Here you are, I have to keep interfaces down, so there's no pf_ring
statistics, etc.
=========================================================================
Service Status
=========================================================================
Status: HIDS
* ossec_agent (sguil)[ OK ]
Status: Bro
Name Type Host Status Pid Peers
Started
manager manager 10.22.75.93 running 59497 1 29 Mar
09:19:13
proxy proxy 10.22.75.93 running 59544 1 29 Mar
09:19:15
Status: nsm1.hostname-eth4
* netsniff-ng (full packet data)[ FAIL ]
* pcap_agent (sguil)[ OK ]
* snort_agent-1 (sguil)[ OK ]
* snort_agent-2 (sguil)[ OK ]
* snort_agent-3 (sguil)[ OK ]
* snort_agent-4 (sguil)[ OK ]
* snort_agent-5 (sguil)[ OK ]
* snort_agent-6 (sguil)[ OK ]
* snort_agent-7 (sguil)[ OK ]
* snort_agent-8 (sguil)[ OK ]
* snort-1 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-2 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-3 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-4 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-5 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-6 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-7 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-8 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* barnyard2-1 (spooler, unified2 format)[ OK ]
* barnyard2-2 (spooler, unified2 format)[ OK ]
* barnyard2-3 (spooler, unified2 format)[ OK ]
* barnyard2-4 (spooler, unified2 format)[ OK ]
* barnyard2-5 (spooler, unified2 format)[ OK ]
* barnyard2-6 (spooler, unified2 format)[ OK ]
* barnyard2-7 (spooler, unified2 format)[ OK ]
* barnyard2-8 (spooler, unified2 format)[ OK ]
* prads (sessions/assets)[ FAIL ]
* sancp_agent (sguil)[ OK ]
* pads_agent (sguil)[ OK ]
* argus[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* http_agent (sguil)[ OK ]
Status: nsm1.hostname-eth5
* netsniff-ng (full packet data)[ FAIL ]
* pcap_agent (sguil)[ OK ]
* snort_agent-1 (sguil)[ OK ]
* snort_agent-2 (sguil)[ OK ]
* snort_agent-3 (sguil)[ OK ]
* snort_agent-4 (sguil)[ OK ]
* snort_agent-5 (sguil)[ OK ]
* snort_agent-6 (sguil)[ OK ]
* snort_agent-7 (sguil)[ OK ]
* snort_agent-8 (sguil)[ OK ]
* snort-1 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-2 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-3 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-4 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-5 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-6 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* snort-7 (alert data)[ OK ]
* snort-8 (alert data)[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* barnyard2-1 (spooler, unified2 format)[ OK ]
* barnyard2-2 (spooler, unified2 format)[ OK ]
* barnyard2-3 (spooler, unified2 format)[ OK ]
* barnyard2-4 (spooler, unified2 format)[ OK ]
* barnyard2-5 (spooler, unified2 format)[ OK ]
* barnyard2-6 (spooler, unified2 format)[ OK ]
* barnyard2-7 (spooler, unified2 format)[ OK ]
* barnyard2-8 (spooler, unified2 format)[ OK ]
* prads (sessions/assets)[ FAIL ]
* sancp_agent (sguil)[ OK ]
* pads_agent (sguil)[ OK ]
* argus[ FAIL ]
* stale PID file found, process will be restarted at the next
5-minute interval!
* http_agent (sguil)[ OK ]
=========================================================================
Interface Status
=========================================================================
eth0 Link encap:Ethernet HWaddr ac:16:2d:6f:75:00
inet addr:10.22.75.93 Bcast:10.22.75.255
Mask:255.255.255.0
inet6 addr: fe80::ae16:2dff:fe6f:7500/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:503574 errors:0 dropped:0 overruns:0 frame:0
TX packets:216626 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:100841822 (100.8 MB) TX bytes:131387807 (131.3
MB)
Interrupt:32
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:57942 errors:0 dropped:0 overruns:0 frame:0
TX packets:57942 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:32383523 (32.3 MB) TX bytes:32383523 (32.3 MB)
=========================================================================
Disk Usage
=========================================================================
Filesystem Size Used Avail Use% Mounted on
/dev/sda2 37G 3.4G 32G 10% /
udev 7.9G 4.0K 7.9G 1% /dev
tmpfs 3.2G 576K 3.2G 1% /run
none 5.0M 0 5.0M 0% /run/lock
none 7.9G 0 7.9G 0% /run/shm
/dev/sda1 460M 59M 378M 14% /boot
/dev/sda4 6.3T 3.3T 2.8T 55% /nsm
=========================================================================
Network Sockets
=========================================================================
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
rsyslogd 927 root 3u IPv4 1315 0t0 UDP *:514
rsyslogd 927 root 4u IPv6 1316 0t0 UDP *:514
rsyslogd 927 root 9u IPv4 168 0t0 UDP
*:34892
rsyslogd 927 root 11u IPv4 169 0t0 UDP
*:51558
rsyslogd 927 root 13u IPv4 12311 0t0 UDP
*:60189
rsyslogd 927 root 16u IPv4 2989 0t0 UDP
*:38805
rsyslogd 927 root 17u IPv4 23742 0t0 UDP
*:41503
rsyslogd 927 root 18u IPv4 23743 0t0 UDP
*:45054
rsyslogd 927 root 20u IPv4 20966 0t0 UDP
*:41474
sshd 1045 root 3r IPv4 1337 0t0 TCP *:22
(LISTEN)
sshd 1045 root 4u IPv6 1339 0t0 TCP *:22
(LISTEN)
mysqld 1217 mysql 10u IPv4 184 0t0 TCP
127.0.0.1:50000 (LISTEN)
ntpd 1442 ntp 16u IPv4 9735 0t0 UDP *:123
ntpd 1442 ntp 17u IPv6 9736 0t0 UDP *:123
ntpd 1442 ntp 18u IPv4 9742 0t0 UDP
127.0.0.1:123
ntpd 1442 ntp 19u IPv4 9743 0t0 UDP
10.22.75.93:123
ntpd 1442 ntp 20u IPv6 9744 0t0 UDP
[fe80::ae16:2dff:fe6f:7500]:123
ntpd 1442 ntp 21u IPv6 9745 0t0 UDP
[::1]:123
ruby 1817 root 5u IPv4 218 0t0 TCP
10.22.75.93:46842->
10.22.75.36:61613 (ESTABLISHED)
master 1956 root 12u IPv4 229 0t0 TCP *:25
(LISTEN)
master 1956 root 13u IPv6 230 0t0 TCP *:25
(LISTEN)
snmpd 1979 snmp 8u IPv4 20811 0t0 UDP
127.0.0.1:161
snmpd 1979 snmp 9u IPv4 20809 0t0 UDP
*:39068
searchd 1988 sphinxsearch 6u IPv4 16822 0t0 TCP *:9306
(LISTEN)
searchd 1988 sphinxsearch 7u IPv4 16823 0t0 TCP *:3307
(LISTEN)
/usr/sbin 2098 root 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 2098 root 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 2098 root 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
collectd 2132 root 5u IPv4 2036 0t0 TCP
10.22.75.93:47287->
10.22.75.142:2003 (ESTABLISHED)
ssh 2197 root 3r IPv4 30022 0t0 TCP
10.22.75.93:52310->
10.22.75.99:22 (ESTABLISHED)
ssh 2197 root 4u IPv6 30025 0t0 TCP
[::1]:3306 (LISTEN)
ssh 2197 root 5u IPv4 30026 0t0 TCP
127.0.0.1:3306 (LISTEN)
ssh 2197 root 6u IPv4 697982 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60558 (ESTABLISHED)
ssh 2197 root 7u IPv4 672375 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60580 (ESTABLISHED)
ssh 2197 root 8u IPv4 710718 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60582 (ESTABLISHED)
ssh 2197 root 9u IPv4 710720 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60584 (ESTABLISHED)
ssh 2197 root 10u IPv4 711696 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60586 (ESTABLISHED)
ssh 2197 root 11u IPv4 711697 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60588 (ESTABLISHED)
ssh 2197 root 12u IPv4 692864 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60590 (ESTABLISHED)
ssh 2197 root 13u IPv4 692865 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60592 (ESTABLISHED)
ssh 2197 root 14u IPv4 692866 0t0 TCP
127.0.0.1:3306->
127.0.0.1:60594 (ESTABLISHED)
nrpe 10040 nagios 3u IPv4 47455 0t0 TCP *:5666
(LISTEN)
sshd 57909 root 3r IPv4 697813 0t0 TCP
10.22.75.93:22->
10.22.75.6:36082 (ESTABLISHED)
sshd 57925 mpurzynski 3u IPv4 697813 0t0 TCP
10.22.75.93:22->
10.22.75.6:36082 (ESTABLISHED)
tclsh 59436 root 3u IPv4 697914 0t0 TCP
10.22.75.93:42521->
10.22.75.99:7736 (ESTABLISHED)
bro 59497 root 4u IPv4 697917 0t0 UDP
10.22.75.93:50230->
10.22.75.40:53
bro 59505 root 0u IPv4 668593 0t0 TCP
*:47761 (LISTEN)
bro 59505 root 1u IPv6 668594 0t0 TCP
*:47761 (LISTEN)
bro 59505 root 2u IPv4 688535 0t0 TCP
10.22.75.93:47761->
10.22.75.93:48374 (ESTABLISHED)
bro 59505 root 4u IPv4 697917 0t0 UDP
10.22.75.93:50230->
10.22.75.40:53
bro 59544 root 4u IPv4 697918 0t0 UDP
10.22.75.93:58558->
10.22.75.40:53
bro 59551 root 0u IPv4 687888 0t0 TCP
10.22.75.93:48374->
10.22.75.93:47761 (ESTABLISHED)
bro 59551 root 1u IPv4 687891 0t0 TCP
*:47762 (LISTEN)
bro 59551 root 2u IPv6 687892 0t0 TCP
*:47762 (LISTEN)
bro 59551 root 4u IPv4 697918 0t0 UDP
10.22.75.93:58558->
10.22.75.40:53
tclsh 59596 root 3u IPv4 697921 0t0 TCP
10.22.75.93:42523->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59616 root 3u IPv4 697924 0t0 TCP
10.22.75.93:42524->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59616 root 4u IPv4 672281 0t0 TCP
127.0.0.1:8001 (LISTEN)
tclsh 59616 root 6u IPv4 688547 0t0 TCP
127.0.0.1:8001->
127.0.0.1:36821 (ESTABLISHED)
tclsh 59634 root 3u IPv4 697927 0t0 TCP
10.22.75.93:42525->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59634 root 4u IPv4 697928 0t0 TCP
127.0.0.1:8002 (LISTEN)
tclsh 59652 root 3u IPv4 697931 0t0 TCP
10.22.75.93:42526->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59652 root 4u IPv4 697932 0t0 TCP
127.0.0.1:8003 (LISTEN)
tclsh 59670 root 3u IPv4 697935 0t0 TCP
10.22.75.93:42527->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59670 root 4u IPv4 697936 0t0 TCP
127.0.0.1:8004 (LISTEN)
tclsh 59688 root 3u IPv4 697939 0t0 TCP
10.22.75.93:42528->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59688 root 4u IPv4 697940 0t0 TCP
127.0.0.1:8005 (LISTEN)
tclsh 59706 root 3u IPv4 697943 0t0 TCP
10.22.75.93:42529->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59706 root 4u IPv4 697944 0t0 TCP
127.0.0.1:8006 (LISTEN)
tclsh 59724 root 3u IPv4 697948 0t0 TCP
10.22.75.93:42530->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59724 root 4u IPv4 697949 0t0 TCP
127.0.0.1:8007 (LISTEN)
tclsh 59742 root 3u IPv4 697952 0t0 TCP
10.22.75.93:42531->
10.22.75.99:7736 (ESTABLISHED)
tclsh 59742 root 4u IPv4 697953 0t0 TCP
127.0.0.1:8008 (LISTEN)
barnyard2 59990 root 3u IPv4 705704 0t0 TCP
127.0.0.1:36821->
127.0.0.1:8001 (ESTABLISHED)
barnyard2 59990 root 4u IPv4 705707 0t0 TCP
127.0.0.1:60558->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 60008 root 3u IPv4 686009 0t0 TCP
127.0.0.1:40896->
127.0.0.1:8002 (ESTABLISHED)
barnyard2 60026 root 3u IPv4 705708 0t0 TCP
127.0.0.1:54448->
127.0.0.1:8003 (ESTABLISHED)
barnyard2 60043 root 3u IPv4 691439 0t0 TCP
127.0.0.1:55000->
127.0.0.1:8004 (ESTABLISHED)
barnyard2 60060 root 3u IPv4 697035 0t0 TCP
127.0.0.1:60688->
127.0.0.1:8005 (ESTABLISHED)
barnyard2 60077 root 3u IPv4 706585 0t0 TCP
127.0.0.1:36642->
127.0.0.1:8006 (ESTABLISHED)
barnyard2 60094 root 3u IPv4 697985 0t0 TCP
127.0.0.1:59601->
127.0.0.1:8007 (ESTABLISHED)
barnyard2 60111 root 3u IPv4 690491 0t0 TCP
127.0.0.1:32772->
127.0.0.1:8008 (ESTABLISHED)
tclsh 60143 root 3u IPv4 672288 0t0 TCP
10.22.75.93:42541->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60160 root 3u IPv4 672289 0t0 TCP
10.22.75.93:42542->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60197 root 3u IPv4 697992 0t0 TCP
10.22.75.93:42543->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60241 root 3u IPv4 697998 0t0 TCP
10.22.75.93:42544->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60261 root 3u IPv4 698001 0t0 TCP
10.22.75.93:42545->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60261 root 4u IPv4 698002 0t0 TCP
127.0.0.1:8101 (LISTEN)
tclsh 60261 root 6u IPv4 703819 0t0 TCP
127.0.0.1:8101->
127.0.0.1:52558 (ESTABLISHED)
tclsh 60279 root 3u IPv4 698005 0t0 TCP
10.22.75.93:42546->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60279 root 4u IPv4 698006 0t0 TCP
127.0.0.1:8102 (LISTEN)
tclsh 60279 root 6u IPv4 693830 0t0 TCP
127.0.0.1:8102->
127.0.0.1:38962 (ESTABLISHED)
tclsh 60297 root 3u IPv4 698009 0t0 TCP
10.22.75.93:42547->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60297 root 4u IPv4 698010 0t0 TCP
127.0.0.1:8103 (LISTEN)
tclsh 60297 root 6u IPv4 686979 0t0 TCP
127.0.0.1:8103->
127.0.0.1:45279 (ESTABLISHED)
tclsh 60315 root 3u IPv4 698013 0t0 TCP
10.22.75.93:42548->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60315 root 4u IPv4 698014 0t0 TCP
127.0.0.1:8104 (LISTEN)
tclsh 60315 root 6u IPv4 703848 0t0 TCP
127.0.0.1:8104->
127.0.0.1:45817 (ESTABLISHED)
tclsh 60333 root 3u IPv4 698017 0t0 TCP
10.22.75.93:42549->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60333 root 4u IPv4 698018 0t0 TCP
127.0.0.1:8105 (LISTEN)
tclsh 60333 root 6u IPv4 698072 0t0 TCP
127.0.0.1:8105->
127.0.0.1:36908 (ESTABLISHED)
tclsh 60351 root 3u IPv4 698021 0t0 TCP
10.22.75.93:42550->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60351 root 4u IPv4 698022 0t0 TCP
127.0.0.1:8106 (LISTEN)
tclsh 60351 root 6u IPv4 703859 0t0 TCP
127.0.0.1:8106->
127.0.0.1:34581 (ESTABLISHED)
tclsh 60369 root 3u IPv4 698025 0t0 TCP
10.22.75.93:42551->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60369 root 4u IPv4 698026 0t0 TCP
127.0.0.1:8107 (LISTEN)
tclsh 60369 root 6u IPv4 703866 0t0 TCP
127.0.0.1:8107->
127.0.0.1:34874 (ESTABLISHED)
tclsh 60387 root 3u IPv4 698029 0t0 TCP
10.22.75.93:42552->
10.22.75.99:7736 (ESTABLISHED)
tclsh 60387 root 4u IPv4 698030 0t0 TCP
127.0.0.1:8108 (LISTEN)
tclsh 60387 root 6u IPv4 698075 0t0 TCP
127.0.0.1:8108->
127.0.0.1:56225 (ESTABLISHED)
barnyard2 61174 root 3u IPv4 693796 0t0 TCP
127.0.0.1:52558->
127.0.0.1:8101 (ESTABLISHED)
barnyard2 61174 root 4u IPv4 693799 0t0 TCP
127.0.0.1:60580->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61235 root 3u IPv4 707832 0t0 TCP
127.0.0.1:38962->
127.0.0.1:8102 (ESTABLISHED)
barnyard2 61235 root 4u IPv4 707835 0t0 TCP
127.0.0.1:60582->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61296 root 3u IPv4 691685 0t0 TCP
127.0.0.1:45279->
127.0.0.1:8103 (ESTABLISHED)
barnyard2 61296 root 4u IPv4 691688 0t0 TCP
127.0.0.1:60584->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61431 root 3u IPv4 691710 0t0 TCP
127.0.0.1:45817->
127.0.0.1:8104 (ESTABLISHED)
barnyard2 61431 root 4u IPv4 691713 0t0 TCP
127.0.0.1:60586->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61512 root 3u IPv4 709809 0t0 TCP
127.0.0.1:36908->
127.0.0.1:8105 (ESTABLISHED)
barnyard2 61512 root 4u IPv4 709812 0t0 TCP
127.0.0.1:60588->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61609 root 3u IPv4 693889 0t0 TCP
127.0.0.1:34581->
127.0.0.1:8106 (ESTABLISHED)
barnyard2 61609 root 4u IPv4 693892 0t0 TCP
127.0.0.1:60590->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61670 root 3u IPv4 691775 0t0 TCP
127.0.0.1:34874->
127.0.0.1:8107 (ESTABLISHED)
barnyard2 61670 root 4u IPv4 691778 0t0 TCP
127.0.0.1:60592->
127.0.0.1:3306 (ESTABLISHED)
barnyard2 61731 root 3u IPv4 693903 0t0 TCP
127.0.0.1:56225->
127.0.0.1:8108 (ESTABLISHED)
barnyard2 61731 root 4u IPv4 693906 0t0 TCP
127.0.0.1:60594->
127.0.0.1:3306 (ESTABLISHED)
tclsh 61850 root 3u IPv4 701357 0t0 TCP
10.22.75.93:42570->
10.22.75.99:7736 (ESTABLISHED)
tclsh 61910 root 3u IPv4 713926 0t0 TCP
10.22.75.93:42571->
10.22.75.99:7736 (ESTABLISHED)
/usr/sbin 61996 www-data 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 61996 www-data 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 61996 www-data 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
/usr/sbin 61997 www-data 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 61997 www-data 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 61997 www-data 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
/usr/sbin 61998 www-data 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 61998 www-data 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 61998 www-data 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
/usr/sbin 61999 www-data 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 61999 www-data 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 61999 www-data 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
/usr/sbin 62000 www-data 4u IPv4 20819 0t0 TCP *:443
(LISTEN)
/usr/sbin 62000 www-data 5u IPv4 20822 0t0 TCP *:9876
(LISTEN)
/usr/sbin 62000 www-data 6u IPv4 20824 0t0 TCP *:444
(LISTEN)
tclsh 62112 root 3u IPv4 698096 0t0 TCP
10.22.75.93:42572->
10.22.75.99:7736 (ESTABLISHED)
=========================================================================
IDS Rules Update
=========================================================================
Fri Mar 29 07:01:01 UTC 2013
Backing up current downloaded.rules file before it gets overwritten.
Cleaning up downloaded.rules backup files older than 30 days.
Backing up current local.rules file before it gets overwritten.
Cleaning up local.rules backup files older than 30 days.
Sleeping for 5 minutes to allow master time to download new rules.
Copying rules from nsmserver1.hostname.
Restarting Barnyard2.
Restarting: nsm1.hostname-eth4
* stopping: barnyard2-1 (spooler, unified2 format)[ OK ]
* starting: barnyard2-1 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-2 (spooler, unified2 format)[ OK ]
* starting: barnyard2-2 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-3 (spooler, unified2 format)[ OK ]
* starting: barnyard2-3 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-4 (spooler, unified2 format)[ OK ]
* starting: barnyard2-4 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-5 (spooler, unified2 format)[ OK ]
* starting: barnyard2-5 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-6 (spooler, unified2 format)[ OK ]
* starting: barnyard2-6 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-7 (spooler, unified2 format)[ OK ]
* starting: barnyard2-7 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-8 (spooler, unified2 format)[ OK ]
* starting: barnyard2-8 (spooler, unified2 format)[ OK ]
Restarting: nsm1.hostname-eth5
* stopping: barnyard2-1 (spooler, unified2 format)[ OK ]
* starting: barnyard2-1 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-2 (spooler, unified2 format)[ OK ]
* starting: barnyard2-2 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-3 (spooler, unified2 format)[ OK ]
* starting: barnyard2-3 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-4 (spooler, unified2 format)[ OK ]
* starting: barnyard2-4 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-5 (spooler, unified2 format)[ OK ]
* starting: barnyard2-5 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-6 (spooler, unified2 format)[ OK ]
* starting: barnyard2-6 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-7 (spooler, unified2 format)[ OK ]
* starting: barnyard2-7 (spooler, unified2 format)[ OK ]
* stopping: barnyard2-8 (spooler, unified2 format)[ OK ]
* starting: barnyard2-8 (spooler, unified2 format)[ OK ]
Restarting IDS Engine.
Restarting: nsm1.hostname-eth4
* stopping: snort-1 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-1 (alert data)[ OK ]
* stopping: snort-2 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-2 (alert data)[ OK ]
* stopping: snort-3 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-3 (alert data)[ OK ]
* stopping: snort-4 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-4 (alert data)[ OK ]
* stopping: snort-5 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-5 (alert data)[ OK ]
* stopping: snort-6 (alert data)[ FAIL ]
* starting: snort-6 (alert data) (already running)[ WARN ]
* stopping: snort-7 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-7 (alert data)[ OK ]
* stopping: snort-8 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-8 (alert data)[ OK ]
Restarting: nsm1.hostname-eth5
* stopping: snort-1 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-1 (alert data)[ OK ]
* stopping: snort-2 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-2 (alert data)[ OK ]
* stopping: snort-3 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-3 (alert data)[ OK ]
* stopping: snort-4 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-4 (alert data)[ OK ]
* stopping: snort-5 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-5 (alert data)[ OK ]
* stopping: snort-6 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-6 (alert data)[ OK ]
* stopping: snort-7 (alert data)[ FAIL ]
* starting: snort-7 (alert data) (already running)[ WARN ]
* stopping: snort-8 (alert data) (not running)[ WARN ]
- stale PID file found, deleting!
* starting: snort-8 (alert data)[ OK ]
=========================================================================
CPU Usage
=========================================================================
top - 09:21:52 up 8:59, 1 user, load average: 0.80, 1.02, 0.92
Tasks: 300 total, 1 running, 299 sleeping, 0 stopped, 0 zombie
Cpu(s): 0.8%us, 1.9%sy, 0.2%ni, 97.1%id, 0.0%wa, 0.0%hi,
0.0%si, 0.0%st
Mem: 16394156k total, 1367668k used, 15026488k free, 167852k
buffers
Swap: 976636k total, 0k used, 976636k free, 299952k
cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+
COMMAND
59551 root 25 5 62832 19m 952 S 10 0.1 0:14.61
bro
59505 root 25 5 133m 19m 936 S 8 0.1 0:15.14
bro
61670 root 20 0 129m 31m 1776 S 2 0.2 0:05.18
barnyard2
62695 root 20 0 17468 1404 916 R 2 0.0 0:00.01
top
1 root 20 0 24336 2324 1364 S 0 0.0 0:03.48
init
2 root 20 0 0 0 0 S 0 0.0 0:00.00
kthreadd
3 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/0
5 root 20 0 0 0 0 S 0 0.0 0:00.24
kworker/u:0
6 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/0
7 root RT 0 0 0 0 S 0 0.0 0:00.04
watchdog/0
8 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/1
9 root 20 0 0 0 0 S 0 0.0 0:00.20
kworker/1:0
10 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/1
12 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/1
13 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/2
14 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/2:0
15 root 20 0 0 0 0 S 0 0.0 0:00.00
ksoftirqd/2
16 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/2
17 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/3
18 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/3:0
19 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/3
20 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/3
21 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/4
22 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/4:0
23 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/4
24 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/4
25 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/5
26 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/5:0
27 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/5
28 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/5
29 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/6
31 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/6
32 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/6
33 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/7
34 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/7:0
35 root 20 0 0 0 0 S 0 0.0 0:00.00
ksoftirqd/7
36 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/7
37 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/8
38 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/8:0
39 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/8
40 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/8
41 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/9
42 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/9:0
43 root 20 0 0 0 0 S 0 0.0 0:00.00
ksoftirqd/9
44 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/9
45 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/10
46 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/10:0
47 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/10
48 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/10
49 root RT 0 0 0 0 S 0 0.0 0:00.07
migration/11
50 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/11:0
51 root 20 0 0 0 0 S 0 0.0 0:00.01
ksoftirqd/11
52 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/11
53 root RT 0 0 0 0 S 0 0.0 0:00.08
migration/12
54 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/12:0
55 root 20 0 0 0 0 S 0 0.0 0:00.02
ksoftirqd/12
56 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/12
57 root RT 0 0 0 0 S 0 0.0 0:00.20
migration/13
58 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/13:0
59 root 20 0 0 0 0 S 0 0.0 0:00.11
ksoftirqd/13
60 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/13
61 root RT 0 0 0 0 S 0 0.0 0:00.19
migration/14
62 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/14:0
63 root 20 0 0 0 0 S 0 0.0 0:00.16
ksoftirqd/14
64 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/14
65 root RT 0 0 0 0 S 0 0.0 0:00.14
migration/15
66 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/15:0
67 root 20 0 0 0 0 S 0 0.0 0:00.18
ksoftirqd/15
68 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/15
69 root RT 0 0 0 0 S 0 0.0 0:00.47
migration/16
71 root 20 0 0 0 0 S 0 0.0 0:00.09
ksoftirqd/16
72 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/16
73 root RT 0 0 0 0 S 0 0.0 0:00.10
migration/17
74 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/17:0
75 root 20 0 0 0 0 S 0 0.0 0:00.04
ksoftirqd/17
76 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/17
77 root RT 0 0 0 0 S 0 0.0 0:00.10
migration/18
78 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/18:0
79 root 20 0 0 0 0 S 0 0.0 0:00.05
ksoftirqd/18
80 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/18
81 root RT 0 0 0 0 S 0 0.0 0:00.24
migration/19
82 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/19:0
83 root 20 0 0 0 0 S 0 0.0 0:00.13
ksoftirqd/19
84 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/19
85 root RT 0 0 0 0 S 0 0.0 0:00.18
migration/20
86 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/20:0
87 root 20 0 0 0 0 S 0 0.0 0:00.14
ksoftirqd/20
88 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/20
89 root RT 0 0 0 0 S 0 0.0 0:00.14
migration/21
90 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/21:0
91 root 20 0 0 0 0 S 0 0.0 0:00.16
ksoftirqd/21
92 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/21
93 root RT 0 0 0 0 S 0 0.0 0:00.12
migration/22
94 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/22:0
95 root 20 0 0 0 0 S 0 0.0 0:00.12
ksoftirqd/22
96 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/22
97 root RT 0 0 0 0 S 0 0.0 0:00.12
migration/23
98 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/23:0
99 root 20 0 0 0 0 S 0 0.0 0:00.05
ksoftirqd/23
100 root RT 0 0 0 0 S 0 0.0 0:00.02
watchdog/23
101 root 0 -20 0 0 0 S 0 0.0 0:00.00
cpuset
102 root 0 -20 0 0 0 S 0 0.0 0:00.00
khelper
103 root 20 0 0 0 0 S 0 0.0 0:00.00
kdevtmpfs
104 root 0 -20 0 0 0 S 0 0.0 0:00.00
netns
105 root 20 0 0 0 0 S 0 0.0 0:00.26
kworker/u:1
106 root 20 0 0 0 0 S 0 0.0 0:00.02
sync_supers
107 root 20 0 0 0 0 S 0 0.0 0:00.00
bdi-default
108 root 0 -20 0 0 0 S 0 0.0 0:00.00
kintegrityd
109 root 0 -20 0 0 0 S 0 0.0 0:00.00
kblockd
110 root 0 -20 0 0 0 S 0 0.0 0:00.00
ata_sff
111 root 20 0 0 0 0 S 0 0.0 0:00.00
khubd
112 root 0 -20 0 0 0 S 0 0.0 0:00.00
md
113 root 20 0 0 0 0 S 0 0.0 0:00.40
kworker/5:1
115 root 20 0 0 0 0 S 0 0.0 0:00.00
khungtaskd
116 root 20 0 0 0 0 S 0 0.0 0:00.00
kswapd0
117 root 20 0 0 0 0 S 0 0.0 0:00.00
kswapd1
118 root 25 5 0 0 0 S 0 0.0 0:00.00
ksmd
119 root 39 19 0 0 0 S 0 0.0 0:00.00
khugepaged
120 root 20 0 0 0 0 S 0 0.0 0:00.00
fsnotify_mark
121 root 20 0 0 0 0 S 0 0.0 0:00.00
ecryptfs-kthrea
122 root 0 -20 0 0 0 S 0 0.0 0:00.00
crypto
130 root 0 -20 0 0 0 S 0 0.0 0:00.00
kthrotld
131 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/6:1
132 root 20 0 0 0 0 S 0 0.0 0:00.02
scsi_eh_0
133 root 20 0 0 0 0 S 0 0.0 0:00.00
scsi_eh_1
155 root 0 -20 0 0 0 S 0 0.0 0:00.00
devfreq_wq
157 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/23:1
158 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/22:1
159 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/21:1
160 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/20:1
161 root 20 0 0 0 0 S 0 0.0 0:01.12
kworker/19:1
162 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/18:1
163 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/17:1
164 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/16:1
165 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/15:1
166 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/14:1
167 root 20 0 0 0 0 S 0 0.0 0:00.19
kworker/13:1
168 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/12:1
169 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/11:1
170 root 20 0 0 0 0 S 0 0.0 0:00.20
kworker/10:1
171 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/9:1
172 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/8:1
173 root 20 0 0 0 0 S 0 0.0 0:00.16
kworker/7:1
174 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/4:1
175 root 20 0 0 0 0 S 0 0.0 0:00.17
kworker/3:1
176 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/2:1
452 root 20 0 0 0 0 S 0 0.0 0:00.00
scsi_eh_2
454 root 20 0 0 0 0 S 0 0.0 0:00.00
hpsa
472 root 20 0 0 0 0 S 0 0.0 0:00.48
jbd2/sda2-8
473 root 0 -20 0 0 0 S 0 0.0 0:00.00
ext4-dio-unwrit
556 root 20 0 0 0 0 S 0 0.0 0:00.21
kworker/6:2
573 root 20 0 0 0 0 S 0 0.0 0:00.00
jbd2/sda1-8
574 root 0 -20 0 0 0 S 0 0.0 0:00.00
ext4-dio-unwrit
587 root 20 0 18040 1428 532 S 0 0.0 0:00.12
upstart-udev-br
594 root 20 0 21656 1468 804 S 0 0.0 0:00.08
udevd
601 root 20 0 0 0 0 S 0 0.0 0:00.38
jbd2/sda4-8
603 root 0 -20 0 0 0 S 0 0.0 0:00.00
ext4-dio-unwrit
676 root 20 0 21596 1000 456 S 0 0.0 0:00.16
udevd
764 root 0 -20 0 0 0 S 0 0.0 0:00.00
edac-poller
818 root 0 -20 0 0 0 S 0 0.0 0:00.00
kpsmoused
927 root 20 0 311m 1964 1180 S 0 0.0 0:08.21
rsyslogd
943 messageb 20 0 23816 696 440 S 0 0.0 0:00.01
dbus-daemon
946 root 20 0 0 0 0 S 0 0.0 0:00.34
flush-8:0
947 root 20 0 0 0 0 S 0 0.0 0:00.18
kworker/16:2
1040 root 20 0 15188 392 196 S 0 0.0 0:00.00
upstart-socket-
1045 root 20 0 49956 2872 2264 S 0 0.0 0:00.07
sshd
1158 root 20 0 14504 964 800 S 0 0.0 0:00.00
getty
1162 root 20 0 14504 968 800 S 0 0.0 0:00.00
getty
1167 root 20 0 14504 968 800 S 0 0.0 0:00.00
getty
1168 root 20 0 14504 956 800 S 0 0.0 0:00.00
getty
1171 root 20 0 14504 956 800 S 0 0.0 0:00.00
getty
1179 root 20 0 19112 1020 780 S 0 0.0 0:00.09
cron
1180 daemon 20 0 16908 376 216 S 0 0.0 0:00.00
atd
1217 mysql 20 0 537m 46m 7280 S 0 0.3 0:03.81
mysqld
1442 ntp 20 0 33456 2088 1492 S 0 0.0 0:00.50
ntpd
1447 root 20 0 213m 1396 664 S 0 0.0 0:01.27
hpasmlited
1800 root 20 0 51148 1580 976 S 0 0.0 0:04.90
lldpd
1803 _lldpd 20 0 46908 700 208 S 0 0.0 0:02.89
lldpd
1817 root 20 0 153m 12m 2232 S 0 0.1 0:00.02
ruby
1956 root 20 0 25108 1668 1356 S 0 0.0 0:00.05
master
1975 postfix 20 0 27336 1796 1452 S 0 0.0 0:00.02
qmgr
1979 snmp 20 0 48804 5188 2568 S 0 0.0 0:06.83
snmpd
1987 sphinxse 20 0 102m 5460 208 S 0 0.0 0:00.00
searchd
1988 sphinxse 20 0 183m 18m 7476 S 0 0.1 0:07.70
searchd
2032 root 16 -4 46232 972 604 S 0 0.0 0:03.30
auditd
2034 root 12 -8 80264 860 688 S 0 0.0 0:05.38
audispd
2035 root 16 -4 19152 1120 908 S 0 0.0 0:12.68
audisp-cef
2037 root 20 0 0 0 0 S 0 0.0 0:01.59
kauditd
2098 root 20 0 178m 15m 8808 S 0 0.1 0:00.46
/usr/sbin/apach
2130 root 20 0 4292 292 200 S 0 0.0 0:00.00
collectdmon
2132 root 20 0 572m 7588 3632 S 0 0.0 0:46.94
collectd
2153 root 20 0 14504 960 800 S 0 0.0 0:00.00
getty
2195 root 20 0 4308 316 216 S 0 0.0 0:00.00
autossh
2197 root 20 0 44996 4416 2480 S 0 0.0 0:01.16
ssh
2245 root 20 0 4340 360 280 S 0 0.0 0:00.00
tail
2877 root 20 0 4344 612 504 S 0 0.0 0:00.00
tail
2895 root 20 0 4344 608 504 S 0 0.0 0:00.00
tail
2913 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
2931 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
2949 root 20 0 4344 608 504 S 0 0.0 0:00.00
tail
2974 root 20 0 4344 612 504 S 0 0.0 0:00.00
tail
2992 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
3010 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
3456 root 20 0 4340 608 512 S 0 0.0 0:00.00
tail
3521 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
3539 root 20 0 4344 360 280 S 0 0.0 0:00.00
tail
3557 root 20 0 4344 608 504 S 0 0.0 0:00.00
tail
3575 root 20 0 4344 356 280 S 0 0.0 0:00.00
tail
3593 root 20 0 4344 608 504 S 0 0.0 0:00.00
tail
3611 root 20 0 4344 612 504 S 0 0.0 0:00.00
tail
3629 root 20 0 4344 356 280 S 0 0.0 0:00.00
tail
3647 root 20 0 4344 612 504 S 0 0.0 0:00.00
tail
4100 root 20 0 4340 612 516 S 0 0.0 0:00.00
tail
6822 root 20 0 21408 832 408 S 0 0.0 0:00.00
udevd
10020 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/1:1
10040 nagios 20 0 25464 1204 688 S 0 0.0 0:00.82
nrpe
41842 root 20 0 0 0 0 S 0 0.0 0:00.02
kworker/0:0
43201 postfix 20 0 27172 1528 1248 S 0 0.0 0:00.00
pickup
51894 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/0:2
54533 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/0:3
57909 root 20 0 79536 3620 2784 S 0 0.0 0:00.01
sshd
57925 mpurzyns 20 0 79536 1744 908 S 0 0.0 0:00.04
sshd
57926 mpurzyns 20 0 25472 7992 1692 S 0 0.0 0:00.46
bash
59436 root 20 0 43716 5240 2680 S 0 0.0 0:00.00
tclsh
59437 root 20 0 5912 616 520 S 0 0.0 0:00.00
tail
59488 root 20 0 11056 1528 1284 S 0 0.0 0:00.00
bash
59497 root 20 0 491m 21m 3916 S 0 0.1 0:01.22
bro
59535 root 20 0 11056 1528 1284 S 0 0.0 0:00.00
bash
59544 root 20 0 203m 20m 3924 S 0 0.1 0:01.20
bro
59596 root 20 0 39232 5336 3148 S 0 0.0 0:00.04
tclsh
59616 root 20 0 38816 5052 3140 S 0 0.0 0:00.03
tclsh
59618 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
59634 root 20 0 38816 5040 3132 S 0 0.0 0:00.02
tclsh
59636 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
59652 root 20 0 38816 5040 3132 S 0 0.0 0:00.03
tclsh
59654 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
59670 root 20 0 38816 5044 3132 S 0 0.0 0:00.03
tclsh
59672 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
59688 root 20 0 38816 5040 3132 S 0 0.0 0:00.02
tclsh
59690 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
59706 root 20 0 38816 5044 3132 S 0 0.0 0:00.02
tclsh
59708 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
59724 root 20 0 38816 5048 3136 S 0 0.0 0:00.02
tclsh
59726 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
59742 root 20 0 38816 5044 3132 S 0 0.0 0:00.03
tclsh
59744 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
59990 root 20 0 129m 31m 1776 S 0 0.2 0:05.16
barnyard2
60008 root 20 0 29956 4112 1256 S 0 0.0 0:00.54
barnyard2
60010 root 20 0 0 0 0 S 0 0.0 0:00.00
kworker/0:1
60026 root 20 0 29956 4108 1256 S 0 0.0 0:00.54
barnyard2
60043 root 20 0 29956 4116 1256 S 0 0.0 0:00.50
barnyard2
60060 root 20 0 29956 4112 1256 S 0 0.0 0:00.52
barnyard2
60077 root 20 0 29956 4108 1256 S 0 0.0 0:00.54
barnyard2
60094 root 20 0 29956 4108 1256 S 0 0.0 0:00.51
barnyard2
60111 root 20 0 29956 4108 1256 S 0 0.0 0:00.51
barnyard2
60143 root 20 0 38792 5020 3132 S 0 0.0 0:00.02
tclsh
60145 root 20 0 5900 360 280 S 0 0.0 0:00.00
cat
60160 root 20 0 38808 4940 3116 S 0 0.0 0:00.02
tclsh
60197 root 20 0 38836 5052 3136 S 0 0.0 0:00.03
tclsh
60199 root 20 0 5912 684 584 S 0 0.0 0:00.00
tail
60241 root 20 0 39232 5332 3144 S 0 0.0 0:00.03
tclsh
60261 root 20 0 38816 5048 3140 S 0 0.0 0:00.02
tclsh
60263 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
60279 root 20 0 38816 5052 3140 S 0 0.0 0:00.03
tclsh
60281 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
60297 root 20 0 38816 5052 3140 S 0 0.0 0:00.03
tclsh
60299 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
60315 root 20 0 38816 5052 3140 S 0 0.0 0:00.03
tclsh
60317 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
60333 root 20 0 38816 5048 3140 S 0 0.0 0:00.03
tclsh
60335 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
60351 root 20 0 38816 5052 3140 S 0 0.0 0:00.03
tclsh
60353 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
60369 root 20 0 38816 5048 3140 S 0 0.0 0:00.02
tclsh
60371 root 20 0 5916 612 520 S 0 0.0 0:00.00
tail
60387 root 20 0 38816 5052 3144 S 0 0.0 0:00.03
tclsh
60389 root 20 0 5916 616 520 S 0 0.0 0:00.00
tail
61174 root 20 0 129m 31m 1776 S 0 0.2 0:05.17
barnyard2
61235 root 20 0 129m 31m 1776 S 0 0.2 0:05.15
barnyard2
61296 root 20 0 129m 31m 1776 S 0 0.2 0:05.12
barnyard2
61431 root 20 0 129m 31m 1776 S 0 0.2 0:05.34
barnyard2
61512 root 20 0 129m 31m 1776 S 0 0.2 0:05.12
barnyard2
61609 root 20 0 129m 31m 1776 S 0 0.2 0:05.21
barnyard2
61731 root 20 0 129m 31m 1776 S 0 0.2 0:05.30
barnyard2
61850 root 20 0 38792 5024 3136 S 0 0.0 0:00.03
tclsh
61852 root 20 0 5900 360 280 S 0 0.0 0:00.00
cat
61910 root 20 0 38808 4940 3116 S 0 0.0 0:00.02
tclsh
61957 root 20 0 215m 2052 1772 S 0 0.0 0:00.00
PassengerWatchd
61961 root 20 0 288m 2288 2000 S 0 0.0 0:00.02
PassengerHelper
61963 root 20 0 108m 8200 2164 S 0 0.1 0:00.07
ruby1.9.1
61967 nobody 20 0 165m 4676 3644 S 0 0.0 0:00.01
PassengerLoggin
61996 www-data 20 0 178m 8064 1296 S 0 0.0 0:00.00
/usr/sbin/apach
61997 www-data 20 0 178m 7340 632 S 0 0.0 0:00.00
/usr/sbin/apach
61998 www-data 20 0 178m 7340 632 S 0 0.0 0:00.00
/usr/sbin/apach
61999 www-data 20 0 178m 7340 632 S 0 0.0 0:00.00
/usr/sbin/apach
62000 www-data 20 0 178m 7340 632 S 0 0.0 0:00.00
/usr/sbin/apach
62112 root 20 0 38836 4956 3112 S 0 0.0 0:00.02
tclsh
62114 root 20 0 5912 684 584 S 0 0.0 0:00.00
tail
62147 root 20 0 48224 1880 1448 S 0 0.0 0:00.00
sudo
62148 root 20 0 11036 1476 1252 S 0 0.0 0:00.00
sostat
=========================================================================
Log Archive
=========================================================================
/nsm/sensor_data/nsm1.hostname-eth4/dailylogs/
659G .
637G ./2013-03-23
7.2G ./2013-03-28
15G ./2013-03-29
/nsm/sensor_data/nsm1.hostname-eth5/dailylogs/
2.6T .
2.6T ./2013-03-23
6.8G ./2013-03-28
2.2G ./2013-03-29
/nsm/bro/logs/
1.6M .
36K ./20--
236K ./2013-03-28
268K ./2013-03-29
1.1M ./stats
=========================================================================
IDS Engine (snort) packet drops
=========================================================================
/nsm/sensor_data/nsm1.hostname-eth4/snort-1.stats last reported
pkt_drop_percent as 49.253
/nsm/sensor_data/nsm1.hostname-eth4/snort-2.stats last reported
pkt_drop_percent as 42.387
/nsm/sensor_data/nsm1.hostname-eth4/snort-3.stats last reported
pkt_drop_percent as 58.134
/nsm/sensor_data/nsm1.hostname-eth4/snort-4.stats last reported
pkt_drop_percent as 64.234
/nsm/sensor_data/nsm1.hostname-eth4/snort-5.stats last reported
pkt_drop_percent as 67.864
/nsm/sensor_data/nsm1.hostname-eth4/snort-6.stats last reported
pkt_drop_percent as 57.978
/nsm/sensor_data/nsm1.hostname-eth4/snort-7.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth4/snort-8.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-10.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-11.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-12.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-13.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-14.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-15.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-16.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-1.stats last reported
pkt_drop_percent as 42.677
/nsm/sensor_data/nsm1.hostname-eth5/snort-2.stats last reported
pkt_drop_percent as 36.215
/nsm/sensor_data/nsm1.hostname-eth5/snort-3.stats last reported
pkt_drop_percent as 0.000
/nsm/sensor_data/nsm1.hostname-eth5/snort-4.stats last reported
pkt_drop_percent as 58.137
/nsm/sensor_data/nsm1.hostname-eth5/snort-5.stats last reported
pkt_drop_percent as 24.771
/nsm/sensor_data/nsm1.hostname-eth5/snort-6.stats last reported
pkt_drop_percent as 33.672
/nsm/sensor_data/nsm1.hostname-eth5/snort-7.stats last reported
pkt_drop_percent as 67.527
/nsm/sensor_data/nsm1.hostname-eth5/snort-8.stats last reported
pkt_drop_percent as 33.540
/nsm/sensor_data/nsm1.hostname-eth5/snort-9.stats last reported
pkt_drop_percent as 0.000
=========================================================================
pf_ring stats
=========================================================================