Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- (standard_in) 1: syntax error
- (standard_in) 1: syntax error
- =========================================================================
- Service Status
- =========================================================================
- Status: HIDS
- * ossec_agent (SO-user)[ OK ]
- Status: Bro
- Name Type Host Status Pid Started
- manager manager localhost running 3247 07 Feb 14:08:05
- proxy proxy localhost running 3588 07 Feb 14:08:10
- SO-server-eth1-1 worker localhost running 4090 07 Feb 14:08:16
- SO-server-eth1-2 worker localhost running 4089 07 Feb 14:08:16
- Status: SO-server-eth1
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (SO-user)[ OK ]
- * snort_agent-1 (SO-user)[ OK ]
- * snort_agent-2 (SO-user)[ OK ]
- * snort-1 (alert data)[ OK ]
- * snort-2 (alert data)[ OK ]
- * barnyard2-1 (spooler, unified2 format)[ OK ]
- * barnyard2-2 (spooler, unified2 format)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- UP BROADCAST MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- eth0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:97824 errors:0 dropped:11 overruns:0 frame:0
- TX packets:16166 errors:0 dropped:0 overruns:0 carrier:0
- collisions:90631 txqueuelen:1000
- RX bytes:21881915 (21.8 MB) TX bytes:13680326 (13.6 MB)
- eth1 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:118358165 errors:0 dropped:33468661 overruns:0 frame:0
- TX packets:2 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:64362663438 (64.3 GB) TX bytes:180 (180.0 B)
- lo Link encap:Local Loopback
- inet addr:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:283411 errors:0 dropped:0 overruns:0 frame:0
- TX packets:283411 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1
- RX bytes:1653438008 (1.6 GB) TX bytes:1653438008 (1.6 GB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
- link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1653540399 283415 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 1653540399 283415 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 21881915 97824 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 11
- TX: bytes packets errors dropped carrier collsns
- 13680326 16166 0 0 0 90631
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 3: eth1: <BROADCAST,MULTICAST,NOARP,PROMISC,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 64363660262 118360277 0 2518436 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 30951467
- TX: bytes packets errors dropped carrier collsns
- 180 2 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 5.9G 4.0K 5.9G 1% /dev
- tmpfs 1.2G 916K 1.2G 1% /run
- /dev/dm-0 1000G 575G 375G 61% /
- none 4.0K 0 4.0K 0% /sys/fs/cgroup
- none 5.0M 0 5.0M 0% /run/lock
- none 5.9G 12K 5.9G 1% /run/shm
- none 100M 4.0K 100M 1% /run/user
- /dev/vda1 236M 51M 173M 23% /boot
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- cupsd 785 root 7u IPv4 8744 0t0 TCP X.X.X.X:631 (LISTEN)
- avahi-dae 806 avahi 12u IPv4 13799 0t0 UDP *:5353
- avahi-dae 806 avahi 13u IPv6 13800 0t0 UDP *:5353
- avahi-dae 806 avahi 14u IPv4 13801 0t0 UDP *:46916
- avahi-dae 806 avahi 15u IPv6 13802 0t0 UDP *:46979
- cups-brow 1004 root 8u IPv4 8805 0t0 UDP *:631
- sshd 1521 root 3u IPv4 12061 0t0 TCP *:ssh_port (LISTEN)
- sshd 1521 root 4u IPv6 12063 0t0 TCP *:ssh_port (LISTEN)
- searchd 1590 sphinxsearch 7u IPv4 12720 0t0 TCP *:9306 (LISTEN)
- searchd 1590 sphinxsearch 8u IPv4 12721 0t0 TCP *:9312 (LISTEN)
- searchd 1590 sphinxsearch 49u IPv4 244831 0t0 TCP X.X.X.X:9306->X.X.X.X:49392 (ESTABLISHED)
- syslog-ng 1660 root 9u IPv4 14142 0t0 TCP *:514 (LISTEN)
- syslog-ng 1660 root 10u IPv4 14143 0t0 UDP *:514
- mysqld 1680 mysql 10u IPv4 14669 0t0 TCP X.X.X.X:50000 (LISTEN)
- salt-mini 1735 root 13u IPv4 16449 0t0 TCP X.X.X.X:56700->X.X.X.X:4506 (ESTABLISHED)
- salt-mini 1735 root 24u IPv4 11244 0t0 TCP X.X.X.X:49270->X.X.X.X:4505 (ESTABLISHED)
- ossec-csy 1835 ossecm 5u IPv4 15395 0t0 UDP X.X.X.X:38951->X.X.X.X:514
- starman 2037 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2048 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2050 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2052 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2054 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2055 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- ntpd 2218 ntp 16u IPv4 16531 0t0 UDP *:123
- ntpd 2218 ntp 17u IPv6 16532 0t0 UDP *:123
- ntpd 2218 ntp 18u IPv4 16538 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 19u IPv4 16539 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 20u IPv4 16540 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 21u IPv6 16541 0t0 UDP [X.X.X.X]:123
- ntpd 2218 ntp 22u IPv6 16542 0t0 UDP [X.X.X.X]:123
- ssh 2966 root 3u IPv4 15833 0t0 TCP X.X.X.X:44776->X.X.X.X:ssh_port (ESTABLISHED)
- ssh 2966 root 4u IPv6 15843 0t0 TCP [X.X.X.X]:3306 (LISTEN)
- ssh 2966 root 5u IPv4 15844 0t0 TCP X.X.X.X:3306 (LISTEN)
- tclsh 3033 SO-user 3u IPv4 20312 0t0 TCP X.X.X.X:43328->X.X.X.X:7736 (ESTABLISHED)
- bro 3247 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- bro 3336 SO-user 0u IPv4 21009 0t0 TCP *:47761 (LISTEN)
- bro 3336 SO-user 1u IPv6 21010 0t0 TCP *:47761 (LISTEN)
- bro 3336 SO-user 2u IPv4 22583 0t0 TCP X.X.X.X:47761->X.X.X.X:55178 (ESTABLISHED)
- bro 3336 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- bro 3336 SO-user 14u IPv4 24638 0t0 TCP X.X.X.X:47761->X.X.X.X:55180 (ESTABLISHED)
- bro 3336 SO-user 19u IPv4 21738 0t0 TCP X.X.X.X:47761->X.X.X.X:55184 (ESTABLISHED)
- bro 3588 SO-user 4u IPv4 22576 0t0 UDP X.X.X.X:41234->X.X.X.X:53
- bro 3688 SO-user 0u IPv4 17140 0t0 TCP X.X.X.X:55178->X.X.X.X:47761 (ESTABLISHED)
- bro 3688 SO-user 4u IPv4 22576 0t0 UDP X.X.X.X:41234->X.X.X.X:53
- bro 3688 SO-user 11u IPv4 17145 0t0 TCP *:47762 (LISTEN)
- bro 3688 SO-user 12u IPv6 17146 0t0 TCP *:47762 (LISTEN)
- bro 3688 SO-user 13u IPv4 24641 0t0 TCP X.X.X.X:47762->X.X.X.X:33122 (ESTABLISHED)
- bro 3688 SO-user 18u IPv4 24666 0t0 TCP X.X.X.X:47762->X.X.X.X:33126 (ESTABLISHED)
- bro 4089 SO-user 4u IPv4 22673 0t0 UDP X.X.X.X:57838->X.X.X.X:53
- bro 4090 SO-user 4u IPv4 23718 0t0 UDP X.X.X.X:42111->X.X.X.X:53
- bro 4185 SO-user 0u IPv4 21727 0t0 TCP X.X.X.X:55180->X.X.X.X:47761 (ESTABLISHED)
- bro 4185 SO-user 4u IPv4 23718 0t0 UDP X.X.X.X:42111->X.X.X.X:53
- bro 4185 SO-user 12u IPv4 21730 0t0 TCP X.X.X.X:33122->X.X.X.X:47762 (ESTABLISHED)
- bro 4185 SO-user 17u IPv4 21735 0t0 TCP *:47763 (LISTEN)
- bro 4185 SO-user 18u IPv6 21736 0t0 TCP *:47763 (LISTEN)
- bro 4210 SO-user 0u IPv4 21261 0t0 TCP X.X.X.X:55184->X.X.X.X:47761 (ESTABLISHED)
- bro 4210 SO-user 4u IPv4 22673 0t0 UDP X.X.X.X:57838->X.X.X.X:53
- bro 4210 SO-user 12u IPv4 21264 0t0 TCP X.X.X.X:33126->X.X.X.X:47762 (ESTABLISHED)
- bro 4210 SO-user 17u IPv4 21269 0t0 TCP *:47764 (LISTEN)
- bro 4210 SO-user 18u IPv6 21270 0t0 TCP *:47764 (LISTEN)
- tclsh 4362 SO-user 3u IPv4 22773 0t0 TCP X.X.X.X:33749->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4392 SO-user 3u IPv4 24829 0t0 TCP X.X.X.X:33843->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4392 SO-user 4u IPv4 24830 0t0 TCP X.X.X.X:8101 (LISTEN)
- tclsh 4392 SO-user 6u IPv4 43505 0t0 TCP X.X.X.X:8101->X.X.X.X:57320 (ESTABLISHED)
- tclsh 4429 SO-user 3u IPv4 21413 0t0 TCP X.X.X.X:35883->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4429 SO-user 4u IPv4 24917 0t0 TCP X.X.X.X:8102 (LISTEN)
- tclsh 4429 SO-user 6u IPv4 43535 0t0 TCP X.X.X.X:8102->X.X.X.X:43342 (ESTABLISHED)
- barnyard2 9265 SO-user 3u IPv4 43504 0t0 TCP X.X.X.X:57320->X.X.X.X:8101 (ESTABLISHED)
- barnyard2 9311 SO-user 3u IPv4 58582 0t0 TCP X.X.X.X:43342->X.X.X.X:8102 (ESTABLISHED)
- sshd 22326 root 3u IPv4 218699 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:15605 (ESTABLISHED)
- sshd 22423 SO-user 3u IPv4 218699 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:15605 (ESTABLISHED)
- perl 22484 root 6u IPv4 243627 0t0 TCP X.X.X.X:49392->X.X.X.X:9306 (ESTABLISHED)
- =========================================================================
- IDS Rules Update
- =========================================================================
- Wed Feb 7 14:30:15 UTC 2018
- Backing up current local_rules.xml file.
- Cleaning up local_rules.xml backup files older than 30 days.
- Backing up current downloaded.rules file before it gets overwritten.
- Cleaning up downloaded.rules backup files older than 30 days.
- Backing up current local.rules file before it gets overwritten.
- Cleaning up local.rules backup files older than 30 days.
- Copying rules from X.X.X.X.
- scp: /usr/local/lib/snort_dynamicrules/*: No such file or directory
- Restarting Barnyard2.
- Restarting: SO-server-eth1
- * stopping: barnyard2-1 (spooler, unified2 format)[ OK ]
- * starting: barnyard2-1 (spooler, unified2 format)[ OK ]
- * stopping: barnyard2-2 (spooler, unified2 format)[ OK ]
- * starting: barnyard2-2 (spooler, unified2 format)[ OK ]
- Restarting IDS Engine.
- Restarting: SO-server-eth1
- * stopping: snort-1 (alert data)[ OK ]
- * starting: snort-1 (alert data)[ OK ]
- * stopping: snort-2 (alert data)[ OK ]
- * starting: snort-2 (alert data)[ OK ]
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 6.23 4.72 3.94
- Processing units: 6
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 15:59:14 up 1:52, 1 user, load average: 6.23, 4.72, 3.94
- Tasks: 220 total, 4 running, 216 sleeping, 0 stopped, 0 zombie
- %Cpu(s): 34.7 us, 6.8 sy, 0.1 ni, 45.7 id, 1.9 wa, 0.0 hi, 10.3 si, 0.4 st
- KiB Mem: 12303568 total, 12018712 used, 284856 free, 43544 buffers
- KiB Swap: 8388604 total, 289556 used, 8099048 free. 7990928 cached Mem
- %CPU %MEM COMMAND
- 80.8 4.0 /usr/bin/indexer --config /etc/sphinxsearch/sphinx.conf --rotate perm_15
- 73.5 4.4 snort -c /etc/nsm/SO-server-eth1/snort.conf -u SO-user -g SO-user -i eth1 -l /nsm/sensor_data/SO-server-eth1/snort-1 --perfmon-file /nsm/sensor_data/SO-server-eth1/snort-1.stats -U --snaplen 1524
- 72.5 4.4 snort -c /etc/nsm/SO-server-eth1/snort.conf -u SO-user -g SO-user -i eth1 -l /nsm/sensor_data/SO-server-eth1/snort-2 --perfmon-file /nsm/sensor_data/SO-server-eth1/snort-2.stats -U --snaplen 1524
- 38.6 2.6 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 37.2 2.4 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 28.0 0.6 perl /opt/elsa/web/cron.pl -c /etc/elsa_web.conf
- 13.6 0.6 netsniff-ng -i eth1 -o /nsm/sensor_data/SO-server-eth1/dailylogs/2018-02-07/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 64 iB --interval 150 iB
- 5.7 0.6 /usr/sbin/mysqld
- 5.6 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 4.2 0.4 perl /opt/elsa/node/elsa.pl -c /etc/elsa_node.conf
- 3.7 0.0 [ksoftirqd/1]
- 3.2 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 2.9 0.1 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- 1.7 0.0 -bash
- 1.3 11.9 /usr/bin/searchd --nodetach
- 0.7 0.0 /bin/bash /usr/sbin/sostat
- 0.6 0.0 [kswapd0]
- 0.6 0.0 sshd: SO-user [priv]
- 0.5 0.0 [kworker/u12:0]
- 0.5 0.6 perl /opt/elsa/web/cron.pl -c /etc/elsa_web.conf
- 0.5 0.0 sudo sostat-redacted
- 0.4 0.0 /var/ossec/bin/ossec-syscheckd
- 0.3 0.1 /usr/bin/dockerd --raw-logs
- 0.2 0.0 [rcu_sched]
- 0.2 0.0 docker-containerd -l unix:///var/run/docker/libcontainerd/docker-containerd.sock --metrics-interval=0 --start-timeout 2m --state-dir /var/run/docker/libcontainerd/containerd --shim docker-containerd-shim --runtime docker-runc
- 0.2 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.2 0.3 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.2 0.4 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.2 0.0 barnyard2 -c /etc/nsm/SO-server-eth1/barnyard2-2.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-eth1/snort-2 -f snort.unified2 -w /etc/nsm/SO-server-eth1/barnyard2.waldo-2 -i SO-server-eth1-2 -U
- 0.2 0.0 [kworker/u12:2]
- 0.2 0.0 CRON
- 0.2 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh > /dev/null 2>&1
- 0.1 0.0 /sbin/init
- 0.1 0.0 [khugepaged]
- 0.1 0.2 /usr/bin/python /usr/bin/salt-minion
- 0.1 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.1 0.0 barnyard2 -c /etc/nsm/SO-server-eth1/barnyard2-1.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-eth1/snort-1 -f snort.unified2 -w /etc/nsm/SO-server-eth1/barnyard2.waldo-1 -i SO-server-eth1-1 -U
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [ksoftirqd/0]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [watchdog/1]
- 0.0 0.0 [migration/1]
- 0.0 0.0 [kworker/1:0]
- 0.0 0.0 [kworker/1:0H]
- 0.0 0.0 [watchdog/2]
- 0.0 0.0 [migration/2]
- 0.0 0.0 [ksoftirqd/2]
- 0.0 0.0 [kworker/2:0]
- 0.0 0.0 [kworker/2:0H]
- 0.0 0.0 [watchdog/3]
- 0.0 0.0 [migration/3]
- 0.0 0.0 [ksoftirqd/3]
- 0.0 0.0 [kworker/3:0H]
- 0.0 0.0 [watchdog/4]
- 0.0 0.0 [migration/4]
- 0.0 0.0 [ksoftirqd/4]
- 0.0 0.0 [kworker/4:0H]
- 0.0 0.0 [watchdog/5]
- 0.0 0.0 [migration/5]
- 0.0 0.0 [ksoftirqd/5]
- 0.0 0.0 [kworker/5:0]
- 0.0 0.0 [kworker/5:0H]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [perf]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [writeback]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [vmstat]
- 0.0 0.0 [fsnotify_mark]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [vballoon]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kworker/2:1]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [deferwq]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kpsmoused]
- 0.0 0.0 [kworker/4:1]
- 0.0 0.0 [kworker/5:1]
- 0.0 0.0 [ttm_swap]
- 0.0 0.0 [qxl_gc]
- 0.0 0.0 [kdmflush]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kdmflush]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [jbd2/dm-0-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kworker/3:1H]
- 0.0 0.0 [kworker/5:1H]
- 0.0 0.0 [kworker/1:1H]
- 0.0 0.0 [kworker/2:1H]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 upstart-udev-bridge --daemon
- 0.0 0.0 /lib/systemd/systemd-udevd --daemon
- 0.0 0.0 dbus-daemon --system --fork
- 0.0 0.0 [kmpathd]
- 0.0 0.0 [kmpath_handlerd]
- 0.0 0.0 [kvm-irqfd-clean]
- 0.0 0.0 /usr/sbin/bluetoothd
- 0.0 0.0 [krfcommd]
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.0 /usr/sbin/cupsd -f
- 0.0 0.0 avahi-daemon: running [SO-server.local]
- 0.0 0.0 avahi-daemon: chroot helper
- 0.0 0.0 [kworker/1:2]
- 0.0 0.0 /usr/sbin/cups-browsed
- 0.0 0.0 upstart-file-bridge --daemon
- 0.0 0.0 upstart-socket-bridge --daemon
- 0.0 0.0 [kworker/4:2]
- 0.0 0.0 /sbin/getty -8 38400 tty4
- 0.0 0.0 /sbin/getty -8 38400 tty5
- 0.0 0.1 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /sbin/getty -8 38400 tty2
- 0.0 0.0 /sbin/getty -8 38400 tty3
- 0.0 0.0 /sbin/getty -8 38400 tty6
- 0.0 0.0 cron
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.0 acpid -c /etc/acpi/events -s /var/run/acpid.socket
- 0.0 0.0 /usr/sbin/irqbalance
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 0.0 0.0 [kauditd]
- 0.0 0.0 lightdm
- 0.0 0.1 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.0 0.0 supervising syslog-ng
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 [kworker/4:1H]
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 /usr/sbin/kerneloops
- 0.0 0.0 lightdm --session-child 16 19
- 0.0 0.0 /bin/sh /usr/lib/lightdm/lightdm-greeter-session /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 //bin/dbus-daemon --fork --print-pid 5 --print-address 7 --session
- 0.0 0.1 /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 /var/ossec/bin/ossec-csyslogd
- 0.0 0.0 /var/ossec/bin/ossec-execd
- 0.0 0.0 /var/ossec/bin/ossec-analysisd
- 0.0 0.0 /var/ossec/bin/ossec-logcollector
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
- 0.0 0.0 /var/ossec/bin/ossec-monitord
- 0.0 0.0 /bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/112/gvfs -f -o big_writes
- 0.0 0.0 lightdm --session-child 12 19
- 0.0 0.1 starman master -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 /sbin/getty -8 38400 tty1
- 0.0 0.0 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- 0.0 0.0 /usr/bin/ssh -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- 0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.1 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-eth1/snort-1.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-2.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-2.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-eth1/snort-2.stats
- 0.0 0.0 [kworker/3:2]
- 0.0 0.0 [kworker/3:1]
- 0.0 0.0 [kworker/0:0]
- 0.0 0.0 [kworker/u12:1]
- 0.0 0.0 [kworker/0:2]
- 0.0 0.0 CRON
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh > /dev/null 2>&1
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh
- 0.0 0.0 [kworker/0:1]
- 0.0 0.0 sshd: SO-user@pts/0
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh
- 0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- eth1: 10237736
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- eth1:
- RX packets:118375333 dropped:33476310 TX packets:2 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- Appl. Name : bro-eth1
- Tot Packets : 51343246
- Tot Pkt Lost : 47811
- Appl. Name : bro-eth1
- Tot Packets : 65349312
- Tot Pkt Lost : 197146
- Appl. Name : snort-cluster-52-socket-0
- Tot Packets : 38295295
- Tot Pkt Lost : 5132033
- Appl. Name : snort-cluster-52-socket-0
- Tot Packets : 50093974
- Tot Pkt Lost : 7861319
- -------------------------------------------------------------------------
- IDS Engine (snort) packet drops:
- /nsm/sensor_data/SO-server-eth1/snort-1.stats last reported pkt_drop_percent as 5.276
- /nsm/sensor_data/SO-server-eth1/snort-2.stats last reported pkt_drop_percent as 10.556
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.210250
- SO-server-eth1-1: 1518019157.379665 recvd=65181203 dropped=197146 link=65181203
- SO-server-eth1-2: 1518019158.592284 recvd=51326075 dropped=47811 link=51326075
- Capture Loss:
- SO-server-eth1-1 23.711863
- SO-server-eth1-1 25.332931
- SO-server-eth1-1 25.485611
- SO-server-eth1-1 25.96035
- SO-server-eth1-2 25.223966
- SO-server-eth1-2 25.622044
- SO-server-eth1-2 27.821147
- SO-server-eth1-2 28.650594
- If you are seeing capture loss without dropped packets, this
- may indicate that an upstream device is dropping packets (tap or SPAN port).
- -------------------------------------------------------------------------
- Netsniff-NG:
- Percentage of packets dropped:
- /var/log/nsm/SO-server-eth1/netsniff-ng.log --
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.6.0 (unknown)
- Total rings : 4
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Cluster Fragment Queue : 157
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/SO-server-eth0/dailylogs/ - 0 days
- 4.0K .
- /nsm/sensor_data/SO-server-eth1/dailylogs/ - 2 days
- 356G .
- 294G ./2018-02-06
- 62G ./2018-02-07
- /nsm/bro/logs/ - 3 days
- 1.5G .
- 935M ./2018-02-05
- 443M ./2018-02-06
- 72M ./2018-02-07
- 4.0M ./stats
- =========================================================================
- Last update
- =========================================================================
- =========================================================================
- Available updates
- =========================================================================
- 64 packages can be updated.
- 48 updates are security updates.
- Run 'sudo soup' to install the latest updates.
- =========================================================================
- ELSA
- =========================================================================
- Syslog-ng
- Checking for process:
- 1660 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- Checking for connection:
- Connection to localhost 514 port [tcp/shell] succeeded!
- MySQL
- Checking for process:
- 1680 /usr/sbin/mysqld
- Checking for connection:
- Connection to localhost 50000 port [tcp/*] succeeded!
- Sphinx
- Checking for process:
- 1587 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 1590 /usr/bin/searchd --nodetach
- Checking for connection:
- Connection to localhost 9306 port [tcp/*] succeeded!
- ELSA Buffers in Queue:
- 3
- If this number is consistently higher than 20, please see:
- https://github.com/Security-Onion-Solutions/security-onion/wiki/FAQ#why-does-sostat-show-a-high-number-of-elsa-buffers-in-queue
- ELSA Directory Sizes:
- 210G /nsm/elsa/data
- 15M /var/lib/mysql/syslog
- 392K /var/lib/mysql/syslog_data
- ELSA Index Date Range
- If you don't have at least 2 full days of logs in the Index Date Range,
- then you'll need to increase log_size_limit in /etc/elsa_node.conf.
- MIN(start) MAX(end)
- 2018-02-01 16:58:15 2018-02-07 15:59:02
- autossh
- Checking for process:
- 2965 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- Checking APIKEY:
- APIKEY matches server.
- starman
- Checking for processes:
- 2037 starman master -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2048 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2050 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2052 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2054 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2055 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- =========================================================================
- Version Information
- =========================================================================
- Ubuntu 14.04.5 LTS
- securityonion-sostat 20120722-0ubuntu0securityonion84
- mis@crockett:~$ clear
- mis@crockett:~$ sudo sostat-redacted
- (standard_in) 1: syntax error
- (standard_in) 1: syntax error
- =========================================================================
- Service Status
- =========================================================================
- Status: HIDS
- * ossec_agent (SO-user)[ OK ]
- Status: Bro
- waiting for lock (owned by PID 23125) ...
- Name Type Host Status Pid Started
- manager manager localhost running 3247 07 Feb 14:08:05
- proxy proxy localhost running 3588 07 Feb 14:08:10
- SO-server-eth1-1 worker localhost running 4090 07 Feb 14:08:16
- SO-server-eth1-2 worker localhost running 4089 07 Feb 14:08:16
- Status: SO-server-eth1
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (SO-user)[ OK ]
- * snort_agent-1 (SO-user)[ OK ]
- * snort_agent-2 (SO-user)[ OK ]
- * snort-1 (alert data)[ OK ]
- * snort-2 (alert data)[ OK ]
- * barnyard2-1 (spooler, unified2 format)[ OK ]
- * barnyard2-2 (spooler, unified2 format)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- UP BROADCAST MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- eth0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:99373 errors:0 dropped:11 overruns:0 frame:0
- TX packets:16685 errors:0 dropped:0 overruns:0 carrier:0
- collisions:93285 txqueuelen:1000
- RX bytes:22375587 (22.3 MB) TX bytes:13889120 (13.8 MB)
- eth1 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:119988245 errors:0 dropped:34754999 overruns:0 frame:0
- TX packets:2 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:65418775319 (65.4 GB) TX bytes:180 (180.0 B)
- lo Link encap:Local Loopback
- inet addr:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:285552 errors:0 dropped:0 overruns:0 frame:0
- TX packets:285552 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1
- RX bytes:1669673391 (1.6 GB) TX bytes:1669673391 (1.6 GB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
- link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1669724426 285554 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 1669724426 285554 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 22375715 99375 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 11
- TX: bytes packets errors dropped carrier collsns
- 13889120 16685 0 0 0 93285
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 3: eth1: <BROADCAST,MULTICAST,NOARP,PROMISC,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 65419308106 119989154 0 2538636 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 32217461
- TX: bytes packets errors dropped carrier collsns
- 180 2 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo SO-usersed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 5.9G 4.0K 5.9G 1% /dev
- tmpfs 1.2G 920K 1.2G 1% /run
- /dev/dm-0 1000G 577G 373G 61% /
- none 4.0K 0 4.0K 0% /sys/fs/cgroup
- none 5.0M 0 5.0M 0% /run/lock
- none 5.9G 12K 5.9G 1% /run/shm
- none 100M 4.0K 100M 1% /run/user
- /dev/vda1 236M 51M 173M 23% /boot
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- cupsd 785 root 7u IPv4 8744 0t0 TCP X.X.X.X:631 (LISTEN)
- avahi-dae 806 avahi 12u IPv4 13799 0t0 UDP *:5353
- avahi-dae 806 avahi 13u IPv6 13800 0t0 UDP *:5353
- avahi-dae 806 avahi 14u IPv4 13801 0t0 UDP *:46916
- avahi-dae 806 avahi 15u IPv6 13802 0t0 UDP *:46979
- cups-brow 1004 root 8u IPv4 8805 0t0 UDP *:631
- sshd 1521 root 3u IPv4 12061 0t0 TCP *:ssh_port (LISTEN)
- sshd 1521 root 4u IPv6 12063 0t0 TCP *:ssh_port (LISTEN)
- searchd 1590 sphinxsearch 7u IPv4 12720 0t0 TCP *:9306 (LISTEN)
- searchd 1590 sphinxsearch 8u IPv4 12721 0t0 TCP *:9312 (LISTEN)
- syslog-ng 1660 root 9u IPv4 14142 0t0 TCP *:514 (LISTEN)
- syslog-ng 1660 root 10u IPv4 14143 0t0 UDP *:514
- mysqld 1680 mysql 10u IPv4 14669 0t0 TCP X.X.X.X:50000 (LISTEN)
- salt-mini 1735 root 13u IPv4 16449 0t0 TCP X.X.X.X:56700->X.X.X.X:4506 (ESTABLISHED)
- salt-mini 1735 root 24u IPv4 11244 0t0 TCP X.X.X.X:49270->X.X.X.X:4505 (ESTABLISHED)
- ossec-csy 1835 ossecm 5u IPv4 15395 0t0 UDP X.X.X.X:38951->X.X.X.X:514
- starman 2037 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2048 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2050 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2052 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2054 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- starman 2055 www-data 5u IPv6 15504 0t0 TCP *:3154 (LISTEN)
- ntpd 2218 ntp 16u IPv4 16531 0t0 UDP *:123
- ntpd 2218 ntp 17u IPv6 16532 0t0 UDP *:123
- ntpd 2218 ntp 18u IPv4 16538 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 19u IPv4 16539 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 20u IPv4 16540 0t0 UDP X.X.X.X:123
- ntpd 2218 ntp 21u IPv6 16541 0t0 UDP [X.X.X.X]:123
- ntpd 2218 ntp 22u IPv6 16542 0t0 UDP [X.X.X.X]:123
- ssh 2966 root 3u IPv4 15833 0t0 TCP X.X.X.X:44776->X.X.X.X:ssh_port (ESTABLISHED)
- ssh 2966 root 4u IPv6 15843 0t0 TCP [X.X.X.X]:3306 (LISTEN)
- ssh 2966 root 5u IPv4 15844 0t0 TCP X.X.X.X:3306 (LISTEN)
- tclsh 3033 SO-user 3u IPv4 20312 0t0 TCP X.X.X.X:43328->X.X.X.X:7736 (ESTABLISHED)
- bro 3247 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- bro 3336 SO-user 0u IPv4 21009 0t0 TCP *:47761 (LISTEN)
- bro 3336 SO-user 1u IPv6 21010 0t0 TCP *:47761 (LISTEN)
- bro 3336 SO-user 2u IPv4 22583 0t0 TCP X.X.X.X:47761->X.X.X.X:55178 (ESTABLISHED)
- bro 3336 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- bro 3336 SO-user 14u IPv4 24638 0t0 TCP X.X.X.X:47761->X.X.X.X:55180 (ESTABLISHED)
- bro 3336 SO-user 19u IPv4 21738 0t0 TCP X.X.X.X:47761->X.X.X.X:55184 (ESTABLISHED)
- bro 3588 SO-user 4u IPv4 22576 0t0 UDP X.X.X.X:41234->X.X.X.X:53
- bro 3688 SO-user 0u IPv4 17140 0t0 TCP X.X.X.X:55178->X.X.X.X:47761 (ESTABLISHED)
- bro 3688 SO-user 4u IPv4 22576 0t0 UDP X.X.X.X:41234->X.X.X.X:53
- bro 3688 SO-user 11u IPv4 17145 0t0 TCP *:47762 (LISTEN)
- bro 3688 SO-user 12u IPv6 17146 0t0 TCP *:47762 (LISTEN)
- bro 3688 SO-user 13u IPv4 24641 0t0 TCP X.X.X.X:47762->X.X.X.X:33122 (ESTABLISHED)
- bro 3688 SO-user 18u IPv4 24666 0t0 TCP X.X.X.X:47762->X.X.X.X:33126 (ESTABLISHED)
- bro 4089 SO-user 4u IPv4 22673 0t0 UDP X.X.X.X:57838->X.X.X.X:53
- bro 4090 SO-user 4u IPv4 23718 0t0 UDP X.X.X.X:42111->X.X.X.X:53
- bro 4185 SO-user 0u IPv4 21727 0t0 TCP X.X.X.X:55180->X.X.X.X:47761 (ESTABLISHED)
- bro 4185 SO-user 4u IPv4 23718 0t0 UDP X.X.X.X:42111->X.X.X.X:53
- bro 4185 SO-user 12u IPv4 21730 0t0 TCP X.X.X.X:33122->X.X.X.X:47762 (ESTABLISHED)
- bro 4185 SO-user 17u IPv4 21735 0t0 TCP *:47763 (LISTEN)
- bro 4185 SO-user 18u IPv6 21736 0t0 TCP *:47763 (LISTEN)
- bro 4210 SO-user 0u IPv4 21261 0t0 TCP X.X.X.X:55184->X.X.X.X:47761 (ESTABLISHED)
- bro 4210 SO-user 4u IPv4 22673 0t0 UDP X.X.X.X:57838->X.X.X.X:53
- bro 4210 SO-user 12u IPv4 21264 0t0 TCP X.X.X.X:33126->X.X.X.X:47762 (ESTABLISHED)
- bro 4210 SO-user 17u IPv4 21269 0t0 TCP *:47764 (LISTEN)
- bro 4210 SO-user 18u IPv6 21270 0t0 TCP *:47764 (LISTEN)
- tclsh 4362 SO-user 3u IPv4 22773 0t0 TCP X.X.X.X:33749->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4392 SO-user 3u IPv4 24829 0t0 TCP X.X.X.X:33843->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4392 SO-user 4u IPv4 24830 0t0 TCP X.X.X.X:8101 (LISTEN)
- tclsh 4392 SO-user 6u IPv4 43505 0t0 TCP X.X.X.X:8101->X.X.X.X:57320 (ESTABLISHED)
- tclsh 4429 SO-user 3u IPv4 21413 0t0 TCP X.X.X.X:35883->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4429 SO-user 4u IPv4 24917 0t0 TCP X.X.X.X:8102 (LISTEN)
- tclsh 4429 SO-user 6u IPv4 43535 0t0 TCP X.X.X.X:8102->X.X.X.X:43342 (ESTABLISHED)
- barnyard2 9265 SO-user 3u IPv4 43504 0t0 TCP X.X.X.X:57320->X.X.X.X:8101 (ESTABLISHED)
- barnyard2 9311 SO-user 3u IPv4 58582 0t0 TCP X.X.X.X:43342->X.X.X.X:8102 (ESTABLISHED)
- sshd 22326 root 3u IPv4 218699 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:15605 (ESTABLISHED)
- sshd 22423 SO-user 3u IPv4 218699 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:15605 (ESTABLISHED)
- archive-l 22961 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 22966 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 22997 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 23010 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 23016 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 23023 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 23194 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- archive-l 23404 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 23729 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 23841 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- summarize 23892 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 24123 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 24141 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 24155 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- time 24204 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- grep 24245 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 24298 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- trace-sum 24454 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- gzip 24484 SO-user 4u IPv4 18366 0t0 UDP X.X.X.X:50739->X.X.X.X:53
- =========================================================================
- IDS Rules Update
- =========================================================================
- Wed Feb 7 14:30:15 UTC 2018
- Backing up current local_rules.xml file.
- Cleaning up local_rules.xml backup files older than 30 days.
- Backing up current downloaded.rules file before it gets overwritten.
- Cleaning up downloaded.rules backup files older than 30 days.
- Backing up current local.rules file before it gets overwritten.
- Cleaning up local.rules backup files older than 30 days.
- Copying rules from X.X.X.X.
- scp: /usr/local/lib/snort_dynamicrules/*: No such file or directory
- Restarting Barnyard2.
- Restarting: SO-server-eth1
- * stopping: barnyard2-1 (spooler, unified2 format)[ OK ]
- * starting: barnyard2-1 (spooler, unified2 format)[ OK ]
- * stopping: barnyard2-2 (spooler, unified2 format)[ OK ]
- * starting: barnyard2-2 (spooler, unified2 format)[ OK ]
- Restarting IDS Engine.
- Restarting: SO-server-eth1
- * stopping: snort-1 (alert data)[ OK ]
- * starting: snort-1 (alert data)[ OK ]
- * stopping: snort-2 (alert data)[ OK ]
- * starting: snort-2 (alert data)[ OK ]
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 19.18 8.55 5.31
- Processing units: 6
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 16:00:40 up 1:53, 1 user, load average: 19.18, 8.55, 5.31
- Tasks: 231 total, 15 running, 216 sleeping, 0 stopped, 0 zombie
- %Cpu(s): 34.9 us, 7.0 sy, 0.1 ni, 45.3 id, 2.0 wa, 0.0 hi, 10.3 si, 0.4 st
- KiB Mem: 12303568 total, 12143432 used, 160136 free, 45876 buffers
- KiB Swap: 8388604 total, 294312 used, 8094292 free. 8140960 cached Mem
- %CPU %MEM COMMAND
- 76.8 4.3 /usr/bin/indexer --config /etc/sphinxsearch/sphinx.conf --rotate perm_15
- 73.5 4.4 snort -c /etc/nsm/SO-server-eth1/snort.conf -u SO-user -g SO-user -i eth1 -l /nsm/sensor_data/SO-server-eth1/snort-1 --perfmon-file /nsm/sensor_data/SO-server-eth1/snort-1.stats -U --snaplen 1524
- 72.5 4.4 snort -c /etc/nsm/SO-server-eth1/snort.conf -u SO-user -g SO-user -i eth1 -l /nsm/sensor_data/SO-server-eth1/snort-2 --perfmon-file /nsm/sensor_data/SO-server-eth1/snort-2.stats -U --snaplen 1524
- 38.5 2.7 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 37.0 2.3 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 13.7 0.6 netsniff-ng -i eth1 -o /nsm/sensor_data/SO-server-eth1/dailylogs/2018-02-07/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 64 iB --interval 150 iB
- 5.7 0.6 /usr/sbin/mysqld
- 5.6 0.2 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 4.5 0.0 gzip -9
- 4.2 0.4 perl /opt/elsa/node/elsa.pl -c /etc/elsa_node.conf
- 4.0 0.0 gzip -9
- 3.7 0.0 [ksoftirqd/1]
- 3.4 0.0 gzip -9
- 3.2 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 3.0 0.1 /usr/bin/python /opt/bro/bin/trace-summary -c -r -S 0.01 -l /opt/bro/etc/networks.cfg conn.2018-02-07-15-00-00.log
- 2.8 0.1 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- 2.6 0.0 gzip -9
- 2.6 0.0 gzip -9
- 1.3 12.0 /usr/bin/searchd --nodetach
- 1.2 0.0 /bin/bash /usr/sbin/sostat
- 0.6 0.0 [kswapd0]
- 0.5 0.0 [kworker/u12:0]
- 0.4 0.0 /var/ossec/bin/ossec-syscheckd
- 0.4 0.6 perl /opt/elsa/web/cron.pl -c /etc/elsa_web.conf
- 0.4 0.0 -bash
- 0.3 0.1 /usr/bin/dockerd --raw-logs
- 0.2 0.0 [rcu_sched]
- 0.2 0.0 docker-containerd -l unix:///var/run/docker/libcontainerd/docker-containerd.sock --metrics-interval=0 --start-timeout 2m --state-dir /var/run/docker/libcontainerd/containerd --shim docker-containerd-shim --runtime docker-runc
- 0.2 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.2 0.4 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.2 0.4 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.2 0.0 barnyard2 -c /etc/nsm/SO-server-eth1/barnyard2-2.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-eth1/snort-2 -f snort.unified2 -w /etc/nsm/SO-server-eth1/barnyard2.waldo-2 -i SO-server-eth1-2 -U
- 0.2 0.0 [kworker/u12:2]
- 0.2 0.0 sshd: SO-user [priv]
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log weird.2018-02-07-15-00-00.log weird 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log files.2018-02-07-15-00-00.log files 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log http_eth1.2018-02-07-15-00-00.log http_eth1 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log dns.2018-02-07-15-00-00.log dns 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log conn.2018-02-07-15-00-00.log conn 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.2 0.0 /bin/bash /opt/bro/share/broctl/scripts/postprocessors/summarize-connections conn.2018-02-07-15-00-00.log conn 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.1 0.0 /sbin/init
- 0.1 0.0 [khugepaged]
- 0.1 0.2 /usr/bin/python /usr/bin/salt-minion
- 0.1 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.1 0.0 barnyard2 -c /etc/nsm/SO-server-eth1/barnyard2-1.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-eth1/snort-1 -f snort.unified2 -w /etc/nsm/SO-server-eth1/barnyard2.waldo-1 -i SO-server-eth1-1 -U
- 0.1 0.0 /bin/bash /opt/bro/share/broctl/scripts/archive-log kerberos.2018-02-07-15-00-00.log kerberos 18-02-07_15.00.00 18-02-07_16.00.00 0 ascii
- 0.1 0.0 sudo sostat-redacted
- 0.1 0.0 /usr/bin/time /opt/bro/bin/trace-summary -c -r -S 0.01 -l /opt/bro/etc/networks.cfg conn.2018-02-07-15-00-00.log
- 0.1 0.0 grep -v exceeds bandwidth
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [ksoftirqd/0]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [watchdog/1]
- 0.0 0.0 [migration/1]
- 0.0 0.0 [kworker/1:0]
- 0.0 0.0 [kworker/1:0H]
- 0.0 0.0 [watchdog/2]
- 0.0 0.0 [migration/2]
- 0.0 0.0 [ksoftirqd/2]
- 0.0 0.0 [kworker/2:0]
- 0.0 0.0 [kworker/2:0H]
- 0.0 0.0 [watchdog/3]
- 0.0 0.0 [migration/3]
- 0.0 0.0 [ksoftirqd/3]
- 0.0 0.0 [kworker/3:0H]
- 0.0 0.0 [watchdog/4]
- 0.0 0.0 [migration/4]
- 0.0 0.0 [ksoftirqd/4]
- 0.0 0.0 [kworker/4:0H]
- 0.0 0.0 [watchdog/5]
- 0.0 0.0 [migration/5]
- 0.0 0.0 [ksoftirqd/5]
- 0.0 0.0 [kworker/5:0]
- 0.0 0.0 [kworker/5:0H]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [perf]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [writeback]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [vmstat]
- 0.0 0.0 [fsnotify_mark]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [vballoon]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kworker/2:1]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [deferwq]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kpsmoused]
- 0.0 0.0 [kworker/4:1]
- 0.0 0.0 [kworker/5:1]
- 0.0 0.0 [ttm_swap]
- 0.0 0.0 [qxl_gc]
- 0.0 0.0 [kdmflush]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kdmflush]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [jbd2/dm-0-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kworker/3:1H]
- 0.0 0.0 [kworker/5:1H]
- 0.0 0.0 [kworker/1:1H]
- 0.0 0.0 [kworker/2:1H]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 upstart-udev-bridge --daemon
- 0.0 0.0 /lib/systemd/systemd-udevd --daemon
- 0.0 0.0 dbus-daemon --system --fork
- 0.0 0.0 [kmpathd]
- 0.0 0.0 [kmpath_handlerd]
- 0.0 0.0 [kvm-irqfd-clean]
- 0.0 0.0 /usr/sbin/bluetoothd
- 0.0 0.0 [krfcommd]
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.0 /usr/sbin/cupsd -f
- 0.0 0.0 avahi-daemon: running [SO-server.local]
- 0.0 0.0 avahi-daemon: chroot helper
- 0.0 0.0 [kworker/1:2]
- 0.0 0.0 /usr/sbin/cups-browsed
- 0.0 0.0 upstart-file-bridge --daemon
- 0.0 0.0 upstart-socket-bridge --daemon
- 0.0 0.0 [kworker/4:2]
- 0.0 0.0 /sbin/getty -8 38400 tty4
- 0.0 0.0 /sbin/getty -8 38400 tty5
- 0.0 0.1 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /sbin/getty -8 38400 tty2
- 0.0 0.0 /sbin/getty -8 38400 tty3
- 0.0 0.0 /sbin/getty -8 38400 tty6
- 0.0 0.0 cron
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.0 acpid -c /etc/acpi/events -s /var/run/acpid.socket
- 0.0 0.0 /usr/sbin/irqbalance
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 0.0 0.0 [kauditd]
- 0.0 0.0 lightdm
- 0.0 0.1 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.0 0.0 supervising syslog-ng
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 [kworker/4:1H]
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-syslog-ng.sh
- 0.0 0.0 /usr/sbin/kerneloops
- 0.0 0.0 lightdm --session-child 16 19
- 0.0 0.0 /bin/sh /usr/lib/lightdm/lightdm-greeter-session /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 //bin/dbus-daemon --fork --print-pid 5 --print-address 7 --session
- 0.0 0.1 /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 /var/ossec/bin/ossec-csyslogd
- 0.0 0.0 /var/ossec/bin/ossec-execd
- 0.0 0.0 /var/ossec/bin/ossec-analysisd
- 0.0 0.0 /var/ossec/bin/ossec-logcollector
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
- 0.0 0.0 /var/ossec/bin/ossec-monitord
- 0.0 0.0 /bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/112/gvfs -f -o big_writes
- 0.0 0.0 lightdm --session-child 12 19
- 0.0 0.1 starman master -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 1.0 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 /sbin/getty -8 38400 tty1
- 0.0 0.0 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- 0.0 0.0 /usr/bin/ssh -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- 0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.1 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p local -p SO-server-eth1-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-eth1/snort-1.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-2.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-2.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-eth1/snort-2.stats
- 0.0 0.0 [kworker/3:2]
- 0.0 0.0 [kworker/3:1]
- 0.0 0.0 [kworker/u12:1]
- 0.0 0.0 [kworker/0:2]
- 0.0 0.0 CRON
- 0.0 0.0 /bin/sh -c sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh > /dev/null 2>&1
- 0.0 0.0 sh /opt/elsa/contrib/securityonion/contrib/securityonion-elsa-cron.sh
- 0.0 0.0 [kworker/0:1]
- 0.0 0.0 sshd: SO-user@pts/0
- 0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- eth1: 10237736
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- eth1:
- RX packets:120056197 dropped:34781111 TX packets:2 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- Appl. Name : bro-eth1
- Tot Packets : 52056991
- Tot Pkt Lost : 219746
- Appl. Name : bro-eth1
- Tot Packets : 66313101
- Tot Pkt Lost : 288350
- Appl. Name : snort-cluster-52-socket-0
- Tot Packets : 39008804
- Tot Pkt Lost : 5224028
- Appl. Name : snort-cluster-52-socket-0
- Tot Packets : 51057410
- Tot Pkt Lost : 7953355
- -------------------------------------------------------------------------
- IDS Engine (snort) packet drops:
- /nsm/sensor_data/SO-server-eth1/snort-1.stats last reported pkt_drop_percent as 14.157
- /nsm/sensor_data/SO-server-eth1/snort-2.stats last reported pkt_drop_percent as 7.322
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.430915
- SO-server-eth1-1: 1518019243.469166 recvd=66047588 dropped=288350 link=66047588
- SO-server-eth1-2: 1518019243.668787 recvd=51863244 dropped=219746 link=51863244
- No capture loss reported.
- -------------------------------------------------------------------------
- Netsniff-NG:
- Percentage of packets dropped:
- /var/log/nsm/SO-server-eth1/netsniff-ng.log --
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.6.0 (unknown)
- Total rings : 4
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Cluster Fragment Queue : 0
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/SO-server-eth0/dailylogs/ - 0 days
- 4.0K .
- /nsm/sensor_data/SO-server-eth1/dailylogs/ - 2 days
- 357G .
- 294G ./2018-02-06
- 63G ./2018-02-07
- /nsm/bro/logs/ - 3 days
- 1.5G .
- 935M ./2018-02-05
- 443M ./2018-02-06
- 94M ./2018-02-07
- 4.0M ./stats
- =========================================================================
- Last update
- =========================================================================
- =========================================================================
- Available updates
- =========================================================================
- 64 packages can be updated.
- 48 updates are security updates.
- Run 'sudo soup' to install the latest updates.
- =========================================================================
- ELSA
- =========================================================================
- Syslog-ng
- Checking for process:
- 1660 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- Checking for connection:
- Connection to localhost 514 port [tcp/shell] succeeded!
- MySQL
- Checking for process:
- 1680 /usr/sbin/mysqld
- Checking for connection:
- Connection to localhost 50000 port [tcp/*] succeeded!
- Sphinx
- Checking for process:
- 1587 su -s /bin/sh -c exec "$0" "$@" sphinxsearch -- /usr/bin/searchd --nodetach
- 1590 /usr/bin/searchd --nodetach
- Checking for connection:
- Connection to localhost 9306 port [tcp/*] succeeded!
- ELSA Buffers in Queue:
- 3
- If this number is consistently higher than 20, please see:
- https://github.com/Security-Onion-Solutions/security-onion/wiki/FAQ#why-does-sostat-show-a-high-number-of-elsa-buffers-in-queue
- ELSA Directory Sizes:
- 211G /nsm/elsa/data
- 15M /var/lib/mysql/syslog
- 392K /var/lib/mysql/syslog_data
- ELSA Index Date Range
- If you don't have at least 2 full days of logs in the Index Date Range,
- then you'll need to increase log_size_limit in /etc/elsa_node.conf.
- MIN(start) MAX(end)
- 2018-02-01 16:58:15 2018-02-07 16:00:02
- autossh
- Checking for process:
- 2965 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -i /root/.ssh/securityonion -L 3306:X.X.X.X:3306 -R 50000:localhost:3154 SO-user@X.X.X.X
- Checking APIKEY:
- APIKEY matches server.
- starman
- Checking for processes:
- 2037 starman master -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2048 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2050 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2052 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2054 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- 2055 starman worker -I/opt/elsa/web/lib --user=www-data --listen :3154 --daemonize --pid /var/run/starman.pid --error-log /var/log/starman.log /opt/elsa/web/lib/Web.psgi
- =========================================================================
- Version Information
- =========================================================================
- Ubuntu 14.04.5 LTS
- securityonion-sostat 20120722-0ubuntu0securityonion84
Add Comment
Please, Sign In to add comment