Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- training@SuricataThreatHunting:~$ selks-health-check_stamus
- ● suricata.service - LSB: Next Generation IDS/IPS
- Loaded: loaded (/etc/init.d/suricata; generated; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 23:12:40 CEST; 9min ago
- Docs: man:systemd-sysv-generator(8)
- Process: 4051 ExecStop=/etc/init.d/suricata stop (code=exited, status=0/SUCCESS)
- Process: 4065 ExecStart=/etc/init.d/suricata start (code=exited, status=0/SUCCESS)
- Tasks: 10 (limit: 19660)
- CGroup: /system.slice/suricata.service
- └─4072 /usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid --af-packet -D -v --user=logstash
- May 15 23:12:40 SuricataThreatHunting systemd[1]: Starting LSB: Next Generation IDS/IPS...
- May 15 23:12:40 SuricataThreatHunting suricata[4065]: Starting suricata in IDS (af-packet) mode... done.
- May 15 23:12:40 SuricataThreatHunting systemd[1]: Started LSB: Next Generation IDS/IPS.
- ● elasticsearch.service - Elasticsearch
- Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 22:05:18 CEST; 1h 16min ago
- Docs: http://www.elastic.co
- Main PID: 624 (java)
- Tasks: 83 (limit: 19660)
- CGroup: /system.slice/elasticsearch.service
- ├─ 624 /usr/bin/java -Xms1g -Xmx1g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -De…et
- └─1012 /usr/share/elasticsearch/modules/x-pack-ml/platform/linux-x86_64/bin/controller
- May 15 22:05:18 SuricataThreatHunting systemd[1]: Started Elasticsearch.
- May 15 22:05:18 SuricataThreatHunting elasticsearch[624]: warning: Falling back to java on path. This behavior is deprecated. Specify JAVA_HOME
- ● logstash.service - logstash
- Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 22:05:18 CEST; 1h 16min ago
- Main PID: 458 (java)
- Tasks: 36 (limit: 19660)
- CGroup: /system.slice/logstash.service
- └─458 /usr/bin/java -Xms1g -Xmx1g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Dja…sh
- May 15 22:06:04 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:04,799][INFO ][logstash.outputs.elasticsearch] Attempting to install templa…}}
- May 15 22:06:04 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:04,799][INFO ][logstash.outputs.elasticsearch] Attempting to install templa…}}
- May 15 22:06:04 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:04,883][INFO ][logstash.outputs.elasticsearch] Installing elasticsea…/logstash
- May 15 22:06:04 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:04,887][INFO ][logstash.outputs.elasticsearch] Installing elasticsea…/logstash
- May 15 22:06:05 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:05,344][INFO ][logstash.filters.geoip ] Using geoip database {:pat…ty.mmdb"}
- May 15 22:06:05 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:05,380][INFO ][logstash.filters.geoip ] Using geoip database {:pat…ty.mmdb"}
- May 15 22:06:05 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:05,655][INFO ][logstash.pipeline ] Pipeline started successfu…5f run>"}
- May 15 22:06:05 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:05,726][INFO ][logstash.agent ] Pipelines running {:count=…ines=>[]}
- May 15 22:06:05 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:05,782][INFO ][filewatch.observingtail ] START, creating Discoverer…llections
- May 15 22:06:06 SuricataThreatHunting logstash[458]: [2019-05-15T22:06:06,156][INFO ][logstash.agent ] Successfully started Logst…rt=>9600}
- Hint: Some lines were ellipsized, use -l to show in full.
- ● kibana.service - Kibana
- Loaded: loaded (/etc/systemd/system/kibana.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 22:05:18 CEST; 1h 16min ago
- Main PID: 448 (node)
- Tasks: 11 (limit: 19660)
- CGroup: /system.slice/kibana.service
- └─448 /usr/share/kibana/bin/../node/bin/node --no-warnings --max-http-header-size=65536 /usr/share/kibana/bin/../src/cli -c /etc/kibana…ml
- May 15 22:41:34 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:34Z","tags":[],"pid":448,"method":"get","stat…"}
- May 15 22:41:35 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:35Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:41:35 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:35Z","tags":[],"pid":448,"method":"get","stat…"}
- May 15 22:41:35 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:35Z","tags":[],"pid":448,"method":"get","stat…"}
- May 15 22:41:40 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:40Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:41:42 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:42Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:42:00 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:41:59Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:42:31 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:42:31Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:42:56 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:42:56Z","tags":[],"pid":448,"method":"post","sta…"}
- May 15 22:45:56 SuricataThreatHunting kibana[448]: {"type":"response","@timestamp":"2019-05-15T20:45:56Z","tags":[],"pid":448,"method":"get","stat…"}
- Hint: Some lines were ellipsized, use -l to show in full.
- ● evebox.service - EveBox Server
- Loaded: loaded (/lib/systemd/system/evebox.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 22:05:18 CEST; 1h 16min ago
- Main PID: 446 (evebox)
- Tasks: 12 (limit: 19660)
- CGroup: /system.slice/evebox.service
- └─446 /usr/bin/evebox server
- May 15 23:21:32 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:32 (anonymous.go:64) <Info> -- Logging in anonymous user {training} fro…:1]:41330
- May 15 23:21:32 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:32 (datastore-alertquery.go:155) <Info> -- Query elapsed time: 8.500778ms
- May 15 23:21:37 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:37 (anonymous.go:64) <Info> -- Logging in anonymous user {training} fro…:1]:41334
- May 15 23:21:37 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:37 (datastore-alertquery.go:155) <Info> -- Query elapsed time: 8.294859ms
- May 15 23:21:42 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:42 (anonymous.go:64) <Info> -- Logging in anonymous user {training} fro…:1]:41344
- May 15 23:21:42 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:42 (datastore-alertquery.go:155) <Info> -- Query elapsed time: 2.537598ms
- May 15 23:21:47 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:47 (anonymous.go:64) <Info> -- Logging in anonymous user {training} fro…:1]:41348
- May 15 23:21:47 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:47 (datastore-alertquery.go:155) <Info> -- Query elapsed time: 6.996214ms
- May 15 23:21:52 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:52 (anonymous.go:64) <Info> -- Logging in anonymous user {training} fro…:1]:41358
- May 15 23:21:52 SuricataThreatHunting evebox[446]: 2019-05-15 23:21:52 (datastore-alertquery.go:155) <Info> -- Query elapsed time: 4.367815ms
- Hint: Some lines were ellipsized, use -l to show in full.
- ● molochviewer-selks.service - Moloch Viewer
- Loaded: loaded (/etc/systemd/system/molochviewer-selks.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 23:16:04 CEST; 5min ago
- Main PID: 4204 (sh)
- Tasks: 11 (limit: 19660)
- CGroup: /system.slice/molochviewer-selks.service
- ├─4204 /bin/sh -c /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini >> /data/moloch/logs/viewer.log 2>&1
- └─4208 /data/moloch/bin/node viewer.js -c /data/moloch/etc/config.ini
- May 15 23:16:04 SuricataThreatHunting systemd[1]: Started Moloch Viewer.
- ● molochpcapread-selks.service - Moloch Pcap Read
- Loaded: loaded (/etc/systemd/system/molochpcapread-selks.service; enabled; vendor preset: enabled)
- Active: active (running) since Wed 2019-05-15 23:16:04 CEST; 5min ago
- Main PID: 4201 (sh)
- Tasks: 5 (limit: 19660)
- CGroup: /system.slice/molochpcapread-selks.service
- ├─4201 /bin/sh -c /data/moloch/bin/moloch-capture -c /data/moloch/etc/config.ini -m -s -R /data/nsm/ >> /data/moloch/logs/capture.log …&1
- └─4202 /data/moloch/bin/moloch-capture -c /data/moloch/etc/config.ini -m -s -R /data/nsm/
- May 15 23:16:04 SuricataThreatHunting systemd[1]: Stopped Moloch Pcap Read.
- May 15 23:16:04 SuricataThreatHunting systemd[1]: Started Moloch Pcap Read.
- error: <class 'socket.error'>, [Errno 13] Permission denied: file: /usr/lib/python2.7/socket.py line: 228
- ii elasticsearch 6.7.2 all Elasticsearch is a distributed RESTful search engine built for the cloud. Reference documentation can be found at https://www.elastic.co/guide/en/elasticsearch/reference/current/index.html and the 'Elasticsearch: The Definitive Guide' book can be found at https://www.elastic.co/guide/en/elasticsearch/guide/current/index.html
- ii elasticsearch-curator 5.7.6 amd64 Have indices in Elasticsearch? This is the tool for you!\n\nLike a museum curator manages the exhibits and collections on display, \nElasticsearch Curator helps you curate, or manage your indices.
- ii evebox 1:0.10.2 amd64 no description given
- ii kibana 6.7.2 amd64 Explore and visualize your Elasticsearch data
- ii kibana-dashboards-stamus 2019030501 amd64 Kibana 6 dashboard templates.
- ii logstash 1:6.7.2-1 all An extensible logging pipeline
- ii moloch 1.8.0-1 amd64 Moloch Full Packet System
- ii scirius 3.2.0-1 amd64 Django application to manage Suricata ruleset
- ii suricata 2019040702-0stamus0 amd64 Suricata open source multi-thread IDS/IPS/NSM system.
- Filesystem Type Size Used Avail Use% Mounted on
- udev devtmpfs 3.9G 0 3.9G 0% /dev
- tmpfs tmpfs 797M 17M 780M 3% /run
- /dev/sda1 ext4 24G 8.7G 14G 39% /
- tmpfs tmpfs 3.9G 19M 3.9G 1% /dev/shm
- tmpfs tmpfs 5.0M 0 5.0M 0% /run/lock
- tmpfs tmpfs 3.9G 0 3.9G 0% /sys/fs/cgroup
- tmpfs tmpfs 797M 12K 797M 1% /run/user/1001
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement