If you're not using the following services, please disable them:
* prads (sessions/assets)[ OK ]
* sancp_agent (SO-user)[ OK ]
* pads_agent (SO-user)[ OK ]
* argus[ OK ]
* http_agent (SO-user)[ OK ]
https://code.google.com/p/security-onion/wiki/DisablingProcesses
Syslog-ng isn't listening on port 514 (could be an issue):
Syslog-ng
Checking for process:
20134 supervising syslog-ng
20135 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
Checking for connection:
nc: connect to localhost port 514 (tcp) failed: Connection refused
You have a large number of buffers in queue:
ELSA Buffers in Queue:
-rw-r--r-- 1 root root 6648 Mar 21 14:57
/nsm/elsa/data/elsa/tmp/buffers/1426949816.00246
-rw-r--r-- 1 root root 19441 Mar 21 14:56
/nsm/elsa/data/elsa/tmp/buffers/1426949755.99867
-rw-r--r-- 1 root root 74624 Mar 21 14:55
/nsm/elsa/data/elsa/tmp/buffers/1426949695.99446
-rw-r--r-- 1 root root 30887 Mar 21 14:54
/nsm/elsa/data/elsa/tmp/buffers/1426949635.99027
-rw-r--r-- 1 root root 88414 Mar 21 14:53
/nsm/elsa/data/elsa/tmp/buffers/1426949575.98571
-rw-r--r-- 1 root root 39992 Mar 21 14:52
/nsm/elsa/data/elsa/tmp/buffers/1426949515.93023
-rw-r--r-- 1 root root 8018 Mar 21 14:51
/nsm/elsa/data/elsa/tmp/buffers/1426949455.7173
-rw-r--r-- 1 root root 19749 Mar 21 14:50
/nsm/elsa/data/elsa/tmp/buffers/1426949395.6656
-rw-r--r-- 1 root root 40288 Mar 21 14:49
/nsm/elsa/data/elsa/tmp/buffers/1426949335.66069
-rw-r--r-- 1 root root 63193 Mar 21 14:48
/nsm/elsa/data/elsa/tmp/buffers/1426949275.64147
-rw-r--r-- 1 root root 31998 Mar 21 14:47
/nsm/elsa/data/elsa/tmp/buffers/1426949215.49496
-rw-r--r-- 1 root root 30217 Mar 21 14:46
/nsm/elsa/data/elsa/tmp/buffers/1426949155.4548
-rw-r--r-- 1 root root 52881 Mar 21 14:45
/nsm/elsa/data/elsa/tmp/buffers/1426949095.4497
-rw-r--r-- 1 root root 56967 Mar 21 14:44
/nsm/elsa/data/elsa/tmp/buffers/1426949035.32912
-rw-r--r-- 1 root root 389971 Mar 21 14:43
/nsm/elsa/data/elsa/tmp/buffers/1426948975.32414
-rw-r--r-- 1 root root 263968 Mar 21 14:42
/nsm/elsa/data/elsa/tmp/buffers/1426948913.84971
-rw-r--r-- 1 root root 55546 Mar 21 14:41
/nsm/elsa/data/elsa/tmp/buffers/1426948850.48367
-rw-r--r-- 1 root root 180888 Mar 21 14:40
/nsm/elsa/data/elsa/tmp/buffers/1426948786.45095
-rw-r--r-- 1 root root 59219 Mar 21 14:39
/nsm/elsa/data/elsa/tmp/buffers/1426948726.42079
-rw-r--r-- 1 root root 74 Mar 21 14:38
/nsm/elsa/data/elsa/tmp/buffers/1426948603.22053
-rw-r--r-- 1 root root 8352 Mar 21 14:36
/nsm/elsa/data/elsa/tmp/buffers/1426948543.16056
-rw-r--r-- 1 root root 468389 Mar 21 14:35
/nsm/elsa/data/elsa/tmp/buffers/1426948483.14179
-rw-r--r-- 1 root root 36 Oct 9 15:28
/nsm/elsa/data/elsa/tmp/buffers/host_stats.tsv
https://code.google.com/p/security-onion/wiki/FAQ#Why_does_sostat_show_a_high_number_of_ELSA_Buffers_in_Queue?