Advertisement
Queena

suricata.log

Jun 12th, 2014
278
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.47 KB | None | 0 0
  1. 12/6/2014 -- 16:45:36 - <Notice> - This is Suricata version 2.0.1 RELEASE
  2. 12/6/2014 -- 16:45:36 - <Info> - CPUs/cores online: 24
  3. 12/6/2014 -- 16:45:36 - <Info> - 'default' server has 'request-body-minimal-inspect-size' set to 33882 and 'request-body-inspect-window' set to 4053 after randomization.
  4. 12/6/2014 -- 16:45:36 - <Info> - 'default' server has 'response-body-minimal-inspect-size' set to 33695 and 'response-body-inspect-window' set to 4218 after randomization.
  5. 12/6/2014 -- 16:45:36 - <Info> - DNS request flood protection level: 500
  6. 12/6/2014 -- 16:45:36 - <Info> - DNS per flow memcap (state-memcap): 524288
  7. 12/6/2014 -- 16:45:36 - <Info> - DNS global memcap: 16777216
  8. 12/6/2014 -- 16:45:36 - <Info> - allocated 3670016 bytes of memory for the defrag hash... 65536 buckets of size 56
  9. 12/6/2014 -- 16:45:36 - <Info> - preallocated 65535 defrag trackers of size 152
  10. 12/6/2014 -- 16:45:36 - <Info> - defrag memory usage: 13631336 bytes, maximum: 536870912
  11. 12/6/2014 -- 16:45:36 - <Info> - AutoFP mode using default "Active Packets" flow load balancer
  12. 12/6/2014 -- 16:45:36 - <Info> - preallocated 65534 packets. Total memory 228713660
  13. 12/6/2014 -- 16:45:36 - <Info> - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64
  14. 12/6/2014 -- 16:45:36 - <Info> - preallocated 1000 hosts of size 112
  15. 12/6/2014 -- 16:45:36 - <Info> - host memory usage: 390144 bytes, maximum: 16777216
  16. 12/6/2014 -- 16:45:37 - <Info> - allocated 67108864 bytes of memory for the flow hash... 1048576 buckets of size 64
  17. 12/6/2014 -- 16:45:37 - <Info> - preallocated 1048576 flows of size 280
  18. 12/6/2014 -- 16:45:37 - <Info> - flow memory usage: 369098752 bytes, maximum: 1073741824
  19. 12/6/2014 -- 16:45:37 - <Info> - IP reputation disabled
  20. 12/6/2014 -- 16:45:37 - <Info> - using magic-file /usr/share/file/magic
  21. 12/6/2014 -- 16:45:37 - <Info> - Delayed detect disabled
  22. 12/6/2014 -- 16:45:37 - <Info> - 1 rule files processed. 1 rules successfully loaded, 0 rules failed
  23. 12/6/2014 -- 16:45:37 - <Info> - 1 signatures processed. 0 are IP-only rules, 0 are inspecting packet payload, 1 inspect application layer, 0 are decoder event only
  24. 12/6/2014 -- 16:45:37 - <Info> - building signature grouping structure, stage 1: preprocessing rules... complete
  25. 12/6/2014 -- 16:45:37 - <Info> - building signature grouping structure, stage 2: building source address list... complete
  26. 12/6/2014 -- 16:45:37 - <Info> - building signature grouping structure, stage 3: building destination address lists... complete
  27. 12/6/2014 -- 16:45:37 - <Warning> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "/usr/local/etc/suricata//threshold.config": No such file or directory
  28. 12/6/2014 -- 16:45:37 - <Info> - Core dump size set to unlimited.
  29. 12/6/2014 -- 16:45:37 - <Info> - fast output device (regular) initialized: fast.log
  30. 12/6/2014 -- 16:45:37 - <Info> - eve-log output device (regular) initialized: eve.json
  31. 12/6/2014 -- 16:45:37 - <Info> - returning output_ctx 0x2326a740
  32. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'alert'
  33. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'http'
  34. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'dns'
  35. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'tls'
  36. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'files'
  37. 12/6/2014 -- 16:45:37 - <Info> - forcing magic lookup for logged files
  38. 12/6/2014 -- 16:45:37 - <Info> - forcing md5 calculation for logged files
  39. 12/6/2014 -- 16:45:37 - <Info> - enabling 'eve-log' module 'ssh'
  40. 12/6/2014 -- 16:45:37 - <Info> - Unified2-alert initialized: filename unified2.alert, limit 32 MB
  41. 12/6/2014 -- 16:45:37 - <Info> - http-log output device (regular) initialized: http.log
  42. 12/6/2014 -- 16:45:37 - <Info> - Adding interface eth3 from config file
  43. 12/6/2014 -- 16:45:37 - <Info> - Enabling mmaped capture on iface eth3
  44. 12/6/2014 -- 16:45:37 - <Info> - Using cpu cluster mode for AF_PACKET (iface eth3)
  45. 12/6/2014 -- 16:45:37 - <Info> - Going to use 16 thread(s)
  46. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  47. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  48. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  49. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  50. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  51. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  52. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  53. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  54. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  55. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  56. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  57. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  58. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  59. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  60. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  61. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  62. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  63. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  64. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  65. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  66. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  67. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  68. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  69. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  70. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  71. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  72. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  73. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  74. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  75. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  76. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode
  77. 12/6/2014 -- 16:45:37 - <Info> - Enabling zero copy mode by using data release call
  78. 12/6/2014 -- 16:45:37 - <Info> - RunModeIdsAFPWorkers initialised
  79. 12/6/2014 -- 16:45:37 - <Info> - stream "prealloc-sessions": 2048 (per thread)
  80. 12/6/2014 -- 16:45:37 - <Info> - stream "memcap": 17179869184
  81. 12/6/2014 -- 16:45:37 - <Info> - stream "midstream" session pickups: enabled
  82. 12/6/2014 -- 16:45:37 - <Info> - stream "async-oneside": disabled
  83. 12/6/2014 -- 16:45:37 - <Info> - stream "checksum-validation": disabled
  84. 12/6/2014 -- 16:45:37 - <Info> - stream."inline": disabled
  85. 12/6/2014 -- 16:45:37 - <Info> - stream "max-synack-queued": 5
  86. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly "memcap": 21474836480
  87. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly "depth": 12582912
  88. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly "toserver-chunk-size": 2461
  89. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly "toclient-chunk-size": 2575
  90. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly.raw: enabled
  91. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 4, prealloc 256
  92. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 16, prealloc 512
  93. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 112, prealloc 512
  94. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 248, prealloc 512
  95. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 512, prealloc 512
  96. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 768, prealloc 1024
  97. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 1448, prealloc 1024
  98. 12/6/2014 -- 16:45:37 - <Info> - segment pool: pktsize 65535, prealloc 128
  99. 12/6/2014 -- 16:45:37 - <Info> - stream.reassembly "chunk-prealloc": 250
  100. 12/6/2014 -- 16:45:37 - <Notice> - all 16 packet processing threads, 3 management threads initialized, engine started.
  101. 12/6/2014 -- 16:45:37 - <Info> - Generic Receive Offload is unset on eth3
  102. 12/6/2014 -- 16:45:37 - <Info> - Large Receive Offload is unset on eth3
  103. 12/6/2014 -- 16:45:37 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  104. 12/6/2014 -- 16:45:37 - <Info> - Using interface 'eth3' via socket 9
  105. 12/6/2014 -- 16:45:37 - <Info> - Thread AFPacketeth31 using socket 9
  106. 12/6/2014 -- 16:45:37 - <Info> - Generic Receive Offload is unset on eth3
  107. 12/6/2014 -- 16:45:37 - <Info> - Large Receive Offload is unset on eth3
  108. 12/6/2014 -- 16:45:37 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  109. 12/6/2014 -- 16:45:38 - <Info> - Using interface 'eth3' via socket 10
  110. 12/6/2014 -- 16:45:38 - <Info> - Thread AFPacketeth32 using socket 10
  111. 12/6/2014 -- 16:45:38 - <Info> - Generic Receive Offload is unset on eth3
  112. 12/6/2014 -- 16:45:38 - <Info> - Large Receive Offload is unset on eth3
  113. 12/6/2014 -- 16:45:38 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  114. 12/6/2014 -- 16:45:39 - <Info> - Using interface 'eth3' via socket 11
  115. 12/6/2014 -- 16:45:39 - <Info> - Thread AFPacketeth33 using socket 11
  116. 12/6/2014 -- 16:45:39 - <Info> - Generic Receive Offload is unset on eth3
  117. 12/6/2014 -- 16:45:39 - <Info> - Large Receive Offload is unset on eth3
  118. 12/6/2014 -- 16:45:39 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  119. 12/6/2014 -- 16:45:39 - <Info> - Using interface 'eth3' via socket 12
  120. 12/6/2014 -- 16:45:39 - <Info> - Thread AFPacketeth34 using socket 12
  121. 12/6/2014 -- 16:45:39 - <Info> - Generic Receive Offload is unset on eth3
  122. 12/6/2014 -- 16:45:39 - <Info> - Large Receive Offload is unset on eth3
  123. 12/6/2014 -- 16:45:39 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  124. 12/6/2014 -- 16:45:40 - <Info> - Using interface 'eth3' via socket 13
  125. 12/6/2014 -- 16:45:40 - <Info> - Thread AFPacketeth35 using socket 13
  126. 12/6/2014 -- 16:45:40 - <Info> - Generic Receive Offload is unset on eth3
  127. 12/6/2014 -- 16:45:40 - <Info> - Large Receive Offload is unset on eth3
  128. 12/6/2014 -- 16:45:40 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  129. 12/6/2014 -- 16:45:41 - <Info> - Using interface 'eth3' via socket 14
  130. 12/6/2014 -- 16:45:41 - <Info> - Thread AFPacketeth36 using socket 14
  131. 12/6/2014 -- 16:45:41 - <Info> - Generic Receive Offload is unset on eth3
  132. 12/6/2014 -- 16:45:41 - <Info> - Large Receive Offload is unset on eth3
  133. 12/6/2014 -- 16:45:41 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  134. 12/6/2014 -- 16:45:42 - <Info> - Using interface 'eth3' via socket 15
  135. 12/6/2014 -- 16:45:42 - <Info> - Thread AFPacketeth37 using socket 15
  136. 12/6/2014 -- 16:45:42 - <Info> - Generic Receive Offload is unset on eth3
  137. 12/6/2014 -- 16:45:42 - <Info> - Large Receive Offload is unset on eth3
  138. 12/6/2014 -- 16:45:42 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  139. 12/6/2014 -- 16:45:42 - <Info> - Using interface 'eth3' via socket 16
  140. 12/6/2014 -- 16:45:42 - <Info> - Thread AFPacketeth38 using socket 16
  141. 12/6/2014 -- 16:45:42 - <Info> - Generic Receive Offload is unset on eth3
  142. 12/6/2014 -- 16:45:42 - <Info> - Large Receive Offload is unset on eth3
  143. 12/6/2014 -- 16:45:42 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  144. 12/6/2014 -- 16:45:43 - <Info> - Using interface 'eth3' via socket 17
  145. 12/6/2014 -- 16:45:43 - <Info> - Thread AFPacketeth39 using socket 17
  146. 12/6/2014 -- 16:45:43 - <Info> - Generic Receive Offload is unset on eth3
  147. 12/6/2014 -- 16:45:43 - <Info> - Large Receive Offload is unset on eth3
  148. 12/6/2014 -- 16:45:43 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  149. 12/6/2014 -- 16:45:44 - <Info> - Using interface 'eth3' via socket 18
  150. 12/6/2014 -- 16:45:44 - <Info> - Thread AFPacketeth310 using socket 18
  151. 12/6/2014 -- 16:45:44 - <Info> - Generic Receive Offload is unset on eth3
  152. 12/6/2014 -- 16:45:44 - <Info> - Large Receive Offload is unset on eth3
  153. 12/6/2014 -- 16:45:44 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  154. 12/6/2014 -- 16:45:45 - <Info> - Using interface 'eth3' via socket 19
  155. 12/6/2014 -- 16:45:45 - <Info> - Thread AFPacketeth311 using socket 19
  156. 12/6/2014 -- 16:45:45 - <Info> - Generic Receive Offload is unset on eth3
  157. 12/6/2014 -- 16:45:45 - <Info> - Large Receive Offload is unset on eth3
  158. 12/6/2014 -- 16:45:45 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  159. 12/6/2014 -- 16:45:45 - <Info> - Using interface 'eth3' via socket 20
  160. 12/6/2014 -- 16:45:45 - <Info> - Thread AFPacketeth312 using socket 20
  161. 12/6/2014 -- 16:45:45 - <Info> - Generic Receive Offload is unset on eth3
  162. 12/6/2014 -- 16:45:45 - <Info> - Large Receive Offload is unset on eth3
  163. 12/6/2014 -- 16:45:45 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  164. 12/6/2014 -- 16:45:46 - <Info> - Using interface 'eth3' via socket 21
  165. 12/6/2014 -- 16:45:46 - <Info> - Thread AFPacketeth313 using socket 21
  166. 12/6/2014 -- 16:45:46 - <Info> - Generic Receive Offload is unset on eth3
  167. 12/6/2014 -- 16:45:46 - <Info> - Large Receive Offload is unset on eth3
  168. 12/6/2014 -- 16:45:46 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  169. 12/6/2014 -- 16:45:47 - <Info> - Using interface 'eth3' via socket 22
  170. 12/6/2014 -- 16:45:47 - <Info> - Thread AFPacketeth314 using socket 22
  171. 12/6/2014 -- 16:45:47 - <Info> - Generic Receive Offload is unset on eth3
  172. 12/6/2014 -- 16:45:47 - <Info> - Large Receive Offload is unset on eth3
  173. 12/6/2014 -- 16:45:47 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  174. 12/6/2014 -- 16:45:48 - <Info> - Using interface 'eth3' via socket 23
  175. 12/6/2014 -- 16:45:48 - <Info> - Thread AFPacketeth315 using socket 23
  176. 12/6/2014 -- 16:45:48 - <Info> - Generic Receive Offload is unset on eth3
  177. 12/6/2014 -- 16:45:48 - <Info> - Large Receive Offload is unset on eth3
  178. 12/6/2014 -- 16:45:48 - <Info> - AF_PACKET RX Ring params: block_size=32768 block_nr=50001 frame_size=1600 frame_nr=1000020
  179. 12/6/2014 -- 16:45:48 - <Info> - Using interface 'eth3' via socket 24
  180. 12/6/2014 -- 16:45:48 - <Info> - All AFP capture threads are running.
  181. 12/6/2014 -- 16:45:48 - <Info> - Thread AFPacketeth316 using socket 24
  182. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth32
  183. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth39
  184. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth313
  185. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth310
  186. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth34
  187. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth33
  188. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth37
  189. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth38
  190. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth312
  191. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth315
  192. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth36
  193. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth314
  194. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth311
  195. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth35
  196. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth316
  197. 12/6/2014 -- 16:45:48 - <Info> - Starting to read on AFPacketeth31
  198. 12/6/2014 -- 16:54:55 - <Notice> - Signal Received. Stopping engine.
  199. 12/6/2014 -- 16:55:16 - <Info> - Flow emergency mode over, back to normal... unsetting FLOW_EMERGENCY bit (ts.tv_sec: 1402563289, ts.tv_usec:570265) flow_spare_q status(): 158% flows at the queue
  200. 12/6/2014 -- 16:55:16 - <Info> - 0 new flows, 0 established flows were timed out, 0 flows in closed state
  201. 12/6/2014 -- 16:56:35 - <Info> - time elapsed 658.030s
  202. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth31) Kernel: Packets 109346048, dropped 101816985
  203. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth31) Packets 2583858, bytes 642350094
  204. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 53177354 TCP packets
  205. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  206. 12/6/2014 -- 16:56:35 - <Info> - Alert unified2 module wrote 0 alerts
  207. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 814807 requests
  208. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth32) Kernel: Packets 108393014, dropped 69871879
  209. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth32) Packets 33548075, bytes 8368136338
  210. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33425040 TCP packets
  211. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  212. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6318 requests
  213. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth33) Kernel: Packets 107535222, dropped 69595342
  214. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth33) Packets 33728481, bytes 8621444105
  215. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33643222 TCP packets
  216. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  217. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6314 requests
  218. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth34) Kernel: Packets 106376518, dropped 69412955
  219. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth34) Packets 33254350, bytes 8354364987
  220. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33179889 TCP packets
  221. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  222. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6438 requests
  223. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth35) Kernel: Packets 104575250, dropped 67822248
  224. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth35) Packets 33663837, bytes 8288417795
  225. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33592742 TCP packets
  226. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  227. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6522 requests
  228. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth36) Kernel: Packets 105523383, dropped 69551485
  229. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth36) Packets 33258411, bytes 8282855427
  230. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33188063 TCP packets
  231. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  232. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6268 requests
  233. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth37) Kernel: Packets 105238893, dropped 69691744
  234. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth37) Packets 33204658, bytes 8798495179
  235. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33127593 TCP packets
  236. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  237. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6452 requests
  238. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth38) Kernel: Packets 104514604, dropped 69053692
  239. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth38) Packets 33426396, bytes 8280973383
  240. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33353038 TCP packets
  241. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  242. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6406 requests
  243. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth39) Kernel: Packets 103764439, dropped 68883675
  244. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth39) Packets 33008870, bytes 8259536023
  245. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 32895981 TCP packets
  246. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  247. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6443 requests
  248. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth310) Kernel: Packets 103454447, dropped 68494688
  249. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth310) Packets 33238557, bytes 8157855957
  250. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33163886 TCP packets
  251. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  252. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6372 requests
  253. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth311) Kernel: Packets 104354260, dropped 69541987
  254. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth311) Packets 33222351, bytes 8359206649
  255. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33149844 TCP packets
  256. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  257. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6619 requests
  258. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth312) Kernel: Packets 105075256, dropped 69979260
  259. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth312) Packets 33597243, bytes 8408373606
  260. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33513645 TCP packets
  261. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  262. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6501 requests
  263. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth313) Kernel: Packets 102314236, dropped 67615011
  264. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth313) Packets 33304520, bytes 8258968548
  265. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33223901 TCP packets
  266. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  267. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6505 requests
  268. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth314) Kernel: Packets 102991267, dropped 68288296
  269. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth314) Packets 33438760, bytes 8192305969
  270. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33349846 TCP packets
  271. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  272. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6444 requests
  273. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth315) Kernel: Packets 104291348, dropped 69988522
  274. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth315) Packets 33192145, bytes 8308793972
  275. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33108772 TCP packets
  276. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  277. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6546 requests
  278. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth316) Kernel: Packets 103057826, dropped 68713588
  279. 12/6/2014 -- 16:56:35 - <Info> - (AFPacketeth316) Packets 33317344, bytes 8253795322
  280. 12/6/2014 -- 16:56:35 - <Info> - Stream TCP processed 33244919 TCP packets
  281. 12/6/2014 -- 16:56:35 - <Info> - Fast log output wrote 0 alerts
  282. 12/6/2014 -- 16:56:35 - <Info> - HTTP logger logged 6442 requests
  283. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 4 had a peak use of 16960 segments, more than the prealloc setting of 256
  284. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 16 had a peak use of 49199 segments, more than the prealloc setting of 512
  285. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 112 had a peak use of 2378310 segments, more than the prealloc setting of 512
  286. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 248 had a peak use of 884882 segments, more than the prealloc setting of 512
  287. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 512 had a peak use of 706481 segments, more than the prealloc setting of 512
  288. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 768 had a peak use of 580836 segments, more than the prealloc setting of 1024
  289. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 1448 had a peak use of 998697 segments, more than the prealloc setting of 1024
  290. 12/6/2014 -- 16:56:49 - <Info> - TCP segment pool of size 65535 had a peak use of 174796 segments, more than the prealloc setting of 128
  291. 12/6/2014 -- 16:56:49 - <Info> - TCP segment chunk pool had a peak use of 3007 chunks, more than the prealloc setting of 250
  292. 12/6/2014 -- 16:56:49 - <Info> - host memory usage: 390144 bytes, maximum: 16777216
  293. 12/6/2014 -- 16:56:49 - <Info> - cleaning up signature grouping structure... complete
  294. 12/6/2014 -- 16:56:49 - <Notice> - Stats for 'eth3': pkts: 1680806011, drop: 1138321357 (67.72%), invalid chksum: 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement