->X.X.X.X:47762 (ESTABLISHED)
bro 5251 SO-user 4u IPv4 31058 0t0 UDP
X.X.X.X:33578->X.X.X.X:53
bro 5251 SO-user 12u IPv4 27180 0t0 TCP
X.X.X.X:44384->X.X.X.X:47761 (ESTABLISHED)
bro 5251 SO-user 17u IPv4 27185 0t0 TCP *:47763
(LISTEN)
bro 5251 SO-user 18u IPv6 27186 0t0 TCP *:47763
(LISTEN)
bro 5252 SO-user 0u IPv4 27187 0t0 TCP
X.X.X.X:44386->X.X.X.X:47761 (ESTABLISHED)
bro 5252 SO-user 4u IPv4 18366 0t0 UDP
X.X.X.X:53591->X.X.X.X:53
bro 5252 SO-user 12u IPv4 27190 0t0 TCP
X.X.X.X:47260->X.X.X.X:47762 (ESTABLISHED)
bro 5252 SO-user 17u IPv4 27195 0t0 TCP *:47768
(LISTEN)
bro 5252 SO-user 18u IPv6 27196 0t0 TCP *:47768
(LISTEN)
bro 5259 SO-user 0u IPv4 31958 0t0 TCP
X.X.X.X:47262->X.X.X.X:47762 (ESTABLISHED)
bro 5259 SO-user 4u IPv4 27169 0t0 UDP
X.X.X.X:47745->X.X.X.X:53
bro 5259 SO-user 12u IPv4 31961 0t0 TCP
X.X.X.X:44392->X.X.X.X:47761 (ESTABLISHED)
bro 5259 SO-user 17u IPv4 31969 0t0 TCP *:47769
(LISTEN)
bro 5259 SO-user 18u IPv6 31970 0t0 TCP *:47769
(LISTEN)
bro 5264 SO-user 0u IPv4 28614 0t0 TCP
X.X.X.X:47266->X.X.X.X:47762 (ESTABLISHED)
bro 5264 SO-user 4u IPv4 28601 0t0 UDP
X.X.X.X:59658->X.X.X.X:53
bro 5264 SO-user 12u IPv4 28617 0t0 TCP
X.X.X.X:44396->X.X.X.X:47761 (ESTABLISHED)
bro 5264 SO-user 17u IPv4 28622 0t0 TCP *:47767
(LISTEN)
bro 5264 SO-user 18u IPv6 28623 0t0 TCP *:47767
(LISTEN)
bro 5278 SO-user 0u IPv4 31087 0t0 TCP
X.X.X.X:44398->X.X.X.X:47761 (ESTABLISHED)
bro 5278 SO-user 4u IPv4 32909 0t0 UDP
X.X.X.X:59409->X.X.X.X:53
bro 5278 SO-user 12u IPv4 31090 0t0 TCP
X.X.X.X:47272->X.X.X.X:47762 (ESTABLISHED)
bro 5278 SO-user 17u IPv4 31095 0t0 TCP *:47764
(LISTEN)
bro 5278 SO-user 18u IPv6 31096 0t0 TCP *:47764
(LISTEN)
ntpd 5581 ntp 16u IPv6 29609 0t0 UDP *:123
ntpd 5581 ntp 17u IPv4 29612 0t0 UDP *:123
ntpd 5581 ntp 18u IPv4 29618 0t0 UDP X.X.X.X:123
ntpd 5581 ntp 19u IPv4 29620 0t0 UDP X.X.X.X:123
ntpd 5581 ntp 20u IPv6 29622 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 21u IPv6 29624 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 25u IPv6 24539 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 26u IPv4 33461 0t0 UDP X.X.X.X:123
ntpd 5581 ntp 27u IPv4 33463 0t0 UDP X.X.X.X:123
ntpd 5581 ntp 28u IPv6 33468 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 29u IPv6 33470 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 30u IPv6 33472 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 31u IPv6 33474 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 32u IPv6 33476 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 33u IPv6 31662 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 34u IPv6 50550 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 35u IPv6 50552 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 36u IPv6 50554 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 37u IPv6 50556 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 38u IPv6 50558 0t0 UDP [X.X.X.X]:123
ntpd 5581 ntp 39u IPv6 71945 0t0 UDP [X.X.X.X]:123
apache2 5622 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 5622 www-data 17u IPv4 236690 0t0 TCP
X.X.X.X:59574->X.X.X.X:5601 (CLOSE_WAIT)
apache2 5763 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 5763 www-data 17u IPv4 92678 0t0 TCP
X.X.X.X:59602->X.X.X.X:5601 (CLOSE_WAIT)
apache2 5763 www-data 18u IPv4 95484 0t0 TCP
X.X.X.X:59644->X.X.X.X:5601 (CLOSE_WAIT)
apache2 5763 www-data 19u IPv4 233221 0t0 TCP
X.X.X.X:59710->X.X.X.X:5601 (CLOSE_WAIT)
tclsh 5866 SO-user 3u IPv4 35095 0t0 TCP
X.X.X.X:8301 (LISTEN)
tclsh 5866 SO-user 5u IPv4 244961 0t0 TCP
X.X.X.X:8301->X.X.X.X:49094 (ESTABLISHED)
tclsh 5952 SO-user 3u IPv4 31341 0t0 TCP
X.X.X.X:8302 (LISTEN)
tclsh 5952 SO-user 5u IPv4 238432 0t0 TCP
X.X.X.X:8302->X.X.X.X:42894 (ESTABLISHED)
tclsh 6013 SO-user 3u IPv4 20423 0t0 TCP
X.X.X.X:8303 (LISTEN)
tclsh 6013 SO-user 5u IPv4 246152 0t0 TCP
X.X.X.X:8303->X.X.X.X:33444 (ESTABLISHED)
tclsh 6193 SO-user 3u IPv4 36487 0t0 TCP
X.X.X.X:8304 (LISTEN)
tclsh 6193 SO-user 5u IPv4 246188 0t0 TCP
X.X.X.X:8304->X.X.X.X:34668 (ESTABLISHED)
tclsh 6239 SO-user 3u IPv4 34086 0t0 TCP
X.X.X.X:8305 (LISTEN)
tclsh 6239 SO-user 5u IPv4 244845 0t0 TCP
X.X.X.X:8305->X.X.X.X:33734 (ESTABLISHED)
tclsh 6361 SO-user 3u IPv4 33233 0t0 TCP
X.X.X.X:8306 (LISTEN)
tclsh 6361 SO-user 5u IPv4 239390 0t0 TCP
X.X.X.X:8306->X.X.X.X:58032 (ESTABLISHED)
tclsh 6428 SO-user 3u IPv4 20463 0t0 TCP
X.X.X.X:8307 (LISTEN)
tclsh 6428 SO-user 5u IPv4 250925 0t0 TCP
X.X.X.X:8307->X.X.X.X:54582 (ESTABLISHED)
barnyard2 6751 SO-user 3u IPv4 243902 0t0 TCP
X.X.X.X:49094->X.X.X.X:8301 (ESTABLISHED)
barnyard2 6780 SO-user 3u IPv4 232191 0t0 TCP
X.X.X.X:42894->X.X.X.X:8302 (ESTABLISHED)
barnyard2 6804 SO-user 3u IPv4 246151 0t0 TCP
X.X.X.X:33444->X.X.X.X:8303 (ESTABLISHED)
barnyard2 6826 SO-user 3u IPv4 246187 0t0 TCP
X.X.X.X:34668->X.X.X.X:8304 (ESTABLISHED)
barnyard2 6845 SO-user 3u IPv4 244844 0t0 TCP
X.X.X.X:33734->X.X.X.X:8305 (ESTABLISHED)
barnyard2 6866 SO-user 3u IPv4 95664 0t0 TCP
X.X.X.X:58032->X.X.X.X:8306 (ESTABLISHED)
barnyard2 6887 SO-user 3u IPv4 250924 0t0 TCP
X.X.X.X:54582->X.X.X.X:8307 (ESTABLISHED)
sshd 7012 root 3u IPv4 42142 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:16222 (ESTABLISHED)
docker-pr 7041 root 4u IPv4 32375 0t0 TCP X.X.X.X:9300
(LISTEN)
docker-pr 7078 root 4u IPv4 32385 0t0 TCP X.X.X.X:9200
(LISTEN)
docker-pr 7415 root 4u IPv6 39223 0t0 TCP *:9600 (LISTEN)
docker-pr 7456 root 4u IPv6 44068 0t0 TCP *:6053 (LISTEN)
docker-pr 7474 root 4u IPv6 45201 0t0 TCP *:6052 (LISTEN)
docker-pr 7488 root 4u IPv6 45228 0t0 TCP *:6051 (LISTEN)
docker-pr 7509 root 4u IPv6 46141 0t0 TCP *:6050 (LISTEN)
docker-pr 7522 root 4u IPv6 45249 0t0 TCP *:5044 (LISTEN)
sshd 7928 SO-user 3u IPv4 42142 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:16222 (ESTABLISHED)
docker-pr 10340 root 3u IPv4 97377 0t0 TCP
X.X.X.X:5601->X.X.X.X:59372 (FIN_WAIT2)
docker-pr 10340 root 4u IPv4 48106 0t0 TCP X.X.X.X:5601
(LISTEN)
docker-pr 10340 root 6u IPv4 97379 0t0 TCP
X.X.X.X:37246->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 7u IPv4 234296 0t0 TCP
X.X.X.X:5601->X.X.X.X:59414 (FIN_WAIT2)
docker-pr 10340 root 8u IPv4 234298 0t0 TCP
X.X.X.X:37288->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 9u IPv4 240074 0t0 TCP
X.X.X.X:5601->X.X.X.X:59434 (FIN_WAIT2)
docker-pr 10340 root 10u IPv4 240076 0t0 TCP
X.X.X.X:37308->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 12u IPv4 95413 0t0 TCP
X.X.X.X:5601->X.X.X.X:59568 (FIN_WAIT2)
docker-pr 10340 root 13u IPv4 95415 0t0 TCP
X.X.X.X:37442->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 14u IPv4 92648 0t0 TCP
X.X.X.X:5601->X.X.X.X:59574 (FIN_WAIT2)
docker-pr 10340 root 15u IPv4 92650 0t0 TCP
X.X.X.X:37448->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 16u IPv4 92654 0t0 TCP
X.X.X.X:5601->X.X.X.X:59580 (FIN_WAIT2)
docker-pr 10340 root 17u IPv4 92656 0t0 TCP
X.X.X.X:37454->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 18u IPv4 95427 0t0 TCP
X.X.X.X:5601->X.X.X.X:59588 (FIN_WAIT2)
docker-pr 10340 root 19u IPv4 95429 0t0 TCP
X.X.X.X:37462->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 20u IPv4 92679 0t0 TCP
X.X.X.X:5601->X.X.X.X:59602 (FIN_WAIT2)
docker-pr 10340 root 21u IPv4 92681 0t0 TCP
X.X.X.X:37476->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 22u IPv4 235661 0t0 TCP
X.X.X.X:5601->X.X.X.X:59606 (FIN_WAIT2)
docker-pr 10340 root 23u IPv4 235663 0t0 TCP
X.X.X.X:37480->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 24u IPv4 95440 0t0 TCP
X.X.X.X:5601->X.X.X.X:59612 (FIN_WAIT2)
docker-pr 10340 root 25u IPv4 95442 0t0 TCP
X.X.X.X:37486->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 26u IPv4 95443 0t0 TCP
X.X.X.X:5601->X.X.X.X:59618 (FIN_WAIT2)
docker-pr 10340 root 27u IPv4 95445 0t0 TCP
X.X.X.X:37492->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 28u IPv4 92710 0t0 TCP
X.X.X.X:5601->X.X.X.X:59636 (FIN_WAIT2)
docker-pr 10340 root 29u IPv4 92712 0t0 TCP
X.X.X.X:37510->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 30u IPv4 238960 0t0 TCP
X.X.X.X:5601->X.X.X.X:59644 (FIN_WAIT2)
docker-pr 10340 root 31u IPv4 238962 0t0 TCP
X.X.X.X:37518->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 32u IPv4 92722 0t0 TCP
X.X.X.X:5601->X.X.X.X:59650 (FIN_WAIT2)
docker-pr 10340 root 33u IPv4 92724 0t0 TCP
X.X.X.X:37524->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 34u IPv4 241687 0t0 TCP
X.X.X.X:5601->X.X.X.X:59656 (FIN_WAIT2)
docker-pr 10340 root 35u IPv4 241689 0t0 TCP
X.X.X.X:37530->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 36u IPv4 238963 0t0 TCP
X.X.X.X:5601->X.X.X.X:59660 (FIN_WAIT2)
docker-pr 10340 root 37u IPv4 238965 0t0 TCP
X.X.X.X:37534->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 38u IPv4 95515 0t0 TCP
X.X.X.X:5601->X.X.X.X:59692 (FIN_WAIT2)
docker-pr 10340 root 39u IPv4 95516 0t0 TCP
X.X.X.X:5601->X.X.X.X:59694 (FIN_WAIT2)
docker-pr 10340 root 40u IPv4 95518 0t0 TCP
X.X.X.X:37568->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 41u IPv4 239116 0t0 TCP
X.X.X.X:37570->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 42u IPv4 92744 0t0 TCP
X.X.X.X:5601->X.X.X.X:59704 (FIN_WAIT2)
docker-pr 10340 root 43u IPv4 92746 0t0 TCP
X.X.X.X:37578->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 44u IPv4 233222 0t0 TCP
X.X.X.X:5601->X.X.X.X:59710 (FIN_WAIT2)
docker-pr 10340 root 45u IPv4 233224 0t0 TCP
X.X.X.X:37584->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 46u IPv4 92760 0t0 TCP
X.X.X.X:5601->X.X.X.X:59720 (FIN_WAIT2)
docker-pr 10340 root 47u IPv4 92762 0t0 TCP
X.X.X.X:37594->X.X.X.X:5601 (CLOSE_WAIT)
docker-pr 10340 root 48u IPv4 92830 0t0 TCP
X.X.X.X:5601->X.X.X.X:59748 (FIN_WAIT2)
docker-pr 10340 root 49u IPv4 92832 0t0 TCP
X.X.X.X:37622->X.X.X.X:5601 (CLOSE_WAIT)
sshd 17250 root 3u IPv4 141845 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:16538 (ESTABLISHED)
sshd 17397 SO-user 3u IPv4 141845 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:16538 (ESTABLISHED)
apache2 17839 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 17839 www-data 17u IPv4 241756 0t0 TCP
X.X.X.X:59694->X.X.X.X:5601 (CLOSE_WAIT)
apache2 17839 www-data 18u IPv4 95619 0t0 TCP
X.X.X.X:59748->X.X.X.X:5601 (CLOSE_WAIT)
apache2 17845 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 17846 www-data 4u IPv6 15735 0t0 TCP *:443 (LISTEN)
apache2 17846 www-data 17u IPv4 92721 0t0 TCP
X.X.X.X:59650->X.X.X.X:5601 (CLOSE_WAIT)
sshd 23417 root 3u IPv4 255082 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:21516 (ESTABLISHED)
sshd 23418 sshd 3u IPv4 255082 0t0 TCP
X.X.X.X:ssh_port->X.X.X.X:21516 (ESTABLISHED)
=========================================================================
IDS Rules Update
=========================================================================
Mon Oct 22 07:01:01 UTC 2018
Backing up current local_rules.xml file.
Cleaning up local_rules.xml backup files older than 30 days.
Backing up current downloaded.rules file before it gets overwritten.
Cleaning up downloaded.rules backup files older than 30 days.
Backing up current local.rules file before it gets overwritten.
Cleaning up local.rules backup files older than 30 days.
Sleeping for 21 minutes to avoid overwhelming rule sites.
Running PulledPork.
https://github.com/shirkdog/pulledpork
_____ ____
`----,\ )
`--==\\ / PulledPork v0.7.3 - Making signature updates great
again!
`--==\\/
.-~~~~-.Y|\\_ Copyright (C) 2009-2016 JJ Cummings
@_/ / 66\_
cumm...@gmail.com
| \ \ _(")
\ /-| ||'--' Rules give me wings!
\_\ \_\\
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Checking latest MD5 for snortrules-snapshot-2990.tar.gz....
They Match
Done!
Checking latest MD5 for emerging.rules.tar.gz....
They Match
Done!
Checking latest MD5 for community-rules.tar.gz....
No Match
Done
Rules tarball download of community-rules.tar.gz....
They Match
Done!
Enabled 190 flowbits
Enabled 1 flowbits
Done
Writing /etc/nsm/rules/downloaded.rules....
Done
Generating sid-msg.map....
Done
Writing v1 /etc/nsm/rules/sid-msg.map....
Done
Writing /var/log/nsm/sid_changes.log....
Done
Rule Stats...
New:-------0
Deleted:---0
Enabled Rules:----30626
Dropped Rules:----0
Disabled Rules:---29792
Total Rules:------60418
No IP Blacklist Changes
Done
Please review /var/log/nsm/sid_changes.log for additional details
Fly Piggy Fly!
=========================================================================
CPU Usage
=========================================================================
Load average for the last 1, 5, and 15 minutes:
17.52 21.27 13.32
Processing units: 16
If load average is higher than processing units,
then tune until load average is lower than processing units.
top - 14:24:31 up 11 min, 2 users, load average: 17.52, 21.27, 13.32
Tasks: 334 total, 18 running, 316 sleeping, 0 stopped, 0 zombie
%Cpu(s): 82.0 us, 3.6 sy, 0.1 ni, 11.0 id, 1.6 wa, 0.0 hi, 1.7 si,
0.0 st
KiB Mem : 28804520 total, 212328 free, 22723196 used, 5868996 buff/cache
KiB Swap: 16764924 total, 16575972 free, 188952 used. 5511632 avail Mem
%CPU %MEM COMMAND
132 9.4 /bin/java -Xms4000m -Xmx4000m -XX:+UseParNewGC
-XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75
-XX:+UseCMSInitiatingOccupancyOnly -Djava.awt.headless=true
-Dfile.encoding=UTF-8 -Djruby.compile.invokedynamic=true
-Djruby.jit.threshold=0 -XX:+HeapDumpOnOutOfMemoryError
-Djava.security.egd=file:/dev/urandom -cp
/usr/share/logstash/logstash-core/lib/jars/animal-sniffer-annotations-1.14.jar:/usr/share/logstash/logstash-core/lib/jars/commons-codec-1.11.jar:/usr/share/logstash/logstash-core/lib/jars/commons-compiler-3.0.8.jar:/usr/share/logstash/logstash-core/lib/jars/error_prone_annotations-2.0.18.jar:/usr/share/logstash/logstash-core/lib/jars/google-java-format-1.1.jar:/usr/share/logstash/logstash-core/lib/jars/gradle-license-report-0.7.1.jar:/usr/share/logstash/logstash-core/lib/jars/guava-22.0.jar:/usr/share/logstash/logstash-core/lib/jars/j2objc-annotations-1.1.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-annotations-2.9.5.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-core-2.9.5.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-databind-2.9.5.jar:/usr/share/logstash/logstash-core/lib/jars/jackson-dataformat-cbor-2.9.5.jar:/usr/share/logstash/logstash-core/lib/jars/janino-3.0.8.jar:/usr/share/logstash/logstash-core/lib/jars/jruby-complete-X.X.X.X.jar:/usr/share/logstash/logstash-core/lib/jars/jsr305-1.3.9.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-api-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-core-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/log4j-slf4j-impl-2.9.1.jar:/usr/share/logstash/logstash-core/lib/jars/logstash-core.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.commands-3.6.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.contenttype-3.4.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.expressions-3.4.300.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.filesystem-1.3.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.jobs-3.5.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.resources-3.7.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.core.runtime-3.7.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.app-1.3.100.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.common-3.6.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.preferences-3.4.1.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.equinox.registry-3.5.101.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.jdt.core-3.10.0.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.osgi-3.7.1.jar:/usr/share/logstash/logstash-core/lib/jars/org.eclipse.text-3.5.101.jar:/usr/share/logstash/logstash-core/lib/jars/slf4j-api-1.7.25.jar
org.logstash.Logstash
80.5 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-7 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
80.5 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-3 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
80.4 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-1 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
80.3 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-5 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
80.0 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-2 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
79.7 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-4 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
79.7 2.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-6 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
78.1 1.1 tclsh /usr/bin/SO-userd -c
/etc/nsm/securityonion/SO-userd.conf -a
/etc/nsm/securityonion/autocat.conf -g
/etc/nsm/securityonion/SO-userd.queries -A
/etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
52.5 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local
-p manager local.bro broctl base/frameworks/cluster local-manager.bro
broctl/auto
49.5 3.5 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-2
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-2.stats -U
--snaplen 1524
48.4 3.6 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-7
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-7.stats -U
--snaplen 1524
47.6 3.6 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-5
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-5.stats -U
--snaplen 1524
46.0 3.5 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-1
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-1.stats -U
--snaplen 1524
45.5 3.6 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-4
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-4.stats -U
--snaplen 1524
43.1 3.5 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-3
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-3.stats -U
--snaplen 1524
40.4 3.6 snort -c /etc/nsm/41-184-204-74-eth2/snort.conf -u SO-user -g
SO-user -i eth2 -l /nsm/sensor_data/41-184-204-74-eth2/snort-6
--perfmon-file /nsm/sensor_data/41-184-204-74-eth2/snort-6.stats -U
--snaplen 1524
39.7 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-7.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-7 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-7 -i
41-184-204-74-eth2-7 -U
39.4 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-4.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-4 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-4 -i
41-184-204-74-eth2-4 -U
39.1 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-1.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-1 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-1 -i
41-184-204-74-eth2-1 -U
38.5 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-3.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-3 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-3 -i
41-184-204-74-eth2-3 -U
35.7 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-5.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-5 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-5 -i
41-184-204-74-eth2-5 -U
35.3 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-2.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-2 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-2 -i
41-184-204-74-eth2-2 -U
33.9 0.0 barnyard2 -c /etc/nsm/41-184-204-74-eth2/barnyard2-6.conf -u
SO-user -g SO-user -d /nsm/sensor_data/41-184-204-74-eth2/snort-6 -f
snort.unified2 -w /etc/nsm/41-184-204-74-eth2/barnyard2.waldo-6 -i
41-184-204-74-eth2-6 -U
33.2 22.7 /usr/lib/jvm/jre-1.8.0-openjdk/bin/java -Xms4104m -Xmx4104m
-XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75
-XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -Xss1m
-Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true
-XX:-OmitStackTraceInFastThrow -Dio.netty.noUnsafe=true
-Dio.netty.noKeySetOptimization=true
-Dio.netty.recycler.maxCapacityPerThread=0
-Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true
-Djava.io.tmpdir=/tmp/elasticsearch.RueHJ3rH
-XX:+HeapDumpOnOutOfMemoryError -XX:+PrintGCDetails
-XX:+PrintGCDateStamps -XX:+PrintTenuringDistribution
-XX:+PrintGCApplicationStoppedTime -Xloggc:logs/gc.log
-XX:+UseGCLogFileRotation -XX:NumberOfGCLogFiles=32
-XX:GCLogFileSize=64m -Des.cgroups.hierarchy.override=/
-Des.path.home=/usr/share/elasticsearch
-Des.path.conf=/usr/share/elasticsearch/config
-Des.distribution.flavor=oss -Des.distribution.type=tar -cp
/usr/share/elasticsearch/lib/* org.elasticsearch.bootstrap.Elasticsearch
-Ecluster.name=SO-server -Ebootstrap.memory_lock=true
-Etransport.host=X.X.X.X -Ehttp.host=X.X.X.X
11.1 0.0 /var/ossec/bin/ossec-syscheckd
8.1 0.0 /usr/sbin/syslog-ng -F
6.0 0.0 /var/ossec/bin/wazuh-modulesd
4.9 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local
-p manager local.bro broctl base/frameworks/cluster local-manager.bro
broctl/auto
3.5 0.5 /usr/sbin/mysqld
3.3 0.0 /usr/libexec/netdata/plugins.d/apps.plugin 1
2.8 0.4 /usr/share/kibana/bin/../node/bin/node --no-warnings
/usr/share/kibana/bin/../src/cli --cpu.cgroup.path.override=/
--cpuacct.cgroup.path.override=/
--kibana.defaultAppId=dashboard/94b52620-342a-11e7-9d52-4f090484f59e
1.7 0.0 /sbin/init
1.7 0.0 /var/ossec/bin/ossec-analysisd
1.7 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local
-p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
1.5 0.3 /usr/sbin/netdata -P /var/run/netdata/netdata.pid -D -W set
global process scheduling policy keep -W set global OOM score keep
1.5 0.2 /usr/bin/python /usr/libexec/netdata/plugins.d/python.d.plugin 1
0.9 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-6 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.9 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-5 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.9 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-2 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.8 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-4 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.8 0.5 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-3 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.8 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-1 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.8 0.6 /opt/bro/bin/bro -i eth2 -U .status -p broctl -p broctl-live
-p local -p 41-184-204-74-eth2-7 local.bro broctl
base/frameworks/cluster local-worker.bro broctl/auto
0.6 0.1 python -m elastalert.elastalert --config
/etc/elastalert/conf/elastalert_config.yaml --verbose
0.5 0.2 /usr/bin/mongod --config /etc/mongodb.conf
0.5 0.1 docker-containerd --config
/var/run/docker/containerd/containerd.toml
0.4 0.1 /usr/bin/dockerd -H fd://
0.3 0.0 bash /usr/libexec/netdata/plugins.d/tc-qos-helper.sh 1
0.2 0.0 [rcu_sched]
0.2 0.0 [ksoftirqd/5]
0.2 0.2 /home/SO-user/.nvm/versions/node/v8.9.3/bin/node
/home/SO-user/FlowBAT/private/bundle/main.js
0.1 0.0 [kswapd0]
0.1 0.0 [kswapd1]
0.1 0.0 /var/ossec/bin/ossec-remoted
0.1 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local
-p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
0.1 0.0 /usr/bin/python /usr/bin/supervisord -c
/etc/elastalert/conf/elastalert_supervisord.conf -n
0.1 0.0 sshd: root [priv]
0.0 0.0 [kthreadd]
0.0 0.0 [ksoftirqd/0]
0.0 0.0 [kworker/0:0H]
0.0 0.0 [rcu_bh]
0.0 0.0 [migration/0]
0.0 0.0 [watchdog/0]
0.0 0.0 [watchdog/1]
0.0 0.0 [migration/1]
0.0 0.0 [ksoftirqd/1]
0.0 0.0 [kworker/1:0H]
0.0 0.0 [watchdog/2]
0.0 0.0 [migration/2]
0.0 0.0 [ksoftirqd/2]
0.0 0.0 [kworker/2:0H]
0.0 0.0 [watchdog/3]
0.0 0.0 [migration/3]
0.0 0.0 [ksoftirqd/3]
0.0 0.0 [kworker/3:0H]
0.0 0.0 [watchdog/4]
0.0 0.0 [migration/4]
0.0 0.0 [ksoftirqd/4]
0.0 0.0 [kworker/4:0H]
0.0 0.0 [watchdog/5]
0.0 0.0 [migration/5]
0.0 0.0 [kworker/5:0H]
0.0 0.0 [watchdog/6]
0.0 0.0 [migration/6]
0.0 0.0 [ksoftirqd/6]
0.0 0.0 [kworker/6:0H]
0.0 0.0 [watchdog/7]
0.0 0.0 [migration/7]
0.0 0.0 [ksoftirqd/7]
0.0 0.0 [kworker/7:0H]
0.0 0.0 [watchdog/8]
0.0 0.0 [migration/8]
0.0 0.0 [ksoftirqd/8]
0.0 0.0 [kworker/8:0H]
0.0 0.0 [watchdog/9]
0.0 0.0 [migration/9]
0.0 0.0 [ksoftirqd/9]
0.0 0.0 [kworker/9:0H]
0.0 0.0 [watchdog/10]
0.0 0.0 [migration/10]
0.0 0.0 [ksoftirqd/10]
0.0 0.0 [kworker/10:0]
0.0 0.0 [kworker/10:0H]
0.0 0.0 [watchdog/11]
0.0 0.0 [migration/11]
0.0 0.0 [ksoftirqd/11]
0.0 0.0 [kworker/11:0H]
0.0 0.0 [watchdog/12]
0.0 0.0 [migration/12]
0.0 0.0 [ksoftirqd/12]
0.0 0.0 [kworker/12:0H]
0.0 0.0 [watchdog/13]
0.0 0.0 [migration/13]
0.0 0.0 [ksoftirqd/13]
0.0 0.0 [kworker/13:0]
0.0 0.0 [kworker/13:0H]
0.0 0.0 [watchdog/14]
0.0 0.0 [migration/14]
0.0 0.0 [ksoftirqd/14]
0.0 0.0 [kworker/14:0H]
0.0 0.0 [watchdog/15]
0.0 0.0 [migration/15]
0.0 0.0 [ksoftirqd/15]
0.0 0.0 [kworker/15:0H]
0.0 0.0 [kdevtmpfs]
0.0 0.0 [netns]
0.0 0.0 [perf]
0.0 0.0 [khungtaskd]
0.0 0.0 [writeback]
0.0 0.0 [ksmd]
0.0 0.0 [khugepaged]
0.0 0.0 [crypto]
0.0 0.0 [kintegrityd]
0.0 0.0 [bioset]
0.0 0.0 [kblockd]
0.0 0.0 [ata_sff]
0.0 0.0 [md]
0.0 0.0 [devfreq_wq]
0.0 0.0 [kworker/u49:1]
0.0 0.0 [kworker/0:1]
0.0 0.0 [vmstat]
0.0 0.0 [fsnotify_mark]
0.0 0.0 [ecryptfs-kthrea]
0.0 0.0 [kthrotld]
0.0 0.0 [acpi_thermal_pm]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [kworker/7:1]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [bioset]
0.0 0.0 [scsi_eh_0]
0.0 0.0 [scsi_tmf_0]
0.0 0.0 [scsi_eh_1]
0.0 0.0 [scsi_tmf_1]
0.0 0.0 [kworker/u50:2]
0.0 0.0 [scsi_eh_2]
0.0 0.0 [scsi_tmf_2]
0.0 0.0 [scsi_eh_3]
0.0 0.0 [scsi_tmf_3]
0.0 0.0 [kworker/u50:3]
0.0 0.0 [kworker/6:1]
0.0 0.0 [kworker/4:1]
0.0 0.0 [kworker/5:1]
0.0 0.0 [kworker/12:1]
0.0 0.0 [kworker/15:1]
0.0 0.0 [kworker/2:1]
0.0 0.0 [kworker/1:1]
0.0 0.0 [kworker/9:1]
0.0 0.0 [kworker/14:1]
0.0 0.0 [kworker/4:2]
0.0 0.0 [kworker/13:1]
0.0 0.0 [ipv6_addrconf]
0.0 0.0 [deferwq]
0.0 0.0 [kworker/u48:1]
0.0 0.0 [charger_manager]
0.0 0.0 [kworker/11:1]
0.0 0.0 [kworker/8:1]
0.0 0.0 [scsi_eh_4]
0.0 0.0 [scsi_tmf_4]
0.0 0.0 [kpsmoused]
0.0 0.0 [kworker/0:2]
0.0 0.0 [bioset]
0.0 0.0 [ixgbe]
0.0 0.0 [jbd2/sda2-8]
0.0 0.0 [ext4-rsv-conver]
0.0 0.0 [kworker/4:1H]
0.0 0.0 [kworker/12:1H]
0.0 0.0 [kauditd]
0.0 0.0 /lib/systemd/systemd-journald
0.0 0.0 [kworker/14:2]
0.0 0.0 [kworker/u49:2]
0.0 0.0 [kworker/6:2]
0.0 0.0 /lib/systemd/systemd-udevd
0.0 0.0 [kworker/1:2]
0.0 0.0 [kworker/0:1H]
0.0 0.0 [kworker/3:2]
0.0 0.0 [kworker/5:2]
0.0 0.0 [edac-poller]
0.0 0.0 [kipmi0]
0.0 0.0 [kvm-irqfd-clean]
0.0 0.0 [kworker/9:2]
0.0 0.0 [kworker/2:2]
0.0 0.0 /usr/sbin/atd -f
0.0 0.0 /usr/lib/accountsservice/accounts-daemon
0.0 0.0 /usr/sbin/cron -f
0.0 0.0 /usr/bin/dbus-daemon --system --address=systemd: --nofork
--nopidfile --systemd-activation
0.0 0.0 /sbin/cgmanager -m name=systemd
0.0 0.0 /lib/systemd/systemd-logind
0.0 0.0 /usr/sbin/acpid
0.0 0.0 [kworker/3:1H]
0.0 0.0 /usr/bin/lxcfs /var/lib/lxcfs/
0.0 0.0 /usr/sbin/irqbalance --pid=/var/run/irqbalance.pid
0.0 0.0 [kworker/6:1H]
0.0 0.0 [kworker/7:2]
0.0 0.0 /usr/bin/nfcapd -D -l /var/cache/nfdump -P
/var/run/nfcapd.pid -p 2055
0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
0.0 0.0 /usr/local/sbin/rwflowpack --compression-method=best
--sensor-configuration=/data/sensors.conf
--site-config-file=/data/silk.conf --output-mode=local-storage
--root-directory=/data/ --pidfile=/var/log/rwflowpack.pid
--log-level=info --log-directory=/var/log --log-basename=rwflowpack
0.0 0.0 /sbin/agetty --noclear tty1 linux
0.0 0.0 [kworker/10:1H]
0.0 0.0 /usr/sbin/sshd -D
0.0 0.0 [kworker/7:1H]
0.0 0.0 [kworker/5:1H]
0.0 0.0 /var/ossec/bin/wazuh-db
0.0 0.0 /var/ossec/bin/ossec-execd
0.0 0.0 /var/ossec/bin/ossec-logcollector
0.0 0.0 /usr/sbin/ntop -d -L -u ntop -P /var/lib/ntop
--access-log-file /var/log/ntop/access.log -i none -p
/etc/ntop/protocol.list -O /var/log/ntop
0.0 0.1 /usr/sbin/apache2 -k start
0.0 0.0 /var/ossec/bin/ossec-monitord
0.0 0.0 [kworker/14:1H]
0.0 0.0 php-fpm: master process (/etc/php/7.0/fpm/php-fpm.conf)
0.0 0.0 php-fpm: pool www
0.0 0.0 php-fpm: pool www
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 [kworker/1:1H]
0.0 0.0 [kworker/2:1H]
0.0 0.0 [kworker/15:1H]
0.0 0.0 [kworker/8:2]
0.0 0.0 [kworker/12:2]
0.0 0.0 su - SO-user -- /usr/bin/SO-userd -c
/etc/nsm/securityonion/SO-userd.conf -a
/etc/nsm/securityonion/autocat.conf -g
/etc/nsm/securityonion/SO-userd.queries -A
/etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
0.0 0.0 /lib/systemd/systemd --user
0.0 0.0 (sd-pam)
0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f
/var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c
/etc/nsm/ossec/ossec_agent.conf
0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f
/var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c
/etc/nsm/ossec/ossec_agent.conf
0.0 0.0 [kworker/11:2]
0.0 0.0 [kworker/15:2]
0.0 0.0 [cfg80211]
0.0 0.0 [kworker/9:1H]
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status
-p broctl -p broctl-live -p local -p manager local.bro broctl
base/frameworks/cluster local-manager.bro broctl/auto
0.0 0.0 tclsh /usr/bin/SO-userd -c
/etc/nsm/securityonion/SO-userd.conf -a
/etc/nsm/securityonion/autocat.conf -g
/etc/nsm/securityonion/SO-userd.queries -A
/etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
0.0 0.0 tclsh /usr/bin/SO-userd -c
/etc/nsm/securityonion/SO-userd.conf -a
/etc/nsm/securityonion/autocat.conf -g
/etc/nsm/securityonion/SO-userd.queries -A
/etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
0.0 0.0 [kworker/u48:2]
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status
-p broctl -p broctl-live -p local -p proxy local.bro broctl
base/frameworks/cluster local-proxy broctl/auto
0.0 0.0 [kworker/11:1H]
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-1
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-2
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-3
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-4
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-6
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-7
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth2 -U
.status -p broctl -p broctl-live -p local -p 41-184-204-74-eth2-5
local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 111:119
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 [kworker/8:1H]
0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/pcap_agent.conf
0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/pcap_agent.conf
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-1.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-1.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-1.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-2.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-2.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-2.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-3.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-3.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-3.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-4.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-4.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-4.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-5.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-5.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-5.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-6.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-6.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-6.stats
0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-7.conf
0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c
/etc/nsm/41-184-204-74-eth2/snort_agent-7.conf
0.0 0.0 tail -n 1 -f /nsm/sensor_data/41-184-204-74-eth2/snort-7.stats
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
9300 -container-ip X.X.X.X -container-port 9300
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
9200 -container-ip X.X.X.X -container-port 9200
0.0 0.0 docker-containerd-shim -namespace moby -workdir
/var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/dedab55550d6725f146f0bcb44707f2e95b6c1498c39f23e59ce6425341e720c
-address /var/run/docker/containerd/docker-containerd.sock
-containerd-binary /usr/bin/docker-containerd -runtime-root
/var/run/docker/runtime-runc
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
9600 -container-ip X.X.X.X -container-port 9600
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
6053 -container-ip X.X.X.X -container-port 6053
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
6052 -container-ip X.X.X.X -container-port 6052
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
6051 -container-ip X.X.X.X -container-port 6051
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
6050 -container-ip X.X.X.X -container-port 6050
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
5044 -container-ip X.X.X.X -container-port 5044
0.0 0.0 docker-containerd-shim -namespace moby -workdir
/var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/aa36a4df37f24c70474c9513a760f4f9c56281751dc548d794ee4ca30457ae19
-address /var/run/docker/containerd/docker-containerd.sock
-containerd-binary /usr/bin/docker-containerd -runtime-root
/var/run/docker/runtime-runc
0.0 0.0 /lib/systemd/systemd --user
0.0 0.0 (sd-pam)
0.0 0.0 sshd: SO-user@pts/0
0.0 0.0 -bash
0.0 0.0 [kworker/13:1H]
0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port
5601 -container-ip X.X.X.X -container-port 5601
0.0 0.0 docker-containerd-shim -namespace moby -workdir
/var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/de692ea276b0fe332ebde3909b069245e61abb3c048c3de4050a03c8094b92d6
-address /var/run/docker/containerd/docker-containerd.sock
-containerd-binary /usr/bin/docker-containerd -runtime-root
/var/run/docker/runtime-runc
0.0 0.0 docker-containerd-shim -namespace moby -workdir
/var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/6d3d8f5e3f29d6c3fc014cad7022dc697e283840eeb66fe3a031f8901aa46f80
-address /var/run/docker/containerd/docker-containerd.sock
-containerd-binary /usr/bin/docker-containerd -runtime-root
/var/run/docker/runtime-runc
0.0 0.0 [kworker/10:2]
0.0 0.0 docker-containerd-shim -namespace moby -workdir
/var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/11370449dde1a1a60fbc5a9367b737aba2fafdd5901e9a345030668f0e28778d
-address /var/run/docker/containerd/docker-containerd.sock
-containerd-binary /usr/bin/docker-containerd -runtime-root
/var/run/docker/runtime-runc
0.0 0.0 /bin/bash
0.0 0.0 sshd: SO-user [priv]
0.0 0.0 [kworker/3:0]
0.0 0.0 sshd: SO-user@pts/1
0.0 0.0 -bash
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 /usr/sbin/apache2 -k start
0.0 0.0 [kworker/u50:0]
0.0 0.0 [kworker/14:0]
0.0 0.0 [kworker/u49:0]
0.0 0.0 sudo sostat-redacted
0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
0.0 0.0 /bin/bash /usr/sbin/sostat
0.0 0.0 sshd: root [net]
0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
=========================================================================
Packets received during last monitoring interval (600 seconds)
=========================================================================
eth2: 19284637
=========================================================================
Packet Loss Stats
=========================================================================
NIC:
eth2:
RX packets:21250848 dropped:1026 TX packets:0 dropped:0
-------------------------------------------------------------------------
pf_ring:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: <unknown>
Tot Packets: 0
Tot Pkt Lost: 0
Loss as a percentage:
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1238151
Tot Pkt Lost: 57968
Loss as a percentage: 4.60
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1521369
Tot Pkt Lost: 373234
Loss as a percentage: 24.50
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1307294
Tot Pkt Lost: 117205
Loss as a percentage: 8.90
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1727726
Tot Pkt Lost: 119692
Loss as a percentage: 6.90
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1687841
Tot Pkt Lost: 164370
Loss as a percentage: 9.70
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1166065
Tot Pkt Lost: 473
Loss as a percentage: 0
Appl. Name: snort-cluster-54-socket-0
Tot Packets: 1761771
Tot Pkt Lost: 80668
Loss as a percentage: 4.50
-------------------------------------------------------------------------
IDS Engine (snort) packet drops:
/nsm/sensor_data/41-184-204-74-eth2/snort-1.stats last reported
pkt_drop_percent as 20.558
/nsm/sensor_data/41-184-204-74-eth2/snort-2.stats last reported
pkt_drop_percent as 52.357
/nsm/sensor_data/41-184-204-74-eth2/snort-3.stats last reported
pkt_drop_percent as 12.564
/nsm/sensor_data/41-184-204-74-eth2/snort-4.stats last reported
pkt_drop_percent as 28.389
/nsm/sensor_data/41-184-204-74-eth2/snort-5.stats last reported
pkt_drop_percent as 30.460
/nsm/sensor_data/41-184-204-74-eth2/snort-6.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/41-184-204-74-eth2/snort-7.stats last reported
pkt_drop_percent as 15.522
-------------------------------------------------------------------------
Bro:
Average packet loss as percent across all Bro workers: 26.891290
41-184-204-74-eth2-1: 1540218271.942222 recvd=15308852 dropped=4944773
link=20279253
41-184-204-74-eth2-2: 1540218271.507145 recvd=14050746 dropped=6187567
link=20281298
41-184-204-74-eth2-3: 1540218273.072250 recvd=15035278 dropped=5253885
link=20293151
41-184-204-74-eth2-4: 1540218272.709685 recvd=15213243 dropped=5066385
link=20299806
41-184-204-74-eth2-5: 1540218271.310810 recvd=14386676 dropped=5862363
link=20300426
41-184-204-74-eth2-6: 1540218272.057230 recvd=14420490 dropped=5836097
link=20309033
41-184-204-74-eth2-7: 1540218272.728095 recvd=15220427 dropped=5055316
link=20314211
No capture loss reported.
-------------------------------------------------------------------------
Netsniff-NG:
0 Loss
=========================================================================
PF_RING
=========================================================================
PF_RING Version : 7.2.0
(7.2.0-stable:9b3fd353fc66a219b73860fd5214fbd541df2515)
Total rings : 14
Standard (non ZC) Options
Ring slots : 4096
Slot version : 17
Capture TX : Yes [RX+TX]
IP Defragment : No
Socket Mode : Standard
Cluster Fragment Queue : 0
Cluster Fragment Discard : 0
=========================================================================
Log Archive
=========================================================================
/nsm/sensor_data/41-184-204-74-enp0s29f1u2/dailylogs/ - 0 days
4.0K .
/nsm/sensor_data/41-184-204-74-eth0/dailylogs/ - 0 days
4.0K .
/nsm/sensor_data/41-184-204-74-eth1/dailylogs/ - 0 days
4.0K .
/nsm/sensor_data/41-184-204-74-eth2/dailylogs/ - 20 days
84K .
4.0K ./2018-10-03
4.0K ./2018-10-04
4.0K ./2018-10-05
4.0K ./2018-10-06
4.0K ./2018-10-07
4.0K ./2018-10-08
4.0K ./2018-10-09
4.0K ./2018-10-10
4.0K ./2018-10-11
4.0K ./2018-10-12
4.0K ./2018-10-13
4.0K ./2018-10-14
4.0K ./2018-10-15
4.0K ./2018-10-16
4.0K ./2018-10-17
4.0K ./2018-10-18
4.0K ./2018-10-19
4.0K ./2018-10-20
4.0K ./2018-10-21
4.0K ./2018-10-22
/nsm/sensor_data/41-184-204-74-eth3/dailylogs/ - 0 days
4.0K .
/nsm/bro/logs/ - 3 days
1.3G .
507M ./2018-10-03
100M ./2018-10-12
626M ./2018-10-22
38M ./stats
=========================================================================
Sguil Uncategorized Events
=========================================================================
COUNT(*)
164724
=========================================================================
Sguil events summary for yesterday
=========================================================================
Total
0
=========================================================================
Top 50 All time Sguil Events
=========================================================================
Totals GenID:SigID Signature
989297 129:15 stream5: Reset outside window
465202 120:3 http_inspect: NO CONTENT-LENGTH OR TRANSFER-ENCODING IN
HTTP RESPONSE
202799 129:4 stream5: TCP Timestamp is outside of PAWS window
119526 129:12 stream5: TCP Small Segment Threshold Exceeded
86657 128:4 ssh: Protocol mismatch
63365 119:33 http_inspect: UNESCAPED SPACE IN HTTP URI
54230 3:19187 PROTOCOL-DNS TMG Firewall Client long host entry exploit
attempt
53621 119:19 http_inspect: LONG HEADER
49587 1:2010935 ET SCAN Suspicious inbound to MSSQL port 1433
47309 139:1 sensitive_data: sensitive data global threshold exceeded
24360 129:14 stream5: TCP Timestamp is missing
15628 1:2016149 ET INFO Session Traversal Utilities for NAT
(STUN Binding Request)
13630 1:2016150 ET INFO Session Traversal Utilities for NAT
(STUN Binding Response)
11564 3:21355 PROTOCOL-DNS potential dns cache poisoning attempt -
mismatched txid
9376 1:2010144 ET P2P Vuze BT UDP Connection (5)
8638 125:1 ftp_pp: Telnet command on FTP command channel
8551 1:2008581 ET P2P BitTorrent DHT ping request
7307 129:5 stream5: Bad segment, overlap adjusted size less
than/equal 0
6667 119:14 http_inspect: NON-RFC DEFINED CHAR
5247 1:2010140 ET P2P Vuze BT UDP Connection
4517 141:1 imap: Unknown IMAP4 command
4270 137:1 spp_ssl: Invalid Client HELLO after Server HELLO Detected
4085 129:2 stream5: Data on SYN packet
4054 140:27 sip: Maximum dialogs in a session reached
3939 1:2402000 ET DROP Dshield Block Listed Source group 1
2952 1:2014703 ET DNS Non-DNS or Non-Compliant DNS traffic on
DNS port Reserved Bit Set
2919 1:2010937 ET SCAN Suspicious inbound to mySQL port 3306
2814 1:2008585 ET P2P BitTorrent DHT announce_peers request
2366 1:2022913 ET INFO WinHttp AutoProxy Request wpad.dat
Possible BadTunnel
2159 3:30881 MALWARE-OTHER dns request with long host name segment -
possible data exfiltration attempt
1948 1:2011716 ET SCAN Sipvicious User-Agent Detected
(friendly-scanner)
1798 1:2014702 ET DNS Non-DNS or Non-Compliant DNS traffic on
DNS port Opcode 8 through 15 set
1788 138:5 sensitive_data: sensitive data - eMail addresses
1750 119:31 http_inspect: UNKNOWN METHOD
1733 1:2008578 ET SCAN Sipvicious Scan
1582 1:2023472 ET POLICY External IP Lookup Domain
(myip.opendns .com in DNS lookup)
1367 119:28 http_inspect: POST W/O CONTENT-LENGTH OR CHUNKS
1317 123:13 frag3: Fragments smaller than configured min_fragment_length
1274 119:15 http_inspect: OVERSIZE REQUEST-URI DIRECTORY
1094 1:2500018 ET COMPROMISED Known Compromised or Hostile Host
Traffic TCP group 10
1086 1:2017162 ET SCAN SipCLI VOIP Scan
988 1:2018904 ET INFO Session Traversal Utilities for NAT
(STUN Binding Request obsolete rfc 3489 CHANGE-REQUEST attribute change
IP flag false change port flag false)
962 123:8 frag3: Fragmentation overlap
903 142:1 pop: Unknown POP3 command
863 129:8 stream5: Data sent on stream after TCP Reset
825 123:12 frag3: Number of overlapping fragments exceed configured
limit
813 3:31738 PROTOCOL-DNS domain not found containing random-looking
hostname - possible DGA detected
790 1:31136 MALWARE-CNC Win.Trojan.ZeroAccess inbound connection
620 1:2403412 ET CINS Active Threat Intelligence Poor
Reputation IP TCP group 57
608 1:2000334 ET P2P BitTorrent peer sync
Total
2344714
=========================================================================
Last update
=========================================================================
Commandline: apt-get -y remove --purge linux-image-4.4.0-135-generic
linux-headers-4.4.0-135-generic
Requested-By: SO-user (1000)
Purge: linux-image-4.4.0-135-generic:amd64 (4.4.0-135.161),
linux-signed-image-4.4.0-135-generic:amd64 (4.4.0-135.161),
linux-image-extra-4.4.0-135-generic:amd64 (4.4.0-135.161),
linux-headers-4.4.0-135-generic:amd64 (4.4.0-135.161)
End-Date: 2018-10-22 13:54:33
Start-Date: 2018-10-22 13:59:03
Commandline: apt-get -y dist-upgrade
Requested-By: SO-user (1000)
Upgrade: pfring-dkms:amd64 (7.2.0, 7.2.0), libssh-gcrypt-4:amd64
(0.6.3-4.3, 0.6.3-4.3ubuntu0.1), ntopng:amd64 (3.6.181012-5267,
3.6.181022-5354), pfring:amd64 (7.2.0-2187, 7.2.0-2193), nprobe:amd64
(8.6.181012-6309, 8.6.181022-6310), ntopng-data:amd64 (3.6.181012,
3.6.181022)
End-Date: 2018-10-22 13:59:50
=========================================================================
Elasticsearch
=========================================================================
Elasticsearch is running.
Cluster Name: "SO-server"
Cluster Status: "green"
Total Nodes: 1
Failed Nodes: 0
Total Indices: 65
Total Shards: 85
Total Documents: 247808375
Total Size: 325771MB
Free Memory: 1%
Total Number of Events: 247808375
Avg. Event Size (In Bytes): 1314
CONTAINER ID NAME CPU % MEM USAGE /
LIMIT MEM % NET I/O BLOCK I/O PIDS
dedab55550d6 so-elasticsearch 2.31% 5.032GiB /
27.47GiB 18.32% 570kB / 41.8MB 2.82GB / 2.49MB 144
=========================================================================
Logstash
=========================================================================
Logstash is running.
CONTAINER ID NAME CPU % MEM USAGE /
LIMIT MEM % NET I/O BLOCK I/O PIDS
aa36a4df37f2 so-logstash 105.23% 2.59GiB /
27.47GiB 9.43% 5.96kB / 3.27kB 68.6MB / 401kB 59
Logstash Queue Stats:
Queue Type:
Queue settings can be modified in /etc/logstash/logstash.yml.
Event Summary (since restart):
Events In:
Events Out:
=========================================================================
Kibana
=========================================================================
Kibana is running.
CONTAINER ID NAME CPU % MEM USAGE /
LIMIT MEM % NET I/O BLOCK I/O PIDS
de692ea276b0 so-kibana 0.75% 118.2MiB /
27.47GiB 0.42% 1.23MB / 3.52MB 65.7MB / 4.1kB 10
=========================================================================
ElastAlert
=========================================================================
ElastAlert is running.
CONTAINER ID NAME CPU % MEM USAGE /
LIMIT MEM % NET I/O BLOCK I/O PIDS
6d3d8f5e3f29 so-elastalert 0.02% 50.71MiB /
27.47GiB 0.18% 146kB / 143kB 23.3MB / 20.5kB 2
=========================================================================
Curator
=========================================================================
Curator is running.
CONTAINER ID NAME CPU % MEM USAGE /
LIMIT MEM % NET I/O BLOCK I/O PIDS
11370449dde1 so-curator 99.54% 51.39MiB /
27.47GiB 0.18% 40.1MB / 200kB 4.32MB / 0B 3
=========================================================================
Version Information
=========================================================================
Ubuntu 16.04.5 LTS
securityonion-sostat 20120722-0ubuntu0securityonion111