Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- souser@servername:~$ sudo sostat
- =========================================================================
- Service Status
- =========================================================================
- Status: securityonion
- * sguil server[ OK ]
- Status: HIDS
- * ossec_agent (sguil)[ OK ]
- Status: Bro
- Getting process status ...
- Getting peer status ...
- Name Type Host Status Pid Peers Started
- manager manager localhost running 5345 2 12 Sep 15:59:37
- proxy proxy localhost running 5514 2 12 Sep 15:59:38
- servername-eth1-1 worker localhost running 5701 2 12 Sep 15:59:40
- Status: servername-eth1
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (sguil)[ OK ]
- * snort_agent (sguil)[ OK ]
- * suricata (alert data)[ OK ]
- * barnyard2 (spooler, unified2 format)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- eth0 Link encap:Ethernet HWaddr
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:255.255.255.0
- inet6 addr: X Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:6044 errors:0 dropped:0 overruns:0 frame:0
- TX packets:1899 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:7270235 (7.2 MB) TX bytes:323325 (323.3 KB)
- eth1 Link encap:Ethernet HWaddr
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:255.255.255.0
- inet6 addr: Scope:Link
- UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:12245438 errors:0 dropped:0 overruns:0 frame:0
- TX packets:384 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:7967382013 (7.9 GB) TX bytes:30082 (30.0 KB)
- lo Link encap:Local Loopback
- inet addr:127.0.0.1 Mask:255.0.0.0
- inet6 addr: ::1/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:513984 errors:0 dropped:0 overruns:0 frame:0
- TX packets:513984 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1
- RX bytes:120586565 (120.5 MB) TX bytes:120586565 (120.5 MB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
- link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
- RX: bytes packets errors dropped overrun mcast
- 120586565 513984 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 120586565 513984 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether brd ff:ff:ff:ff:ff:ff
- RX: bytes packets errors dropped overrun mcast
- 7270475 6048 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 326223 1910 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 3: eth1: <BROADCAST,MULTICAST,PROMISC,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether brd ff:ff:ff:ff:ff:ff
- RX: bytes packets errors dropped overrun mcast
- 7967384915 12245440 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 30082 384 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 4: gre0@NONE: <NOARP> mtu 1476 qdisc noop state DOWN mode DEFAULT group default qlen 1
- link/gre 0.0.0.0 brd 0.0.0.0
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 5: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN mode DEFAULT group default qlen 1000
- link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 7.9G 4.0K 7.9G 1% /dev
- tmpfs 1.6G 1.3M 1.6G 1% /run
- /dev/sda6 15G 3.5G 11G 25% /
- none 4.0K 0 4.0K 0% /sys/fs/cgroup
- none 5.0M 0 5.0M 0% /run/lock
- none 7.9G 14M 7.9G 1% /run/shm
- none 100M 24K 100M 1% /run/user
- /dev/sdb1 99G 4.0G 90G 5% /var
- /dev/sdc1 99G 84G 9.4G 90% /nsm
- /dev/sda1 945M 49M 832M 6% /boot
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- avahi-dae 952 avahi 12u IPv4 7746 0t0 UDP *:5353
- avahi-dae 952 avahi 13u IPv6 7747 0t0 UDP *:5353
- avahi-dae 952 avahi 14u IPv4 7748 0t0 UDP *:45403
- avahi-dae 952 avahi 15u IPv6 7749 0t0 UDP *:36516
- ntpd 1591 ntp 16u IPv4 10793 0t0 UDP *:123
- ntpd 1591 ntp 17u IPv6 10796 0t0 UDP *:123
- ntpd 1591 ntp 18u IPv4 10803 0t0 UDP 127.0.0.1:123
- ntpd 1591 ntp 19u IPv4 10805 0t0 UDP X.X.X.X:123
- ntpd 1591 ntp 20u IPv4 10807 0t0 UDP X.X.X.X:123
- ntpd 1591 ntp 21u IPv6 10809 0t0 UDP [::1]:123
- ntpd 1591 ntp 22u IPv6 10811 0t0 UDP [fe80::250:56ff:fe88:16fc]:123
- ntpd 1591 ntp 23u IPv6 10813 0t0 UDP [fe80::250:56ff:fe88:7359]:123
- cupsd 1603 root 10u IPv6 11592 0t0 TCP [::1]:631 (LISTEN)
- cupsd 1603 root 11u IPv4 11593 0t0 TCP 127.0.0.1:631 (LISTEN)
- cups-brow 1614 root 8u IPv4 11612 0t0 UDP *:631
- sshd 1823 root 3u IPv4 10999 0t0 TCP *:22 (LISTEN)
- sshd 1823 root 4u IPv6 11001 0t0 TCP *:22 (LISTEN)
- searchd 1865 sphinxsearch 7u IPv4 12245 0t0 TCP *:9306 (LISTEN)
- searchd 1865 sphinxsearch 8u IPv4 12246 0t0 TCP *:9312 (LISTEN)
- syslog-ng 1897 root 9u IPv4 12256 0t0 TCP *:514 (LISTEN)
- syslog-ng 1897 root 10u IPv4 12257 0t0 UDP *:514
- mysqld 1903 mysql 10u IPv4 11246 0t0 TCP 127.0.0.1:3306 (LISTEN)
- salt-mini 1960 root 13u IPv4 14980 0t0 TCP 127.0.0.1:41090->127.0.0.1:4506 (ESTABLISHED)
- salt-mini 1960 root 24u IPv4 14152 0t0 TCP 127.0.0.1:42724->127.0.0.1:4505 (ESTABLISHED)
- ossec-csy 1979 ossecm 5u IPv4 13652 0t0 UDP 127.0.0.1:47097->127.0.0.1:514
- salt-mast 2060 root 12u IPv4 14536 0t0 TCP *:4505 (LISTEN)
- salt-mast 2060 root 14u IPv4 15764 0t0 TCP 127.0.0.1:4505->127.0.0.1:42724 (ESTABLISHED)
- salt-mast 2087 root 20u IPv4 13727 0t0 TCP *:4506 (LISTEN)
- salt-mast 2087 root 22u IPv4 16542 0t0 TCP 127.0.0.1:4506->127.0.0.1:41090 (ESTABLISHED)
- /usr/sbin 3068 root 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 3068 root 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 3068 root 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- tclsh 5048 sguil 13u IPv4 29542 0t0 TCP *:7734 (LISTEN)
- tclsh 5048 sguil 14u IPv6 29543 0t0 TCP *:7734 (LISTEN)
- tclsh 5048 sguil 15u IPv4 29546 0t0 TCP *:7736 (LISTEN)
- tclsh 5048 sguil 16u IPv6 29547 0t0 TCP *:7736 (LISTEN)
- tclsh 5048 sguil 17u IPv4 29548 0t0 TCP 127.0.0.1:7736->127.0.0.1:46260 (ESTABLISHED)
- tclsh 5048 sguil 18u IPv4 32703 0t0 TCP 127.0.0.1:7736->127.0.0.1:34888 (ESTABLISHED)
- tclsh 5048 sguil 19u IPv4 33514 0t0 TCP 127.0.0.1:7736->127.0.0.1:33042 (ESTABLISHED)
- tclsh 5048 sguil 20u IPv4 55756 0t0 TCP 127.0.0.1:7734->127.0.0.1:36412 (ESTABLISHED)
- tclsh 5094 sguil 3u IPv4 29551 0t0 TCP 127.0.0.1:33042->127.0.0.1:7736 (ESTABLISHED)
- bro 5345 sguil 4u IPv4 29236 0t0 UDP X.X.X.X:51119->X.X.X.X:53
- bro 5347 sguil 0u IPv4 24971 0t0 TCP *:47761 (LISTEN)
- bro 5347 sguil 1u IPv6 24972 0t0 TCP *:47761 (LISTEN)
- bro 5347 sguil 2u IPv4 25051 0t0 TCP 127.0.0.1:47761->127.0.0.1:36552 (ESTABLISHED)
- bro 5347 sguil 4u IPv4 29236 0t0 UDP X.X.X.X:51119->X.X.X.X:53
- bro 5347 sguil 268u IPv4 25168 0t0 TCP 127.0.0.1:47761->127.0.0.1:36554 (ESTABLISHED)
- bro 5514 sguil 4u IPv4 29346 0t0 UDP X.X.X.X:35295->X.X.X.X:53
- bro 5516 sguil 0u IPv4 25050 0t0 TCP 127.0.0.1:36552->127.0.0.1:47761 (ESTABLISHED)
- bro 5516 sguil 4u IPv4 29346 0t0 UDP X.X.X.X:35295->X.X.X.X:53
- bro 5516 sguil 266u IPv4 25058 0t0 TCP *:47762 (LISTEN)
- bro 5516 sguil 267u IPv6 25059 0t0 TCP *:47762 (LISTEN)
- bro 5516 sguil 268u IPv4 25174 0t0 TCP 127.0.0.1:47762->127.0.0.1:57592 (ESTABLISHED)
- bro 5701 sguil 4u IPv4 23252 0t0 UDP X.X.X.X:49728->X.X.X.X:53
- bro 5702 sguil 0u IPv4 25167 0t0 TCP 127.0.0.1:36554->127.0.0.1:47761 (ESTABLISHED)
- bro 5702 sguil 4u IPv4 23252 0t0 UDP X.X.X.X:49728->X.X.X.X:53
- bro 5702 sguil 266u IPv4 25173 0t0 TCP 127.0.0.1:57592->127.0.0.1:47762 (ESTABLISHED)
- bro 5702 sguil 271u IPv4 25181 0t0 TCP *:47763 (LISTEN)
- bro 5702 sguil 272u IPv6 25182 0t0 TCP *:47763 (LISTEN)
- tclsh 5775 sguil 3u IPv4 32699 0t0 TCP 127.0.0.1:46260->127.0.0.1:7736 (ESTABLISHED)
- tclsh 5791 sguil 3u IPv4 23352 0t0 TCP 127.0.0.1:8100 (LISTEN)
- tclsh 5791 sguil 5u IPv4 23391 0t0 TCP 127.0.0.1:8100->127.0.0.1:52504 (ESTABLISHED)
- tclsh 5791 sguil 7u IPv4 32702 0t0 TCP 127.0.0.1:34888->127.0.0.1:7736 (ESTABLISHED)
- barnyard2 5834 sguil 3u IPv4 25286 0t0 TCP 127.0.0.1:52504->127.0.0.1:8100 (ESTABLISHED)
- wish 6742 souser 4u IPv4 57363 0t0 TCP 127.0.0.1:36412->127.0.0.1:7734 (ESTABLISHED)
- chromium- 7018 souser 101u IPv4 34966 0t0 UDP *:5353
- chromium- 7018 souser 106u IPv6 220375 0t0 TCP [::1]:53652->[::1]:443 (ESTABLISHED)
- chromium- 7018 souser 107u IPv6 220374 0t0 TCP [::1]:53650->[::1]:443 (ESTABLISHED)
- chromium- 7018 souser 108u IPv6 220376 0t0 TCP [::1]:53654->[::1]:443 (ESTABLISHED)
- chromium- 7018 souser 110u IPv6 220377 0t0 TCP [::1]:53656->[::1]:443 (ESTABLISHED)
- /usr/sbin 18446 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18446 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18446 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18449 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18449 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18449 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18449 www-data 28u IPv4 221367 0t0 TCP 127.0.0.1:46416->127.0.0.1:3154 (CLOSE_WAIT)
- /usr/sbin 18475 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18475 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18475 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18475 www-data 25u IPv6 221380 0t0 TCP [::1]:443->[::1]:53650 (ESTABLISHED)
- /usr/sbin 18476 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18476 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18476 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18476 www-data 25u IPv6 217467 0t0 TCP [::1]:443->[::1]:53652 (ESTABLISHED)
- /usr/sbin 18477 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18477 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18477 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18477 www-data 25u IPv6 217468 0t0 TCP [::1]:443->[::1]:53654 (ESTABLISHED)
- /usr/sbin 18478 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18478 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18478 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18478 www-data 25u IPv6 217469 0t0 TCP [::1]:443->[::1]:53656 (ESTABLISHED)
- /usr/sbin 18480 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18480 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18480 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18482 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18482 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18482 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18484 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18484 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18484 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18485 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18485 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18485 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18486 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18486 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18486 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18487 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18487 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18487 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18488 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18488 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18488 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- /usr/sbin 18489 www-data 5u IPv6 15792 0t0 TCP *:443 (LISTEN)
- /usr/sbin 18489 www-data 7u IPv6 15796 0t0 TCP *:9876 (LISTEN)
- /usr/sbin 18489 www-data 9u IPv6 15802 0t0 TCP *:3154 (LISTEN)
- sshd 18942 root 3u IPv4 221653 0t0 TCP X.X.X.X:22->X.X.X.X:56340 (ESTABLISHED)
- sshd 19023 souser 3u IPv4 221653 0t0 TCP X.X.X.X:22->X.X.X.X:56340 (ESTABLISHED)
- =========================================================================
- IDS Rules Update
- =========================================================================
- Mon Sep 12 07:01:01 UTC 2016
- Backing up current local_rules.xml file.
- Cleaning up local_rules.xml backup files older than 30 days.
- Backing up current downloaded.rules file before it gets overwritten.
- Cleaning up downloaded.rules backup files older than 30 days.
- Backing up current local.rules file before it gets overwritten.
- Cleaning up local.rules backup files older than 30 days.
- Sleeping for 38 minutes to avoid overwhelming rule sites.
- ENGINE=suricata, so we'll execute PulledPork with the -T option to avoid adding soid rules to downloaded.rules.
- Running PulledPork.
- Error 500 when fetching https://rules.emergingthreatspro.com/open/suricata-3.1.1/emerging.rules.tar.gz.md5 at /usr/bin/pulledpork.pl line 463.
- main::md5file('open', 'emerging.rules.tar.gz', '/tmp/', 'https://rules.emergingthreatspro.com/open/suricata-3.1.1/') called at /usr/bin/pulledpork.pl line 1885
- http://code.google.com/p/pulledpork/
- _____ ____
- `----,\ )
- `--==\\ / PulledPork v0.7.0 - Swine Flu!
- `--==\\/
- .-~~~~-.Y|\\_ Copyright (C) 2009-2013 JJ Cummings
- @_/ / 66\_ [email protected]
- | \ \ _(")
- \ /-| ||'--' Rules give me wings!
- \_\ \_\\
- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
- Checking latest MD5 for emerging.rules.tar.gz....
- Restarting Barnyard2.
- Restarting: servername-eth1
- * stopping: barnyard2 (spooler, unified2 format)[ OK ]
- * starting: barnyard2 (spooler, unified2 format)[ OK ]
- Restarting IDS Engine.
- Restarting: servername-eth1
- * stopping: suricata (alert data)[ OK ]
- * starting: suricata (alert data)[ OK ]
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 0.44 0.66 0.68
- Processing units: 4
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 16:44:08 up 47 min, 5 users, load average: 0.44, 0.66, 0.68
- Tasks: 279 total, 3 running, 273 sleeping, 0 stopped, 3 zombie
- %Cpu(s): 14.5 us, 3.5 sy, 0.0 ni, 79.4 id, 1.2 wa, 0.0 hi, 1.5 si, 0.0 st
- KiB Mem: 16432856 total, 15570064 used, 862792 free, 74260 buffers
- KiB Swap: 3998716 total, 0 used, 3998716 free. 8759260 cached Mem
- %CPU %MEM COMMAND
- 26.5 0.5 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p servername-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 21.8 0.4 perl /opt/elsa/web/cron.pl -c /etc/elsa_web.conf
- 17.3 0.5 /usr/sbin/mysqld
- 7.9 2.2 suricata --user sguil --group sguil -c /etc/nsm/servername-eth1/suricata.yaml --pfring=eth1 -l /nsm/sensor_data/servername-eth1
- 3.5 0.1 wish /usr/bin/sguil.tk
- 3.2 25.9 tclsh /usr/bin/sguild -c /etc/nsm/securityonion/sguild.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/sguild.queries -A /etc/nsm/securityonion/sguild.access -C /etc/nsm/securityonion/certs
- 2.4 0.0 barnyard2 -c /etc/nsm/servername-eth1/barnyard2.conf -u sguil -g sguil -d /nsm/sensor_data/servername-eth1 -f snort.unified2 -w /etc/nsm/servername-eth1/barnyard2.waldo -i 1 -U
- 2.1 0.5 netsniff-ng -i eth1 -o /nsm/sensor_data/servername-eth1/dailylogs/2016-09-12/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 64 iB --interval 150 iB
- 1.6 0.8 /usr/lib/chromium-browser/chromium-browser --type=renderer --enable-pinch --enable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingInc
- 1.3 0.3 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 1.2 0.3 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.9 0.5 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.8 1.3 wireshark
- 0.6 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/servername-eth1/snort_agent.conf
- 0.6 1.1 /usr/lib/chromium-browser/chromium-browser --enable-pinch https://localhost/squert
- 0.4 0.0 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- 0.4 0.0 /var/ossec/bin/ossec-syscheckd
- 0.4 0.0 -bash
- 0.3 0.3 perl /opt/elsa/node/elsa.pl -c /etc/elsa_node.conf
- 0.3 0.0 [kworker/u8:1]
- 0.2 5.3 /usr/bin/searchd --nodetach
- 0.2 0.2 /usr/bin/python /usr/bin/salt-master
- 0.1 0.0 [rcu_sched]
- 0.1 0.0 /var/ossec/bin/ossec-analysisd
- 0.1 0.2 xfce4-terminal --geometry=78x24 --display :0.0 --role=xfce4-terminal-1473540190-1197851340 --show-menubar --show-borders --hide-toolbar --working-directory /home/souser --tab --working-directory /home/souser --tab --working-directory /etc/network --sm-client-id 2615dce6f-a6b3-
- 0.1 0.6 /usr/lib/chromium-browser/chromium-browser --type=renderer --enable-pinch --enable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingInc
- 0.0 0.0 /sbin/init
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [ksoftirqd/0]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [watchdog/1]
- 0.0 0.0 [migration/1]
- 0.0 0.0 [ksoftirqd/1]
- 0.0 0.0 [kworker/1:0]
- 0.0 0.0 [kworker/1:0H]
- 0.0 0.0 [watchdog/2]
- 0.0 0.0 [migration/2]
- 0.0 0.0 [ksoftirqd/2]
- 0.0 0.0 [kworker/2:0H]
- 0.0 0.0 [watchdog/3]
- 0.0 0.0 [migration/3]
- 0.0 0.0 [ksoftirqd/3]
- 0.0 0.0 [kworker/3:0]
- 0.0 0.0 [kworker/3:0H]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [perf]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [writeback]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [khugepaged]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [kworker/3:1]
- 0.0 0.0 [kworker/1:1]
- 0.0 0.0 [kswapd0]
- 0.0 0.0 [vmstat]
- 0.0 0.0 [fsnotify_mark]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [deferwq]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_2]
- 0.0 0.0 [scsi_tmf_2]
- 0.0 0.0 [vmw_pvscsi_wq_2]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kpsmoused]
- 0.0 0.0 [ttm_swap]
- 0.0 0.0 [bioset]
- 0.0 0.0 [jbd2/sda6-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 upstart-udev-bridge --daemon
- 0.0 0.0 /lib/systemd/systemd-udevd --daemon
- 0.0 0.0 [jbd2/sdb1-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [jbd2/sdc1-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [jbd2/sda1-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kmpathd]
- 0.0 0.0 [kmpath_handlerd]
- 0.0 0.0 upstart-file-bridge --daemon
- 0.0 0.0 dbus-daemon --system --fork
- 0.0 0.0 [kworker/2:1H]
- 0.0 0.0 /usr/sbin/bluetoothd
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.0 avahi-daemon: running [servername.local]
- 0.0 0.0 avahi-daemon: chroot helper
- 0.0 0.0 [krfcommd]
- 0.0 0.0 upstart-socket-bridge --daemon
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 [kworker/1:1H]
- 0.0 0.0 [kworker/3:1H]
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 /usr/sbin/cupsd -f
- 0.0 0.0 /usr/sbin/cups-browsed
- 0.0 0.0 /sbin/getty -8 38400 tty4
- 0.0 0.0 /sbin/getty -8 38400 tty5
- 0.0 0.1 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /sbin/getty -8 38400 tty2
- 0.0 0.0 /sbin/getty -8 38400 tty3
- 0.0 0.1 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /sbin/getty -8 38400 tty6
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.0 cron
- 0.0 0.0 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 0.0 0.0 /usr/sbin/irqbalance
- 0.0 0.0 [kauditd]
- 0.0 0.0 acpid -c /etc/acpi/events -s /var/run/acpid.socket
- 0.0 0.0 supervising syslog-ng
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 /usr/sbin/kerneloops
- 0.0 0.1 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /var/ossec/bin/ossec-csyslogd
- 0.0 0.0 /var/ossec/bin/ossec-execd
- 0.0 0.0 /var/ossec/bin/ossec-logcollector
- 0.0 0.0 lightdm
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.1 /usr/bin/python /usr/bin/salt-master
- 0.0 0.1 /usr/bin/python /usr/bin/salt-master
- 0.0 0.1 /usr/bin/python /usr/bin/salt-master
- 0.0 0.2 /usr/bin/python /usr/bin/salt-master
- 0.0 0.2 /usr/bin/python /usr/bin/salt-master
- 0.0 0.2 /usr/bin/python /usr/bin/salt-master
- 0.0 0.2 /usr/bin/python /usr/bin/salt-master
- 0.0 0.2 /usr/bin/python /usr/bin/salt-master
- 0.0 0.1 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /var/ossec/bin/ossec-monitord
- 0.0 0.0 /usr/bin/vmtoolsd
- 0.0 0.9 /usr/sbin/apache2 -k start
- 0.0 0.0 /sbin/getty -8 38400 tty1
- 0.0 0.0 lightdm --session-child 12 21
- 0.0 0.0 /usr/bin/gnome-keyring-daemon --daemonize --login
- 0.0 0.0 init --user
- 0.0 0.0 [kworker/2:2]
- 0.0 0.0 dbus-daemon --fork --session --address=unix:abstract=/tmp/dbus-xGD8mxwMsw
- 0.0 0.0 upstart-event-bridge
- 0.0 0.0 upstart-file-bridge --daemon --user
- 0.0 0.0 upstart-dbus-bridge --daemon --session --user --bus-name session
- 0.0 0.0 upstart-dbus-bridge --daemon --system --user --bus-name system
- 0.0 0.0 /bin/sh /etc/xdg/xfce4/xinitrc -- /etc/X11/xinit/xserverrc
- 0.0 0.1 xfce4-session
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
- 0.0 0.0 /usr/bin/ssh-agent -s
- 0.0 0.1 xfwm4 --display :0.0 --sm-client-id 2f644d165-be3c-4b88-91cc-a9e9f80e0c19
- 0.0 0.0 Thunar --sm-client-id 2293f6004-4316-4a6e-b7da-32e4e25314a5 --daemon
- 0.0 0.1 xfce4-panel --display :0.0 --sm-client-id 26e3c0834-e808-4099-99d6-1e10978363bb
- 0.0 0.1 xfdesktop --display :0.0 --sm-client-id 26c99a627-093d-46e1-aafa-9b682b9993d6
- 0.0 0.0 xfsettingsd --display :0.0 --sm-client-id 258929f22-683c-48bc-8f40-3c655aa0f6b2
- 0.0 0.0 /usr/lib/upower/upowerd
- 0.0 0.1 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libwhiskermenu.so 1 12582944 whiskermenu Whisker Menu Show a menu to easily access installed applications
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 4 12582945 systray Notification Area Area where notification icons appear
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 xfce4-power-manager --restart --sm-client-id 2ede874ab-9b9c-4a88-80a8-0a802f25ea68
- 0.0 0.1 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libindicator-plugin.so 5 12582946 indicator Indicator Plugin Provides a panel area for Unity indicators. Indicators allow applications and system services to display their status and
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/1000/gvfs -f -o big_writes
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
- 0.0 0.1 update-notifier
- 0.0 0.0 /bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 xfce4-power-manager
- 0.0 0.0 xfce4-volumed
- 0.0 0.1 /usr/bin/python /usr/share/system-config-printer/applet.py
- 0.0 0.0 light-locker
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
- 0.0 0.2 /usr/bin/python /usr/bin/blueman-applet
- 0.0 0.1 nm-applet
- 0.0 0.0 /usr/bin/pulseaudio --start --log-target=syslog
- 0.0 0.0 /usr/lib/rtkit/rtkit-daemon
- 0.0 0.0 /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
- 0.0 0.0 /usr/lib/gvfs/gvfs-udisks2-volume-monitor
- 0.0 0.0 gnome-pty-helper
- 0.0 0.0 bash
- 0.0 0.0 /usr/lib/udisks2/udisksd --no-debug
- 0.0 0.0 bash
- 0.0 0.0 bash
- 0.0 0.0 init --user --startup-event indicator-services-start
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
- 0.0 0.0 /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfs-mtp-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfs-afc-volume-monitor
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/gconf/gconfd-2
- 0.0 0.0 /usr/lib/gvfs/gvfsd-trash --spawner :1.14 /org/gtk/gvfs/exec_spaw/0
- 0.0 0.0 /usr/bin/obex-data-server --no-daemon
- 0.0 0.0 su - sguil -- /usr/bin/sguild -c /etc/nsm/securityonion/sguild.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/sguild.queries -A /etc/nsm/securityonion/sguild.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/sguild -c /etc/nsm/securityonion/sguild.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/sguild.queries -A /etc/nsm/securityonion/sguild.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/sguild -c /etc/nsm/securityonion/sguild.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/sguild.queries -A /etc/nsm/securityonion/sguild.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 su - sguil -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i 127.0.0.1 -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i 127.0.0.1 -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.0 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.3 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p local -p servername-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.5 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p servername-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 su - sguil -- /usr/bin/pcap_agent.tcl -c /etc/nsm/servername-eth1/pcap_agent.conf
- 0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/servername-eth1/pcap_agent.conf
- 0.0 0.0 su - sguil -- /usr/bin/snort_agent.tcl -c /etc/nsm/servername-eth1/snort_agent.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/servername-eth1/snort.stats
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.3 /usr/lib/chromium-browser/chromium-browser --type=zygote
- 0.0 0.0 /usr/lib/chromium-browser/chromium-browser --type=zygote
- 0.0 0.0 [kworker/2:0]
- 0.0 0.0 [tcpdump] <defunct>
- 0.0 0.0 [wireshark] <defunct>
- 0.0 0.0 [tcpdump] <defunct>
- 0.0 0.0 sudo wireshark
- 0.0 0.0 [kworker/u8:2]
- 0.0 0.0 [kworker/0:1]
- 0.0 0.0 [kworker/0:2]
- 0.0 0.0 [kworker/u8:3]
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.9 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.8 /usr/sbin/apache2 -k start
- 0.0 0.0 sshd: souser [priv]
- 0.0 0.0 [kworker/0:0]
- 0.0 0.0 sshd: souser@pts/0
- 0.0 0.0 CRON
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh > /dev/null 2>&1
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh
- 0.0 0.0 sudo sostat
- 0.0 0.0 /bin/bash /usr/bin/sostat
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- eth1: 2682892
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- eth1:
- RX packets:12248658 dropped:0 TX packets:384 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- Appl. Name : bro-eth1
- Tot Packets : 11606250
- Tot Pkt Lost : 0
- Appl. Name : Suricata
- Tot Packets : 11552125
- Tot Pkt Lost : 813
- -------------------------------------------------------------------------
- IDS Engine (suricata) packet drops:
- /nsm/sensor_data/servername-eth1/stats.log
- capture.kernel_drops | W#01-eth1 | 813
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.000000
- servername-eth1-1: 1473698648.941722 recvd=11607742 dropped=0 link=11607742
- Capture Loss:
- servername-eth1-1 0.0
- If you are seeing capture loss without dropped packets, this
- may indicate that an upstream device is dropping packets (tap or SPAN port).
- -------------------------------------------------------------------------
- Netsniff-NG:
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911000004 Processed: +289931 Lost: -31411
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +159953 Lost: -5854
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +511521 Lost: -14434
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +182277 Lost: -9306
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +160728 Lost: -2720
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +170405 Lost: -511
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160911035109 Processed: +155862 Lost: -4748
- File: /var/log/nsm/servername-eth1/netsniff-ng.log.20160912000007 Processed: +441592 Lost: -8658
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.4.1 (unknown)
- Total rings : 2
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Total plugins : 0
- Cluster Fragment Queue : 0
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/servername-eth0/dailylogs/ - 0 days
- 4.0K .
- /nsm/sensor_data/servername-eth1/dailylogs/ - 1 days
- 82G .
- 82G ./2016-09-12
- /nsm/bro/logs/ - 1 days
- 2.0M .
- 800K ./2016-09-12
- 1.2M ./stats
- =========================================================================
- Sguil Uncategorized Events
- =========================================================================
- +----------+
- | COUNT(*) |
- +----------+
- | 2247635 |
- +----------+
- =========================================================================
- Sguil events summary for yesterday
- =========================================================================
- +---------+-------------+--------------------------------------------------------------------------+
- | Totals | GenID:SigID | Signature |
- +---------+-------------+--------------------------------------------------------------------------+
- | 3869519 | 1:2101411 | GPL SNMP public access udp |
- | 18075 | 1:2003068 | ET SCAN Potential SSH Scan OUTBOUND |
- | 2184 | 1:2016150 | ET INFO Session Traversal Utilities for NAT (STUN Binding Response) |
- | 943 | 1:2200037 | SURICATA TCP duplicated option |
- | 851 | 1:2001581 | ET SCAN Behavioral Unusual Port 135 traffic, Potential Scan or Infection |
- | 92 | 1:2020565 | ET POLICY Dropbox DNS Lookup - Possible Offsite File Backup in Use |
- | 88 | 1:2009702 | ET POLICY DNS Update From External net |
- | 33 | 1:2200074 | SURICATA TCPv4 invalid checksum |
- | 11 | 1:2402000 | ET DROP Dshield Block Listed Source group 1 |
- | 10 | 1:2100651 | GPL SHELLCODE x86 stealth NOOP |
- | 8 | 1:2403304 | ET CINS Active Threat Intelligence Poor Reputation IP group 5 |
- | 6 | 1:2008581 | ET P2P BitTorrent DHT ping request |
- | 6 | 1:2001219 | ET SCAN Potential SSH Scan |
- | 5 | 1:2522070 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 36 |
- | 5 | 1:2520070 | ET TOR Known Tor Exit Node Traffic group 36 |
- | 3 | 1:2000340 | ET P2P Kaaza Media desktop p2pnetworking.exe Activity |
- | 3 | 1:2200075 | SURICATA UDPv4 invalid checksum |
- | 1 | 1:2520148 | ET TOR Known Tor Exit Node Traffic group 75 |
- | 1 | 1:2403323 | ET CINS Active Threat Intelligence Poor Reputation IP group 24 |
- | 1 | 1:2522148 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 75 |
- | 1 | 1:2523296 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 649 |
- | 1 | 1:2522424 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 213 |
- | 1 | 1:2400002 | ET DROP Spamhaus DROP Listed Traffic Inbound group 3 |
- | 1 | 1:2500082 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 42 |
- +---------+-------------+--------------------------------------------------------------------------+
- +---------+
- | Total |
- +---------+
- | 3891849 |
- +---------+
- =========================================================================
- Top 50 All time Sguil Events
- =========================================================================
- +---------+-------------+--------------------------------------------------------------------------+
- | Totals | GenID:SigID | Signature |
- +---------+-------------+--------------------------------------------------------------------------+
- | 7158612 | 1:2101411 | GPL SNMP public access udp |
- | 32517 | 1:2003068 | ET SCAN Potential SSH Scan OUTBOUND |
- | 4601 | 1:2016150 | ET INFO Session Traversal Utilities for NAT (STUN Binding Response) |
- | 1867 | 1:2200037 | SURICATA TCP duplicated option |
- | 1124 | 1:2001581 | ET SCAN Behavioral Unusual Port 135 traffic, Potential Scan or Infection |
- | 167 | 1:2009702 | ET POLICY DNS Update From External net |
- | 116 | 1:2020565 | ET POLICY Dropbox DNS Lookup - Possible Offsite File Backup in Use |
- | 33 | 1:2200074 | SURICATA TCPv4 invalid checksum |
- | 17 | 1:2402000 | ET DROP Dshield Block Listed Source group 1 |
- | 15 | 1:2403304 | ET CINS Active Threat Intelligence Poor Reputation IP group 5 |
- | 12 | 1:2008581 | ET P2P BitTorrent DHT ping request |
- | 11 | 1:2100651 | GPL SHELLCODE x86 stealth NOOP |
- | 10 | 1:2001219 | ET SCAN Potential SSH Scan |
- | 5 | 1:2520070 | ET TOR Known Tor Exit Node Traffic group 36 |
- | 5 | 1:2000340 | ET P2P Kaaza Media desktop p2pnetworking.exe Activity |
- | 5 | 1:2522070 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 36 |
- | 3 | 1:2200075 | SURICATA UDPv4 invalid checksum |
- | 3 | 1:2403316 | ET CINS Active Threat Intelligence Poor Reputation IP group 17 |
- | 2 | 1:2523296 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 649 |
- | 2 | 1:2522492 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 247 |
- | 2 | 1:2400002 | ET DROP Spamhaus DROP Listed Traffic Inbound group 3 |
- | 2 | 1:2013800 | ET POLICY Outgoing Chromoting Session Response |
- | 1 | 1:2403303 | ET CINS Active Threat Intelligence Poor Reputation IP group 4 |
- | 1 | 1:2520042 | ET TOR Known Tor Exit Node Traffic group 22 |
- | 1 | 1:2400007 | ET DROP Spamhaus DROP Listed Traffic Inbound group 8 |
- | 1 | 1:2522424 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 213 |
- | 1 | 1:2403301 | ET CINS Active Threat Intelligence Poor Reputation IP group 2 |
- | 1 | 1:2403323 | ET CINS Active Threat Intelligence Poor Reputation IP group 24 |
- | 1 | 1:2522042 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 22 |
- | 1 | 1:2520148 | ET TOR Known Tor Exit Node Traffic group 75 |
- | 1 | 1:2500082 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 42 |
- | 1 | 1:2523150 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 576 |
- | 1 | 1:2403308 | ET CINS Active Threat Intelligence Poor Reputation IP group 9 |
- | 1 | 1:2522148 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 75 |
- +---------+-------------+--------------------------------------------------------------------------+
- +---------+
- | Total |
- +---------+
- | 7199518 |
- +---------+
- =========================================================================
- Last update
- =========================================================================
- Start-Date: 2016-09-10 15:14:09
- Commandline: apt-get -y dist-upgrade
- Upgrade: update-manager-core:amd64 (0.196.19, 0.196.21), isc-dhcp-common:amd64 (4.2.4-7ubuntu12.5, 4.2.4-7ubuntu12.6), python3-update-manager:amd64 (0.196.19, 0.196.21), chromium-codecs-ffmpeg-extra:amd64 (51.0.2704.79-0ubuntu0.14.04.1.1121, 52.0.2743.116-0ubuntu0.14.04.1.1134), curl:amd64 (7.35.0-1ubuntu2.8, 7.35.0-1ubuntu2.9), chromium-browser-l10n:amd64 (51.0.2704.79-0ubuntu0.14.04.1.1121, 52.0.2743.116-0ubuntu0.14.04.1.1134), isc-dhcp-client:amd64 (4.2.4-7ubuntu12.5, 4.2.4-7ubuntu12.6), libcurl3:amd64 (7.35.0-1ubuntu2.8, 7.35.0-1ubuntu2.9), xserver-xorg-core-lts-xenial:amd64 (1.18.3-1ubuntu2.2~trusty2, 1.18.3-1ubuntu2.2~trusty3), update-manager:amd64 (0.196.19, 0.196.21), chromium-browser:amd64 (51.0.2704.79-0ubuntu0.14.04.1.1121, 52.0.2743.116-0ubuntu0.14.04.1.1134), file-roller:amd64 (3.10.2.1-0ubuntu4.1, 3.10.2.1-0ubuntu4.2), libcurl3-gnutls:amd64 (7.35.0-1ubuntu2.8, 7.35.0-1ubuntu2.9)
- End-Date: 2016-09-10 15:14:23
- Start-Date: 2016-09-11 03:43:21
- Commandline: apt-get install open-vm-tools
- Install: open-vm-tools:amd64 (9.4.0-1280544-5ubuntu6.2), zerofree:amd64 (1.0.2-1ubuntu1, automatic)
- End-Date: 2016-09-11 03:43:25
- =========================================================================
- ELSA
- =========================================================================
- Syslog-ng
- Checking for process:
- 1897 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- Checking for connection:
- Connection to localhost 514 port [tcp/shell] succeeded!
- MySQL
- Checking for process:
- 1903 /usr/sbin/mysqld
- Checking for connection:
- Connection to localhost 3306 port [tcp/mysql] succeeded!
- Sphinx
- Checking for process:
- 1836 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 1865 /usr/bin/searchd --nodetach
- Checking for connection:
- Connection to localhost 9306 port [tcp/*] succeeded!
- ELSA Buffers in Queue:
- 2
- If this number is consistently higher than 20, please see:
- https://github.com/Security-Onion-Solutions/security-onion/wiki/FAQ#why-does-sostat-show-a-high-number-of-elsa-buffers-in-queue
- ELSA Directory Sizes:
- 1.5G /nsm/elsa/data
- 2.9M /var/lib/mysql/syslog
- 32K /var/lib/mysql/syslog_data
- ELSA Index Date Range
- If you don't have at least 2 full days of logs in the Index Date Range,
- then you'll need to increase log_size_limit in /etc/elsa_node.conf.
- +---------------------+---------------------+
- | MIN(start) | MAX(end) |
- +---------------------+---------------------+
- | 2016-09-10 20:36:41 | 2016-09-12 16:43:56 |
- +---------------------+---------------------+
Add Comment
Please, Sign In to add comment