On Fri, Apr 5, 2013 at 8:52 AM, <
offe...@gmail.com> wrote:
> Hi Doug and Matt,
>
> Ok it looks like NOT downgrading python (step 15 in the installation guide) and NOT installing ubuntu server with encrypted home folder did the trick..
>
> To others who may experience this in the future i currently don't know if my problems was solved by both solutions OR one of them.
I'm 99% sure it was the encrypted home folder.
> And sadly i seriously don't have time right now to test... sorry..
>
> My SOstat output now looks like this.. is this a healthy sensor?
>
> support@ITG-IDS-Sensor01:~$ sudo sostat
> [sudo] password for support:
> =========================================================================
> Service Status
> =========================================================================
> Status: HIDS
> * ossec_agent (sguil)[ OK ]
> Status: Bro
> waiting for lock ..... ok
> Name Type Host Status Pid Peers Started
> manager manager 10.10.10.20 running 7628 4 05 Apr 10:45:17
> proxy proxy 10.10.10.20 running 7775 4 05 Apr 10:45:20
> ITG-IDS-Sensor01-eth0-1 worker 10.10.10.20 running 7849 2 05 Apr 10:45:22
> ITG-IDS-Sensor01-eth0-2 worker 10.10.10.20 running 7850 2 05 Apr 10:45:22
> ITG-IDS-Sensor01-eth0-3 worker 10.10.10.20 running 7851 2 05 Apr 10:45:22
> Status: ITG-IDS-Sensor01-eth0
> * netsniff-ng (full packet data)[ FAIL ]
> * pcap_agent (sguil)[ FAIL ]
netsniff-ng and pcap_agent are failed. Please try the following:
sudo nsm_sensor_ps-restart
> * snort_agent-1 (sguil)[ OK ]
> * snort_agent-2 (sguil)[ OK ]
> * snort_agent-3 (sguil)[ OK ]
> * snort-1 (alert data)[ OK ]
> * snort-2 (alert data)[ OK ]
> * snort-3 (alert data)[ OK ]
> * barnyard2-1 (spooler, unified2 format)[ OK ]
> * barnyard2-2 (spooler, unified2 format)[ OK ]
> * barnyard2-3 (spooler, unified2 format)[ OK ]
> * prads (sessions/assets)[ OK ]
> * sancp_agent (sguil)[ OK ]
> * pads_agent (sguil)[ OK ]
> * argus[ OK ]
> * http_agent (sguil)[ OK ]
>
> =========================================================================
> Interface Status
> =========================================================================
> eth0 Link encap:Ethernet HWaddr 88:51:fb:28:55:88
> UP BROADCAST NOARP PROMISC MULTICAST MTU:1500 Metric:1
> RX packets:0 errors:0 dropped:0 overruns:0 frame:0
> TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
> collisions:0 txqueuelen:1000
> RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
> Interrupt:16
Looks like you're not seeing any traffic on eth0 yet. Is that what
you're expecting?
> eth1 Link encap:Ethernet HWaddr 88:51:fb:28:55:89
> inet addr:10.10.10.20 Bcast:10.10.10.255 Mask:255.255.255.0
> inet6 addr: fe80::8a51:fbff:fe28:5589/64 Scope:Link
> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
> RX packets:108317 errors:0 dropped:0 overruns:0 frame:0
> TX packets:85197 errors:0 dropped:0 overruns:0 carrier:0
> collisions:0 txqueuelen:1000
> RX bytes:25647006 (25.6 MB) TX bytes:17180920 (17.1 MB)
> Interrupt:17
>
> lo Link encap:Local Loopback
> inet addr:127.0.0.1 Mask:255.0.0.0
> inet6 addr: ::1/128 Scope:Host
> UP LOOPBACK RUNNING MTU:16436 Metric:1
> RX packets:162465 errors:0 dropped:0 overruns:0 frame:0
> TX packets:162465 errors:0 dropped:0 overruns:0 carrier:0
> collisions:0 txqueuelen:0
> RX bytes:19926415 (19.9 MB) TX bytes:19926415 (19.9 MB)
>
>
> =========================================================================
> Disk Usage
> =========================================================================
> Filesystem Size Used Avail Use% Mounted on
> /dev/md1 8.2T 2.7G 7.8T 1% /
> udev 972M 4.0K 972M 1% /dev
> tmpfs 393M 400K 393M 1% /run
> none 5.0M 0 5.0M 0% /run/lock
> none 982M 0 982M 0% /run/shm
> /dev/md0 1.9G 62M 1.7G 4% /boot
>
> =========================================================================
> Network Sockets
> =========================================================================
> COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
> sshd 935 root 3u IPv4 8119 0t0 TCP *:22 (LISTEN)
> sshd 935 root 4u IPv6 8121 0t0 TCP *:22 (LISTEN)
> /usr/sbin 1547 root 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1547 root 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1547 root 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> /usr/sbin 1595 www-data 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1595 www-data 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1595 www-data 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> /usr/sbin 1596 www-data 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1596 www-data 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1596 www-data 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> /usr/sbin 1597 www-data 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1597 www-data 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1597 www-data 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> /usr/sbin 1598 www-data 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1598 www-data 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1598 www-data 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> /usr/sbin 1599 www-data 4u IPv4 11187 0t0 TCP *:443 (LISTEN)
> /usr/sbin 1599 www-data 5u IPv4 11190 0t0 TCP *:9876 (LISTEN)
> /usr/sbin 1599 www-data 6u IPv4 11192 0t0 TCP *:444 (LISTEN)
> ntpd 1874 ntp 16u IPv4 13333 0t0 UDP *:123
> ntpd 1874 ntp 17u IPv6 13334 0t0 UDP *:123
> ntpd 1874 ntp 18u IPv4 13340 0t0 UDP
127.0.0.1:123
> ntpd 1874 ntp 19u IPv4 13341 0t0 UDP
10.10.10.20:123
> ntpd 1874 ntp 20u IPv6 13342 0t0 UDP [fe80::8a51:fbff:fe28:5589]:123
> ntpd 1874 ntp 21u IPv6 13343 0t0 UDP [::1]:123
> sshd 2624 root 3u IPv4 11762 0t0 TCP 10.10.10.20:22->
10.10.10.111:39852 (ESTABLISHED)
> sshd 2781 support 3u IPv4 11762 0t0 TCP 10.10.10.20:22->
10.10.10.111:39852 (ESTABLISHED)
> sshd 2781 support 8u IPv6 11812 0t0 TCP [::1]:6010 (LISTEN)
> sshd 2781 support 9u IPv4 11813 0t0 TCP
127.0.0.1:6010 (LISTEN)
> sshd 2781 support 11u IPv4 164562 0t0 TCP 127.0.0.1:6010->
127.0.0.1:37324 (ESTABLISHED)
> ssh 7437 root 3u IPv4 154562 0t0 TCP 10.10.10.20:53168->
10.10.10.19:22 (ESTABLISHED)
> ssh 7437 root 4u IPv6 156869 0t0 TCP [::1]:3306 (LISTEN)
> ssh 7437 root 5u IPv4 156870 0t0 TCP
127.0.0.1:3306 (LISTEN)
> ssh 7437 root 6u IPv4 165385 0t0 TCP 127.0.0.1:3306->
127.0.0.1:56086 (ESTABLISHED)
> ssh 7437 root 7u IPv4 164593 0t0 TCP 127.0.0.1:3306->
127.0.0.1:56087 (ESTABLISHED)
> ssh 7437 root 8u IPv4 164594 0t0 TCP 127.0.0.1:3306->
127.0.0.1:56088 (ESTABLISHED)
> mysqld 7475 mysql 10u IPv4 157705 0t0 TCP
127.0.0.1:50000 (LISTEN)
> tclsh 7514 root 3u IPv4 162686 0t0 TCP 10.10.10.20:52944->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 5u IPv4 168011 0t0 UDP *:43228
> tclsh 7514 root 7u IPv4 165390 0t0 TCP 10.10.10.20:52957->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 8u IPv4 164600 0t0 TCP 10.10.10.20:52958->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 9u IPv4 164601 0t0 TCP 10.10.10.20:52959->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 10u IPv4 164602 0t0 TCP 10.10.10.20:52960->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 11u IPv4 162705 0t0 TCP 10.10.10.20:52961->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 12u IPv4 163558 0t0 TCP 10.10.10.20:52962->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 13u IPv4 162706 0t0 TCP 10.10.10.20:52963->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 14u IPv4 163559 0t0 TCP 10.10.10.20:52964->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 15u IPv4 163560 0t0 TCP 10.10.10.20:52965->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 16u IPv4 164603 0t0 TCP 10.10.10.20:52966->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 17u IPv4 164604 0t0 TCP 10.10.10.20:52967->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 18u IPv4 164605 0t0 TCP 10.10.10.20:52968->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 7514 root 19u IPv4 162707 0t0 TCP 10.10.10.20:52969->
10.10.10.19:7736 (ESTABLISHED)
> bro 7628 root 4u IPv4 156903 0t0 UDP 10.10.10.20:56877->
10.10.10.12:53
> bro 7741 root 0u IPv4 155457 0t0 TCP *:47761 (LISTEN)
> bro 7741 root 1u IPv6 155458 0t0 TCP *:47761 (LISTEN)
> bro 7741 root 2u IPv4 157814 0t0 TCP 10.10.10.20:47761->
10.10.10.20:46504 (ESTABLISHED)
> bro 7741 root 4u IPv4 156903 0t0 UDP 10.10.10.20:56877->
10.10.10.12:53
> bro 7741 root 8u IPv4 155505 0t0 TCP 10.10.10.20:47761->
10.10.10.20:46506 (ESTABLISHED)
> bro 7741 root 10u IPv4 156563 0t0 TCP 10.10.10.20:47761->
10.10.10.20:46507 (ESTABLISHED)
> bro 7741 root 11u IPv4 157085 0t0 TCP 10.10.10.20:47761->
10.10.10.20:46509 (ESTABLISHED)
> bro 7775 root 4u IPv4 157005 0t0 UDP 10.10.10.20:47531->
10.10.10.12:53
> bro 7782 root 0u IPv4 157813 0t0 TCP 10.10.10.20:46504->
10.10.10.20:47761 (ESTABLISHED)
> bro 7782 root 1u IPv4 157817 0t0 TCP *:47762 (LISTEN)
> bro 7782 root 2u IPv6 157818 0t0 TCP *:47762 (LISTEN)
> bro 7782 root 4u IPv4 157005 0t0 UDP 10.10.10.20:47531->
10.10.10.12:53
> bro 7782 root 7u IPv4 157083 0t0 TCP 10.10.10.20:47762->
10.10.10.20:49877 (ESTABLISHED)
> bro 7782 root 9u IPv4 156565 0t0 TCP 10.10.10.20:47762->
10.10.10.20:49880 (ESTABLISHED)
> bro 7782 root 10u IPv4 155508 0t0 TCP 10.10.10.20:47762->
10.10.10.20:49882 (ESTABLISHED)
> bro 7849 root 4u IPv4 156554 0t0 UDP 10.10.10.20:48201->
10.10.10.12:53
> bro 7850 root 4u IPv4 157076 0t0 UDP 10.10.10.20:43480->
10.10.10.12:53
> bro 7851 root 4u IPv4 157835 0t0 UDP 10.10.10.20:56623->
10.10.10.12:53
> bro 7855 root 0u IPv4 156556 0t0 TCP 10.10.10.20:49877->
10.10.10.20:47762 (ESTABLISHED)
> bro 7855 root 1u IPv4 156557 0t0 TCP 10.10.10.20:46506->
10.10.10.20:47761 (ESTABLISHED)
> bro 7855 root 2u IPv4 156560 0t0 TCP *:47763 (LISTEN)
> bro 7855 root 4u IPv4 156554 0t0 UDP 10.10.10.20:48201->
10.10.10.12:53
> bro 7855 root 8u IPv6 156561 0t0 TCP *:47763 (LISTEN)
> bro 7859 root 0u IPv4 156562 0t0 TCP 10.10.10.20:46507->
10.10.10.20:47761 (ESTABLISHED)
> bro 7859 root 1u IPv4 156564 0t0 TCP 10.10.10.20:49880->
10.10.10.20:47762 (ESTABLISHED)
> bro 7859 root 2u IPv4 156568 0t0 TCP *:47764 (LISTEN)
> bro 7859 root 4u IPv4 157076 0t0 UDP 10.10.10.20:43480->
10.10.10.12:53
> bro 7859 root 8u IPv6 156569 0t0 TCP *:47764 (LISTEN)
> bro 7865 root 0u IPv4 157084 0t0 TCP 10.10.10.20:46509->
10.10.10.20:47761 (ESTABLISHED)
> bro 7865 root 1u IPv4 157086 0t0 TCP 10.10.10.20:49882->
10.10.10.20:47762 (ESTABLISHED)
> bro 7865 root 2u IPv4 157089 0t0 TCP *:47765 (LISTEN)
> bro 7865 root 4u IPv4 157835 0t0 UDP 10.10.10.20:56623->
10.10.10.12:53
> bro 7865 root 8u IPv6 157090 0t0 TCP *:47765 (LISTEN)
> tclsh 7981 root 3u IPv4 158794 0t0 TCP
127.0.0.1:8001 (LISTEN)
> tclsh 7981 root 4u IPv4 157408 0t0 TCP 127.0.0.1:8001->
127.0.0.1:37151 (ESTABLISHED)
> tclsh 7981 root 6u IPv4 162694 0t0 TCP 10.10.10.20:52949->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 8007 root 3u IPv4 157928 0t0 TCP
127.0.0.1:8002 (LISTEN)
> tclsh 8007 root 4u IPv4 158086 0t0 TCP 127.0.0.1:8002->
127.0.0.1:39356 (ESTABLISHED)
> tclsh 8007 root 6u IPv4 162695 0t0 TCP 10.10.10.20:52950->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 8033 root 3u IPv4 157251 0t0 TCP
127.0.0.1:8003 (LISTEN)
> tclsh 8033 root 4u IPv4 159046 0t0 TCP 127.0.0.1:8003->
127.0.0.1:56968 (ESTABLISHED)
> tclsh 8033 root 6u IPv4 165384 0t0 TCP 10.10.10.20:52952->
10.10.10.19:7736 (ESTABLISHED)
> barnyard2 8147 root 3u IPv4 157407 0t0 TCP 127.0.0.1:37151->
127.0.0.1:8001 (ESTABLISHED)
> barnyard2 8147 root 4u IPv4 163549 0t0 TCP 127.0.0.1:56086->
127.0.0.1:3306 (ESTABLISHED)
> barnyard2 8169 root 3u IPv4 158085 0t0 TCP 127.0.0.1:39356->
127.0.0.1:8002 (ESTABLISHED)
> barnyard2 8169 root 4u IPv4 162698 0t0 TCP 127.0.0.1:56087->
127.0.0.1:3306 (ESTABLISHED)
> barnyard2 8193 root 3u IPv4 158090 0t0 TCP 127.0.0.1:56968->
127.0.0.1:8003 (ESTABLISHED)
> barnyard2 8193 root 4u IPv4 163552 0t0 TCP 127.0.0.1:56088->
127.0.0.1:3306 (ESTABLISHED)
> tclsh 8228 root 6u IPv4 162689 0t0 TCP 10.10.10.20:52945->
10.10.10.19:7736 (ESTABLISHED)
> tclsh 8251 root 3u IPv4 164592 0t0 TCP 10.10.10.20:52946->
10.10.10.19:7736 (ESTABLISHED)
> searchd 8294 root 6u IPv4 159351 0t0 TCP *:9306 (LISTEN)
> searchd 8294 root 7u IPv4 159352 0t0 TCP *:3307 (LISTEN)
> syslog-ng 8323 root 9u IPv4 161388 0t0 TCP *:514 (LISTEN)
> syslog-ng 8323 root 10u IPv4 161389 0t0 UDP *:514
> tclsh 8349 root 3u IPv4 162691 0t0 TCP 10.10.10.20:52948->
10.10.10.19:7736 (ESTABLISHED)
> wish 9189 support 3u IPv4 162645 0t0 TCP 127.0.0.1:37324->
127.0.0.1:6010 (ESTABLISHED)
> wish 9189 support 4u IPv4 165383 0t0 TCP 10.10.10.20:34165->
10.10.10.19:7734 (ESTABLISHED)
> sshd 9211 root 3u IPv4 162708 0t0 TCP 10.10.10.20:22->
10.10.10.111:40184 (ESTABLISHED)
> sshd 9361 support 3u IPv4 162708 0t0 TCP 10.10.10.20:22->
10.10.10.111:40184 (ESTABLISHED)
> sshd 9361 support 8u IPv6 163612 0t0 TCP [::1]:6011 (LISTEN)
> sshd 9361 support 9u IPv4 163613 0t0 TCP
127.0.0.1:6011 (LISTEN)
>
> =========================================================================
> IDS Rules Update
> =========================================================================
> tail: cannot open `/var/log/nsm/pulledpork.log' for reading: No such file or directory
>
> =========================================================================
> CPU Usage
> =========================================================================
> top - 10:50:11 up 50 min, 2 users, load average: 2.10, 1.17, 0.58
> Tasks: 156 total, 6 running, 150 sleeping, 0 stopped, 0 zombie
> Cpu(s): 1.7%us, 1.7%sy, 0.3%ni, 95.4%id, 0.8%wa, 0.0%hi, 0.0%si, 0.0%st
> Mem: 2009284k total, 1851216k used, 158068k free, 24836k buffers
Looks like you only have 2GB RAM? Might want to max out your RAM for
a production sensor.
> Swap: 7809008k total, 260k used, 7808748k free, 391536k cached
>
> PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
> 7741 root 25 5 139m 18m 936 R 20 0.9 0:54.67 bro
> 7782 root 25 5 69016 18m 952 S 20 0.9 0:53.45 bro
> 7855 root 25 5 127m 82m 64m R 18 4.2 0:43.33 bro
> 7865 root 25 5 127m 82m 64m S 18 4.2 0:42.50 bro
> 7850 root 20 0 267m 85m 68m S 16 4.4 0:43.02 bro
> 7851 root 20 0 267m 85m 68m R 16 4.4 0:44.50 bro
> 7859 root 25 5 127m 82m 64m R 16 4.2 0:43.25 bro
> 7849 root 20 0 267m 85m 68m R 14 4.4 0:42.78 bro
> 7437 root 20 0 41752 3204 2408 S 2 0.2 0:02.91 ssh
> 7775 root 20 0 275m 21m 3972 S 2 1.1 0:02.68 bro
> 1 root 20 0 24432 2336 1360 S 0 0.1 0:00.49 init
> 2 root 20 0 0 0 0 S 0 0.0 0:00.00 kthreadd
> 3 root 20 0 0 0 0 S 0 0.0 0:00.16 ksoftirqd/0
> 6 root RT 0 0 0 0 S 0 0.0 0:02.92 migration/0
> 7 root RT 0 0 0 0 S 0 0.0 0:00.00 watchdog/0
> 8 root RT 0 0 0 0 S 0 0.0 0:00.04 migration/1
> 10 root 20 0 0 0 0 S 0 0.0 0:00.10 ksoftirqd/1
> 11 root RT 0 0 0 0 S 0 0.0 0:00.00 watchdog/1
> 12 root RT 0 0 0 0 S 0 0.0 0:00.20 migration/2
> 13 root 20 0 0 0 0 S 0 0.0 0:00.09 kworker/2:0
> 14 root 20 0 0 0 0 S 0 0.0 0:00.11 ksoftirqd/2
> 15 root RT 0 0 0 0 S 0 0.0 0:00.00 watchdog/2
> 16 root RT 0 0 0 0 S 0 0.0 0:00.00 migration/3
> 18 root 20 0 0 0 0 S 0 0.0 0:00.10 ksoftirqd/3
> 19 root RT 0 0 0 0 S 0 0.0 0:00.00 watchdog/3
> 20 root 0 -20 0 0 0 S 0 0.0 0:00.00 cpuset
> 21 root 0 -20 0 0 0 S 0 0.0 0:00.00 khelper
> 22 root 20 0 0 0 0 S 0 0.0 0:00.00 kdevtmpfs
> 23 root 0 -20 0 0 0 S 0 0.0 0:00.00 netns
> 25 root 20 0 0 0 0 S 0 0.0 0:00.01 sync_supers
> 26 root 20 0 0 0 0 S 0 0.0 0:00.00 bdi-default
> 27 root 0 -20 0 0 0 S 0 0.0 0:00.00 kintegrityd
> 28 root 0 -20 0 0 0 S 0 0.0 0:00.00 kblockd
> 29 root 0 -20 0 0 0 S 0 0.0 0:00.00 ata_sff
> 30 root 20 0 0 0 0 S 0 0.0 0:00.00 khubd
> 31 root 0 -20 0 0 0 S 0 0.0 0:00.00 md
> 34 root 20 0 0 0 0 S 0 0.0 0:00.00 khungtaskd
> 35 root 20 0 0 0 0 S 0 0.0 0:00.03 kswapd0
> 36 root 25 5 0 0 0 S 0 0.0 0:00.00 ksmd
> 37 root 39 19 0 0 0 S 0 0.0 0:00.00 khugepaged
> 38 root 20 0 0 0 0 S 0 0.0 0:00.00 fsnotify_mark
> 39 root 20 0 0 0 0 S 0 0.0 0:00.00 ecryptfs-kthrea
> 40 root 0 -20 0 0 0 S 0 0.0 0:00.00 crypto
> 49 root 0 -20 0 0 0 S 0 0.0 0:00.00 kthrotld
> 50 root 20 0 0 0 0 S 0 0.0 0:00.00 scsi_eh_0
> 51 root 20 0 0 0 0 S 0 0.0 0:00.00 scsi_eh_1
> 52 root 20 0 0 0 0 S 0 0.0 0:00.00 kworker/u:2
> 53 root 20 0 0 0 0 S 0 0.0 0:00.00 scsi_eh_2
> 54 root 20 0 0 0 0 S 0 0.0 0:00.00 scsi_eh_3
> 55 root 20 0 0 0 0 S 0 0.0 0:00.00 kworker/u:3
> 57 root 0 -20 0 0 0 S 0 0.0 0:00.00 binder
> 77 root 0 -20 0 0 0 S 0 0.0 0:00.00 deferwq
> 78 root 0 -20 0 0 0 S 0 0.0 0:00.00 charger_manager
> 79 root 0 -20 0 0 0 S 0 0.0 0:00.00 devfreq_wq
> 80 root 20 0 0 0 0 S 0 0.0 0:00.09 kworker/3:1
> 81 root 20 0 0 0 0 S 0 0.0 0:00.49 kworker/1:1
> 144 root 20 0 0 0 0 S 0 0.0 0:00.09 kworker/2:2
> 261 root 20 0 0 0 0 S 0 0.0 0:00.07 kworker/3:2
> 270 root 20 0 0 0 0 S 0 0.0 0:00.46 kworker/1:2
> 292 root 20 0 0 0 0 S 0 0.0 0:01.06 md1_raid5
> 302 root 20 0 0 0 0 S 0 0.0 0:00.00 md0_raid1
> 315 root 20 0 0 0 0 S 0 0.0 0:00.09 jbd2/md1-8
> 316 root 0 -20 0 0 0 S 0 0.0 0:00.00 ext4-dio-unwrit
> 408 root 20 0 17364 640 452 S 0 0.0 0:00.03 upstart-udev-br
> 411 root 20 0 21732 1536 804 S 0 0.1 0:00.03 udevd
> 550 root 20 0 21728 1048 328 S 0 0.1 0:00.00 udevd
> 551 root 20 0 21728 1036 312 S 0 0.1 0:00.00 udevd
> 588 root 0 -20 0 0 0 S 0 0.0 0:00.00 kpsmoused
> 616 root 0 -20 0 0 0 S 0 0.0 0:00.00 kvm-irqfd-clean
> 690 root 20 0 15188 392 200 S 0 0.0 0:00.00 upstart-socket-
> 745 root 20 0 0 0 0 S 0 0.0 0:00.03 ext4lazyinit
> 891 root 20 0 0 0 0 S 0 0.0 0:00.00 jbd2/md0-8
> 892 root 0 -20 0 0 0 S 0 0.0 0:00.00 ext4-dio-unwrit
> 913 root 20 0 0 0 0 S 0 0.0 0:00.06 flush-9:1
> 935 root 20 0 49956 2824 2220 S 0 0.1 0:00.00 sshd
> 990 messageb 20 0 23916 984 684 S 0 0.0 0:00.00 dbus-daemon
> 1017 root 20 0 15784 960 800 S 0 0.0 0:00.00 getty
> 1024 root 20 0 15784 964 800 S 0 0.0 0:00.00 getty
> 1037 root 20 0 15784 964 800 S 0 0.0 0:00.00 getty
> 1038 root 20 0 15784 960 800 S 0 0.0 0:00.00 getty
> 1041 root 20 0 15784 956 800 S 0 0.0 0:00.00 getty
> 1047 root 20 0 4328 688 560 S 0 0.0 0:00.00 acpid
> 1067 root 20 0 19112 1016 780 S 0 0.1 0:00.00 cron
> 1068 daemon 20 0 16908 372 216 S 0 0.0 0:00.00 atd
> 1080 root 20 0 15980 688 512 S 0 0.0 0:00.23 irqbalance
> 1107 whoopsie 20 0 195m 5092 3756 S 0 0.3 0:00.00 whoopsie
> 1486 root 20 0 13368 736 504 S 0 0.0 0:00.00 mdadm
> 1547 root 20 0 176m 12m 6540 S 0 0.6 0:00.10 /usr/sbin/apach
> 1560 root 20 0 215m 2060 1768 S 0 0.1 0:00.00 PassengerWatchd
> 1563 root 20 0 288m 2292 1996 S 0 0.1 0:00.01 PassengerHelper
> 1565 root 20 0 108m 8196 2164 S 0 0.4 0:00.03 ruby1.9.1
> 1568 nobody 20 0 165m 4684 3656 S 0 0.2 0:00.00 PassengerLoggin
> 1592 root 20 0 15784 964 800 S 0 0.0 0:00.00 getty
> 1595 www-data 20 0 176m 6860 660 S 0 0.3 0:00.00 /usr/sbin/apach
> 1596 www-data 20 0 176m 6860 660 S 0 0.3 0:00.00 /usr/sbin/apach
> 1597 www-data 20 0 176m 6860 660 S 0 0.3 0:00.00 /usr/sbin/apach
> 1598 www-data 20 0 176m 6860 660 S 0 0.3 0:00.00 /usr/sbin/apach
> 1599 www-data 20 0 176m 6860 660 S 0 0.3 0:00.00 /usr/sbin/apach
> 1874 ntp 20 0 37696 2244 1612 S 0 0.1 0:00.09 ntpd
> 2624 root 20 0 77488 3552 2732 S 0 0.2 0:00.01 sshd
> 2781 support 20 0 77808 1980 1128 S 0 0.1 0:00.68 sshd
> 2782 support 20 0 26560 7836 1760 S 0 0.4 0:00.31 bash
> 5775 root 20 0 0 0 0 S 0 0.0 0:00.13 kworker/0:2
> 6524 root 20 0 0 0 0 S 0 0.0 0:00.09 kworker/0:1
> 6651 root 20 0 12804 532 348 S 0 0.0 0:00.00 ossec-execd
> 6655 ossec 20 0 14508 2328 768 S 0 0.1 0:00.46 ossec-analysisd
> 6659 root 20 0 4528 560 420 S 0 0.0 0:00.00 ossec-logcollec
> 6670 root 20 0 5080 1096 488 S 0 0.1 0:00.65 ossec-syscheckd
> 6674 ossec 20 0 13060 548 364 S 0 0.0 0:00.00 ossec-monitord
> 7423 root 20 0 4400 616 512 S 0 0.0 0:00.00 sh
> 7426 root 20 0 4400 324 220 S 0 0.0 0:00.00 sh
> 7431 root 20 0 7160 352 276 S 0 0.0 0:00.00 sleep
> 7435 root 20 0 4308 320 216 S 0 0.0 0:00.00 autossh
> 7475 mysql 20 0 1113m 48m 8176 S 0 2.5 0:01.09 mysqld
> 7514 root 20 0 47480 13m 2756 S 0 0.7 0:00.02 tclsh
> 7578 root 20 0 17884 1588 1308 S 0 0.1 0:00.00 bash
> 7628 root 20 0 635m 21m 3952 S 0 1.1 0:02.83 bro
> 7766 root 20 0 17884 1584 1308 S 0 0.1 0:00.00 bash
> 7818 root 20 0 17884 1588 1308 S 0 0.1 0:00.00 bash
> 7822 root 20 0 17884 1584 1308 S 0 0.1 0:00.00 bash
> 7829 root 20 0 17884 1588 1308 S 0 0.1 0:00.00 bash
> 7981 root 20 0 33044 4836 2964 S 0 0.2 0:00.01 tclsh
> 8007 root 20 0 33044 4844 2964 S 0 0.2 0:00.01 tclsh
> 8033 root 20 0 33044 4844 2964 S 0 0.2 0:00.01 tclsh
> 8063 sguil 20 0 541m 205m 10m S 0 10.5 0:05.71 snort
> 8089 sguil 20 0 540m 205m 10m S 0 10.5 0:05.74 snort
> 8115 sguil 20 0 543m 207m 10m S 0 10.6 0:05.69 snort
> 8147 root 20 0 150m 51m 1772 S 0 2.6 0:18.45 barnyard2
> 8169 root 20 0 150m 51m 1772 S 0 2.6 0:20.09 barnyard2
> 8193 root 20 0 150m 51m 1752 S 0 2.6 0:10.19 barnyard2
> 8209 sguil 20 0 25728 6836 3636 S 0 0.3 0:00.01 prads
> 8228 root 20 0 32992 4740 2952 S 0 0.2 0:00.01 tclsh
> 8230 root 20 0 4328 356 280 S 0 0.0 0:00.00 cat
> 8251 root 20 0 33008 4708 2952 S 0 0.2 0:00.01 tclsh
> 8287 sguil 20 0 111m 6192 1144 S 0 0.3 0:00.12 argus
> 8293 root 20 0 102m 5460 204 S 0 0.3 0:00.00 searchd
> 8294 root 20 0 309m 24m 6076 S 0 1.2 0:01.45 searchd
> 8322 root 20 0 26780 440 200 S 0 0.0 0:00.00 syslog-ng
> 8323 root 20 0 70516 4200 2876 S 0 0.2 0:00.03 syslog-ng
> 8324 root 20 0 4400 612 508 S 0 0.0 0:00.00 sh
> 8326 root 20 0 201m 36m 3740 S 0 1.9 0:01.03 perl
> 8349 root 20 0 33020 4864 2972 S 0 0.2 0:00.01 tclsh
> 9177 root 20 0 4344 360 280 S 0 0.0 0:00.00 tail
> 9178 root 20 0 4344 356 280 S 0 0.0 0:00.00 tail
> 9180 root 20 0 4344 608 504 S 0 0.0 0:00.00 tail
> 9189 support 20 0 93552 21m 6300 S 0 1.1 0:00.75 wish
> 9200 root 20 0 4344 356 280 S 0 0.0 0:00.00 tail
> 9201 root 20 0 4340 612 512 S 0 0.0 0:00.00 tail
> 9210 root 20 0 0 0 0 S 0 0.0 0:00.00 kworker/0:0
> 9211 root 20 0 77488 3548 2732 S 0 0.2 0:00.01 sshd
> 9214 root 20 0 201m 34m 824 S 0 1.7 0:00.00 perl
> 9361 support 20 0 77488 1984 1140 S 0 0.1 0:00.00 sshd
> 9362 support 20 0 26484 7612 1624 S 0 0.4 0:00.21 bash
> 9684 root 20 0 43300 1872 1392 S 0 0.1 0:00.00 sudo
> 9816 root 20 0 12316 1472 1248 S 0 0.1 0:00.00 sostat
> 10419 root 20 0 17336 1272 916 R 0 0.1 0:00.00 top
>
>
> =========================================================================
> Log Archive
> =========================================================================
> /nsm/sensor_data/ITG-IDS-Sensor01-eth0/dailylogs/
> 8.0K .
> 4.0K ./2013-04-05
>
> /nsm/bro/logs/
> 20K .
> 16K ./stats
>
> =========================================================================
> IDS Engine (snort) packet drops
> =========================================================================
> ERROR: No stats found in /nsm/sensor_data/ITG-IDS-Sensor01-eth0/snort-1.stats
> ERROR: No stats found in /nsm/sensor_data/ITG-IDS-Sensor01-eth0/snort-2.stats
> ERROR: No stats found in /nsm/sensor_data/ITG-IDS-Sensor01-eth0/snort-3.stats
>
> =========================================================================
> pf_ring stats
> =========================================================================
> Appl. Name : <unknown>
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> Appl. Name : <unknown>
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> Appl. Name : <unknown>
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> Appl. Name : snort-cluster-51-socket-0
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> Appl. Name : snort-cluster-51-socket-0
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> Appl. Name : snort-cluster-51-socket-0
> Tot Packets : 0
> Tot Pkt Lost : 0
> TX: Send Errors : 0
> Reflect: Fwd Errors: 0
> support@ITG-IDS-Sensor01:~$