Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- =========================================================================
- Service Status
- =========================================================================
- Status: securityonion
- * SO-user server[ OK ]
- Status: HIDS
- * ossec_agent (SO-user)[ OK ]
- Status: Bro
- Name Type Host Status Pid Started
- bro standalone localhost running 10369 12 Apr 14:11:46
- Status: SO-server-eth1
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (SO-user)[ OK ]
- * snort_agent-1 (SO-user)[ OK ]
- * snort-1 (alert data)[ OK ]
- * barnyard2-1 (spooler, unified2 format)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- br-5e455ea35dc9 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:3 errors:0 dropped:0 overruns:0 frame:0
- TX packets:48 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:84 (84.0 B) TX bytes:7154 (7.1 KB)
- docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:1943 errors:0 dropped:0 overruns:0 frame:0
- TX packets:1948 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:8717119 (8.7 MB) TX bytes:8471404 (8.4 MB)
- eth0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:543 errors:0 dropped:0 overruns:0 frame:0
- TX packets:661 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:63638 (63.6 KB) TX bytes:63619 (63.6 KB)
- eth1 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:123050 errors:0 dropped:0 overruns:0 frame:0
- TX packets:3 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:7481807 (7.4 MB) TX bytes:270 (270.0 B)
- lo Link encap:Local Loopback
- inet addr:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:5746 errors:0 dropped:0 overruns:0 frame:0
- TX packets:5746 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1
- RX bytes:17671172 (17.6 MB) TX bytes:17671172 (17.6 MB)
- so-curator
- -------------------------------------------------------------------------
- (eth0)
- veth749199a Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:44 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:6056 (6.0 KB)
- (eth1)
- veth8d65c25 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:328 errors:0 dropped:0 overruns:0 frame:0
- TX packets:260 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:47012 (47.0 KB) TX bytes:303939 (303.9 KB)
- so-elastalert
- -------------------------------------------------------------------------
- (eth0)
- veth08048b7 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:44 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:6056 (6.0 KB)
- (eth1)
- vetha658568 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:526 errors:0 dropped:0 overruns:0 frame:0
- TX packets:454 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:125714 (125.7 KB) TX bytes:94048 (94.0 KB)
- so-kibana
- -------------------------------------------------------------------------
- (eth0)
- vethbe07365 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:1613 errors:0 dropped:0 overruns:0 frame:0
- TX packets:1503 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:8349109 (8.3 MB) TX bytes:8434654 (8.4 MB)
- (eth1)
- veth1f6f38d Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:4976 errors:0 dropped:0 overruns:0 frame:0
- TX packets:3645 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:8869533 (8.8 MB) TX bytes:1318994 (1.3 MB)
- so-elasticsearch
- -------------------------------------------------------------------------
- (eth0)
- vethe3f2c7f Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:313 errors:0 dropped:0 overruns:0 frame:0
- TX packets:489 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:394426 (394.4 KB) TX bytes:44176 (44.1 KB)
- (eth1)
- veth186c3f0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:4226 errors:0 dropped:0 overruns:0 frame:0
- TX packets:5890 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:1698726 (1.6 MB) TX bytes:9050990 (9.0 MB)
- so-freqserver
- -------------------------------------------------------------------------
- (eth0)
- veth4cb899a Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:81 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:12119 (12.1 KB)
- (eth1)
- veth30cc751 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:83 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:12293 (12.2 KB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
- link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 17671172 5746 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 17671172 5746 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 63638 543 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 63619 661 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 3: eth1: <BROADCAST,MULTICAST,NOARP,PROMISC,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 7481807 123050 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 270 3 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 4: docker0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 8717119 1943 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 8471404 1948 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 5: br-5e455ea35dc9: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 84 3 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 7154 48 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 7: veth4cb899a@if6: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 12119 81 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 9: veth30cc751@if8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-5e455ea35dc9 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 12293 83 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 11: vethe3f2c7f@if10: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 394426 313 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 44176 489 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 13: veth186c3f0@if12: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-5e455ea35dc9 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1698858 4228 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 9051122 5892 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 19: vethbe07365@if18: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 8349109 1613 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 8434654 1503 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 21: veth1f6f38d@if20: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-5e455ea35dc9 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 8869665 4978 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 1319126 3647 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 23: veth08048b7@if22: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 6056 44 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 25: vetha658568@if24: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-5e455ea35dc9 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 125714 526 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 94048 454 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 27: veth749199a@if26: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 6056 44 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 29: veth8d65c25@if28: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-5e455ea35dc9 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 47012 328 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 303939 260 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 1.5G 4.0K 1.5G 1% /dev
- tmpfs 300M 1.5M 298M 1% /run
- /dev/sda1 17G 8.1G 7.8G 52% /
- none 4.0K 0 4.0K 0% /sys/fs/cgroup
- none 5.0M 0 5.0M 0% /run/lock
- none 1.5G 1.4M 1.5G 1% /run/shm
- none 100M 28K 100M 1% /run/user
- none 17G 8.1G 7.8G 52% /var/lib/docker/aufs/mnt/e1018557b4576b3405641725f304af113fde9af85544ed1e3ed345b009431772
- shm 64M 0 64M 0% /var/lib/docker/containers/9f10032d2013c0217207be21bc1f05c239f210d4bf34e43e4e7f7cee6c03cf73/mounts/shm
- none 17G 8.1G 7.8G 52% /var/lib/docker/aufs/mnt/bb4eb4a68340aaa3618e4be7eed857ecdf608e4f0f6a279b172ccb7a27daea74
- shm 64M 0 64M 0% /var/lib/docker/containers/0eaeea57cf6c07d34c3f46f989f4dfdabd62e8e3bb2cdbef7c527ea4f129a45b/mounts/shm
- none 17G 8.1G 7.8G 52% /var/lib/docker/aufs/mnt/9caddd7f611302447461de6f24456836831f5fda7ab547bb0d8319dd78d6676b
- shm 64M 0 64M 0% /var/lib/docker/containers/a5ad18aedd369a71c02c2c6a18ca5f59bb80f347b66f1f2cb35e08ec7594550d/mounts/shm
- none 17G 8.1G 7.8G 52% /var/lib/docker/aufs/mnt/27e54819e8195f9b7c2226b4cd1dcb0c3e736f578513cdd892b3117d08edea98
- shm 64M 0 64M 0% /var/lib/docker/containers/2b27abf540bde224175d693e5704903f5c3d9f6aa98df1f507f42d66fc5222af/mounts/shm
- none 17G 8.1G 7.8G 52% /var/lib/docker/aufs/mnt/ec071781c730bcf68046102e1cb746860810973521765c2282340ed3f73a8f92
- shm 64M 0 64M 0% /var/lib/docker/containers/2adb19d0a241e32e9cecd2d029311400b6634ae0a9617ace2f8351e22545acc5/mounts/shm
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- avahi-dae 733 avahi 12u IPv4 11337 0t0 UDP *:5353
- avahi-dae 733 avahi 13u IPv6 11338 0t0 UDP *:5353
- avahi-dae 733 avahi 14u IPv4 11339 0t0 UDP *:33062
- avahi-dae 733 avahi 15u IPv6 11340 0t0 UDP *:43467
- sshd 1704 root 3u IPv4 13613 0t0 TCP *:ssh_port (LISTEN)
- sshd 1704 root 4u IPv6 13615 0t0 TCP *:ssh_port (LISTEN)
- cups-brow 1792 root 6u IPv6 20351 0t0 TCP [X.X.X.X]:55548->[X.X.X.X]:631 (CLOSE_WAIT)
- cups-brow 1792 root 8u IPv4 20358 0t0 UDP *:631
- cupsd 3186 root 10u IPv6 20281 0t0 TCP [X.X.X.X]:631 (LISTEN)
- cupsd 3186 root 11u IPv4 20282 0t0 TCP X.X.X.X:631 (LISTEN)
- mysqld 3619 mysql 10u IPv4 21250 0t0 TCP X.X.X.X:3306 (LISTEN)
- tclsh 5472 SO-user 13u IPv4 24159 0t0 TCP *:7734 (LISTEN)
- tclsh 5472 SO-user 14u IPv6 24160 0t0 TCP *:7734 (LISTEN)
- tclsh 5472 SO-user 15u IPv4 24163 0t0 TCP *:7736 (LISTEN)
- tclsh 5472 SO-user 16u IPv6 24164 0t0 TCP *:7736 (LISTEN)
- tclsh 5472 SO-user 17u IPv4 24394 0t0 TCP X.X.X.X:7736->X.X.X.X:40500 (ESTABLISHED)
- tclsh 5472 SO-user 18u IPv4 29808 0t0 TCP X.X.X.X:7736->X.X.X.X:35440 (ESTABLISHED)
- tclsh 5472 SO-user 19u IPv4 29975 0t0 TCP X.X.X.X:7736->X.X.X.X:41428 (ESTABLISHED)
- tclsh 5522 SO-user 3u IPv4 24393 0t0 TCP X.X.X.X:40500->X.X.X.X:7736 (ESTABLISHED)
- tclsh 5930 SO-user 3u IPv4 29807 0t0 TCP X.X.X.X:35440->X.X.X.X:7736 (ESTABLISHED)
- tclsh 5949 SO-user 3u IPv4 29974 0t0 TCP X.X.X.X:41428->X.X.X.X:7736 (ESTABLISHED)
- tclsh 5949 SO-user 4u IPv4 29976 0t0 TCP X.X.X.X:8101 (LISTEN)
- tclsh 5949 SO-user 5u IPv4 33845 0t0 TCP X.X.X.X:8101->X.X.X.X:33716 (ESTABLISHED)
- barnyard2 6034 SO-user 3u IPv4 33844 0t0 TCP X.X.X.X:33716->X.X.X.X:8101 (ESTABLISHED)
- docker-pr 6983 root 4u IPv4 31895 0t0 TCP X.X.X.X:9300 (LISTEN)
- docker-pr 7001 root 4u IPv4 31925 0t0 TCP X.X.X.X:9200 (LISTEN)
- docker-pr 8073 root 4u IPv4 36010 0t0 TCP X.X.X.X:5601 (LISTEN)
- ntpd 8699 ntp 16u IPv4 37398 0t0 UDP *:123
- ntpd 8699 ntp 17u IPv6 37399 0t0 UDP *:123
- ntpd 8699 ntp 18u IPv4 37405 0t0 UDP X.X.X.X:123
- ntpd 8699 ntp 19u IPv4 37406 0t0 UDP X.X.X.X:123
- ntpd 8699 ntp 20u IPv4 37407 0t0 UDP X.X.X.X:123
- ntpd 8699 ntp 21u IPv4 37408 0t0 UDP X.X.X.X:123
- ntpd 8699 ntp 22u IPv6 37409 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 24u IPv6 37411 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 25u IPv6 37412 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 26u IPv6 37413 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 27u IPv6 37414 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 28u IPv6 37415 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 30u IPv6 37417 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 31u IPv6 37418 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 32u IPv6 37419 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 33u IPv6 37420 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 35u IPv6 43046 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 36u IPv6 43047 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 37u IPv6 43048 0t0 UDP [X.X.X.X]:123
- ntpd 8699 ntp 38u IPv6 43049 0t0 UDP [X.X.X.X]:123
- apache2 9546 root 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- apache2 9550 www-data 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- apache2 9551 www-data 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- apache2 9552 www-data 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- apache2 9553 www-data 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- apache2 9554 www-data 4u IPv6 41648 0t0 TCP *:443 (LISTEN)
- syslog-ng 9621 root 12u IPv4 41705 0t0 TCP *:514 (LISTEN)
- syslog-ng 9621 root 13u IPv4 41706 0t0 UDP *:514
- ossec-csy 9728 ossecm 5u IPv4 41919 0t0 UDP X.X.X.X:42224->X.X.X.X:514
- bro 10369 SO-user 4u IPv4 42711 0t0 UDP X.X.X.X:43904->X.X.X.X:53
- bro 10380 SO-user 0u IPv4 42765 0t0 TCP *:47760 (LISTEN)
- bro 10380 SO-user 1u IPv6 42766 0t0 TCP *:47760 (LISTEN)
- bro 10380 SO-user 4u IPv4 42711 0t0 UDP X.X.X.X:43904->X.X.X.X:53
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 1.12 1.78 1.69
- Processing units: 1
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 14:24:20 up 16 min, 4 users, load average: 1.12, 1.78, 1.69
- Tasks: 272 total, 1 running, 271 sleeping, 0 stopped, 0 zombie
- %Cpu(s): 53.4 us, 8.6 sy, 5.7 ni, 27.1 id, 4.6 wa, 0.0 hi, 0.6 si, 0.0 st
- KiB Mem: 3062204 total, 2969180 used, 93024 free, 25092 buffers
- KiB Swap: 3143676 total, 522228 used, 2621448 free. 902160 cached Mem
- %CPU %MEM COMMAND
- 7.7 5.9 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p standalone -p local -p bro local.bro broctl broctl/standalone broctl/auto
- 3.5 7.2 wireshark
- 3.3 33.0 /usr/lib/jvm/jre-1.8.0-openjdk/bin/java -Xms765m -Xmx765m -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -XX:-OmitStackTraceInFastThrow -Dio.netty.noUnsafe=true -Dio.netty.noKeySetOptimization=true -Dio.netty.recycler.maxCapacityPerThread=0 -Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true -Djava.io.tmpdir=/tmp/elasticsearch.8DTPA80e -XX:+HeapDumpOnOutOfMemoryError -XX:+PrintGCDetails -XX:+PrintGCDateStamps -XX:+PrintTenuringDistribution -XX:+PrintGCApplicationStoppedTime -Xloggc:logs/gc.log -XX:+UseGCLogFileRotation -XX:NumberOfGCLogFiles=32 -XX:GCLogFileSize=64m -Des.cgroups.hierarchy.override=/ -Des.path.home=/usr/share/elasticsearch -Des.path.conf=/usr/share/elasticsearch/config -cp /usr/share/elasticsearch/lib/* org.elasticsearch.bootstrap.Elasticsearch -Ecluster.name=SO-server -Ebootstrap.memory_lock=true -Etransport.host=X.X.X.X -Ehttp.host=X.X.X.X
- 3.1 4.1 snort -c /etc/nsm/SO-server-eth1/snort.conf -u SO-user -g SO-user -i eth1 -l /nsm/sensor_data/SO-server-eth1/snort-1 --perfmon-file /nsm/sensor_data/SO-server-eth1/snort-1.stats -U --snaplen 1524
- 1.2 2.4 /usr/share/kibana/bin/../node/bin/node --no-warnings /usr/share/kibana/bin/../src/cli --cpu.cgroup.path.override=/ --cpuacct.cgroup.path.override=/ --kibana.defaultAppId=dashboard/94b52620-342a-11e7-9d52-4f090484f59e
- 1.0 1.1 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.8 0.2 barnyard2 -c /etc/nsm/SO-server-eth1/barnyard2-1.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-eth1/snort-1 -f snort.unified2 -w /etc/nsm/SO-server-eth1/barnyard2.waldo-1 -i SO-server-eth1-1 -U
- 0.8 0.0 /var/ossec/bin/ossec-syscheckd
- 0.7 0.0 [kswapd0]
- 0.4 0.0 /var/ossec/bin/ossec-analysisd
- 0.3 0.1 /usr/bin/python3 /usr/bin/update-manager
- 0.3 0.8 xfce4-terminal
- 0.2 1.0 /usr/bin/dockerd --raw-logs
- 0.2 0.7 python -m elastalert.elastalert --config /etc/elastalert/conf/elastalert_config.yaml --verbose
- 0.1 0.1 /sbin/init
- 0.1 0.3 docker-containerd --config /var/run/docker/containerd/containerd.toml
- 0.1 0.1 /usr/sbin/vmtoolsd
- 0.1 0.6 xfdesktop --display :0.0 --sm-client-id 2f62bb50b-ad07-48b7-ad16-9a6b84d818b4
- 0.1 0.2 /usr/lib/vmware-tools/sbin64/vmtoolsd -n vmusr --blockFd 3
- 0.1 2.2 netsniff-ng -i eth1 -o /nsm/sensor_data/SO-server-eth1/dailylogs/2018-04-12/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 64 iB --interval 150 iB -c
- 0.1 0.1 /usr/bin/python /opt/freq_server/freq/freq_server.py -ip X.X.X.X 10004 /opt/freq_server/freq/freq_table.freq
- 0.1 0.0 [kworker/0:2]
- 0.1 0.2 bash
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [ksoftirqd/0]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [rcu_sched]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [perf]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [writeback]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [khugepaged]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [kworker/0:1]
- 0.0 0.0 [vmstat]
- 0.0 0.0 [fsnotify_mark]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [deferwq]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [mpt_poll_0]
- 0.0 0.0 [mpt/0]
- 0.0 0.0 [kpsmoused]
- 0.0 0.0 [scsi_eh_2]
- 0.0 0.0 [scsi_tmf_2]
- 0.0 0.0 [bioset]
- 0.0 0.0 [ttm_swap]
- 0.0 0.0 [scsi_eh_3]
- 0.0 0.0 [scsi_tmf_3]
- 0.0 0.0 [scsi_eh_4]
- 0.0 0.0 [scsi_tmf_4]
- 0.0 0.0 [scsi_eh_5]
- 0.0 0.0 [scsi_tmf_5]
- 0.0 0.0 [scsi_eh_6]
- 0.0 0.0 [scsi_tmf_6]
- 0.0 0.0 [scsi_eh_7]
- 0.0 0.0 [scsi_tmf_7]
- 0.0 0.0 [scsi_eh_8]
- 0.0 0.0 [scsi_tmf_8]
- 0.0 0.0 [scsi_eh_9]
- 0.0 0.0 [scsi_tmf_9]
- 0.0 0.0 [scsi_eh_10]
- 0.0 0.0 [scsi_tmf_10]
- 0.0 0.0 [scsi_eh_11]
- 0.0 0.0 [scsi_tmf_11]
- 0.0 0.0 [scsi_eh_12]
- 0.0 0.0 [scsi_tmf_12]
- 0.0 0.0 [scsi_eh_13]
- 0.0 0.0 [scsi_tmf_13]
- 0.0 0.0 [scsi_eh_14]
- 0.0 0.0 [scsi_tmf_14]
- 0.0 0.0 [scsi_eh_15]
- 0.0 0.0 [scsi_tmf_15]
- 0.0 0.0 [scsi_eh_16]
- 0.0 0.0 [scsi_tmf_16]
- 0.0 0.0 [scsi_eh_17]
- 0.0 0.0 [scsi_tmf_17]
- 0.0 0.0 [scsi_eh_18]
- 0.0 0.0 [scsi_tmf_18]
- 0.0 0.0 [scsi_eh_19]
- 0.0 0.0 [scsi_tmf_19]
- 0.0 0.0 [scsi_eh_20]
- 0.0 0.0 [scsi_tmf_20]
- 0.0 0.0 [scsi_eh_21]
- 0.0 0.0 [scsi_tmf_21]
- 0.0 0.0 [scsi_eh_22]
- 0.0 0.0 [scsi_tmf_22]
- 0.0 0.0 [scsi_eh_23]
- 0.0 0.0 [scsi_tmf_23]
- 0.0 0.0 [scsi_eh_24]
- 0.0 0.0 [scsi_tmf_24]
- 0.0 0.0 [scsi_eh_25]
- 0.0 0.0 [scsi_tmf_25]
- 0.0 0.0 [scsi_eh_26]
- 0.0 0.0 [scsi_tmf_26]
- 0.0 0.0 [scsi_eh_27]
- 0.0 0.0 [scsi_tmf_27]
- 0.0 0.0 [scsi_eh_28]
- 0.0 0.0 [scsi_tmf_28]
- 0.0 0.0 [scsi_eh_29]
- 0.0 0.0 [scsi_tmf_29]
- 0.0 0.0 [scsi_eh_30]
- 0.0 0.0 [scsi_tmf_30]
- 0.0 0.0 [scsi_eh_31]
- 0.0 0.0 [scsi_tmf_31]
- 0.0 0.0 [scsi_eh_32]
- 0.0 0.0 [scsi_tmf_32]
- 0.0 0.0 [kworker/u256:29]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [jbd2/sda1-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 upstart-udev-bridge --daemon
- 0.0 0.0 /lib/systemd/systemd-udevd --daemon
- 0.0 0.0 dbus-daemon --system --fork
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.0 /usr/sbin/bluetoothd
- 0.0 0.0 avahi-daemon: running [SO-server.local]
- 0.0 0.0 avahi-daemon: chroot helper
- 0.0 0.0 [krfcommd]
- 0.0 0.0 upstart-file-bridge --daemon
- 0.0 0.0 [kmpathd]
- 0.0 0.0 [kmpath_handlerd]
- 0.0 0.0 upstart-socket-bridge --daemon
- 0.0 0.0 /sbin/getty -8 38400 tty4
- 0.0 0.0 /sbin/getty -8 38400 tty5
- 0.0 0.0 thermald --no-daemon --dbus-enable
- 0.0 0.0 /sbin/getty -8 38400 tty2
- 0.0 0.0 /sbin/getty -8 38400 tty3
- 0.0 0.0 /sbin/getty -8 38400 tty6
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.0 cron
- 0.0 0.0 acpid -c /etc/acpi/events -s /var/run/acpid.socket
- 0.0 0.0 [kauditd]
- 0.0 0.0 lightdm
- 0.0 0.0 /usr/sbin/cups-browsed
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.1 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.0 /usr/sbin/kerneloops
- 0.0 0.0 lightdm --session-child 12 15
- 0.0 0.0 init --user
- 0.0 0.0 /usr/sbin/vmware-vmblock-fuse -o subtype=vmware-vmblock,default_permissions,allow_other /var/run/vmblock-fuse
- 0.0 0.0 dbus-daemon --fork --session --address=unix:abstract=/tmp/dbus-q2zm7lfNju
- 0.0 0.0 upstart-event-bridge
- 0.0 0.0 upstart-dbus-bridge --daemon --session --user --bus-name session
- 0.0 0.0 upstart-dbus-bridge --daemon --system --user --bus-name system
- 0.0 0.0 upstart-file-bridge --daemon --user
- 0.0 0.0 gnome-keyring-daemon --start --components pkcs11,secrets
- 0.0 0.0 /usr/lib/vmware-vgauth/VGAuthService -s
- 0.0 0.1 //usr/lib/vmware-caf/pme/bin/ManagementAgentHost
- 0.0 0.0 /bin/sh /etc/xdg/xfce4/xinitrc -- /etc/X11/xinit/xserverrc
- 0.0 0.1 xfce4-session
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
- 0.0 0.0 /bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 /usr/bin/ssh-agent -s
- 0.0 0.2 xfwm4 --display :0.0 --sm-client-id 24dd69015-5e3f-4005-ba7a-fb57e5ccbb90
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/1000/gvfs -f -o big_writes
- 0.0 0.5 Thunar --sm-client-id 253c52dfb-ef45-42c2-aa36-1e94af7c0222 --daemon
- 0.0 0.3 xfce4-panel --display :0.0 --sm-client-id 26b4eea9e-73b4-45a4-ac23-6e332d0ab8df
- 0.0 0.0 /usr/lib/gvfs/gvfs-udisks2-volume-monitor
- 0.0 0.1 /usr/lib/udisks2/udisksd --no-debug
- 0.0 0.0 xfsettingsd --display :0.0 --sm-client-id 2ead7ddd1-8832-41d8-993e-0101578f463d
- 0.0 0.0 /usr/lib/upower/upowerd
- 0.0 0.5 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libwhiskermenu.so 1 12582944 whiskermenu Whisker Menu Show a menu to easily access installed applications
- 0.0 0.0 /usr/lib/gvfs/gvfs-mtp-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
- 0.0 0.1 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 4 12582945 systray Notification Area Area where notification icons appear
- 0.0 0.1 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libindicator-plugin.so 5 12582946 indicator Indicator Plugin Provides a panel area for Unity indicators. Indicators allow applications and system services to display their status and interact with the user.
- 0.0 0.0 /usr/lib/gvfs/gvfs-afc-volume-monitor
- 0.0 0.0 xfce4-power-manager --restart --sm-client-id 2d5f0ba76-76da-44c8-a375-eb5b73825023
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
- 0.0 0.1 xfce4-power-manager
- 0.0 0.0 light-locker
- 0.0 0.0 /usr/bin/python /usr/share/system-config-printer/applet.py
- 0.0 0.0 /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
- 0.0 0.1 xfce4-volumed
- 0.0 0.1 update-notifier
- 0.0 0.1 nm-applet
- 0.0 0.1 /usr/bin/python /usr/bin/blueman-applet
- 0.0 0.1 /usr/lib/gvfs/gvfsd-trash --spawner :1.12 /org/gtk/gvfs/exec_spaw/0
- 0.0 0.0 init --user --startup-event indicator-services-start
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
- 0.0 0.0 /usr/bin/pulseaudio --start --log-target=syslog
- 0.0 0.0 /usr/lib/rtkit/rtkit-daemon
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/gconf/gconfd-2
- 0.0 0.0 /usr/bin/obex-data-server --no-daemon
- 0.0 0.0 /usr/lib/dconf/dconf-service
- 0.0 0.0 /usr/sbin/cupsd -f
- 0.0 0.2 /usr/sbin/mysqld
- 0.0 0.0 su - SO-user -- /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.2 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.1 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-eth1/pcap_agent.conf
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.0 0.1 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-eth1/snort_agent-1.conf
- 0.0 0.0 docker-containerd-shim -namespace moby -workdir /var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/9f10032d2013c0217207be21bc1f05c239f210d4bf34e43e4e7f7cee6c03cf73 -address /var/run/docker/containerd/docker-containerd.sock -containerd-binary /usr/bin/docker-containerd -runtime-root /var/run/docker/runtime-runc
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9300 -container-ip X.X.X.X -container-port 9300
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9200 -container-ip X.X.X.X -container-port 9200
- 0.0 0.0 docker-containerd-shim -namespace moby -workdir /var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/0eaeea57cf6c07d34c3f46f989f4dfdabd62e8e3bb2cdbef7c527ea4f129a45b -address /var/run/docker/containerd/docker-containerd.sock -containerd-binary /usr/bin/docker-containerd -runtime-root /var/run/docker/runtime-runc
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-eth1/snort-1.stats
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 5601 -container-ip X.X.X.X -container-port 5601
- 0.0 0.0 docker-containerd-shim -namespace moby -workdir /var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/a5ad18aedd369a71c02c2c6a18ca5f59bb80f347b66f1f2cb35e08ec7594550d -address /var/run/docker/containerd/docker-containerd.sock -containerd-binary /usr/bin/docker-containerd -runtime-root /var/run/docker/runtime-runc
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 /sbin/getty -8 38400 tty1
- 0.0 0.0 docker-containerd-shim -namespace moby -workdir /var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/2b27abf540bde224175d693e5704903f5c3d9f6aa98df1f507f42d66fc5222af -address /var/run/docker/containerd/docker-containerd.sock -containerd-binary /usr/bin/docker-containerd -runtime-root /var/run/docker/runtime-runc
- 0.0 0.1 /usr/bin/python /usr/bin/supervisord -c /etc/elastalert/conf/elastalert_supervisord.conf -n
- 0.0 0.0 docker-containerd-shim -namespace moby -workdir /var/lib/docker/containerd/daemon/io.containerd.runtime.v1.linux/moby/2adb19d0a241e32e9cecd2d029311400b6634ae0a9617ace2f8351e22545acc5 -address /var/run/docker/containerd/docker-containerd.sock -containerd-binary /usr/bin/docker-containerd -runtime-root /var/run/docker/runtime-runc
- 0.0 0.0 /bin/bash
- 0.0 0.2 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 supervising syslog-ng
- 0.0 0.5 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- 0.0 0.0 /var/ossec/bin/ossec-csyslogd
- 0.0 0.0 /var/ossec/bin/ossec-execd
- 0.0 0.0 /var/ossec/bin/ossec-logcollector
- 0.0 0.0 /var/ossec/bin/ossec-monitord
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth1 -U .status -p broctl -p broctl-live -p standalone -p local -p bro local.bro broctl broctl/standalone broctl/auto
- 0.0 2.4 /opt/bro/bin/bro -i eth1 -U .status -p broctl -p broctl-live -p standalone -p local -p bro local.bro broctl broctl/standalone broctl/auto
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 [kworker/u256:0]
- 0.0 0.0 [kworker/0:0]
- 0.0 0.0 gnome-pty-helper
- 0.0 0.2 bash
- 0.0 0.2 bash
- 0.0 0.1 sudo wireshark
- 0.0 0.0 [cfg80211]
- 0.0 0.1 /usr/bin/dumpcap -n -i eth1 -y EN10MB -Z none
- 0.0 0.0 [kworker/u256:1]
- 0.0 0.1 sudo sostat-redacted
- 0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
- 0.0 0.0 /bin/bash /usr/sbin/sostat
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- eth1: 121958
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- eth1:
- RX packets:123050 dropped:0 TX packets:3 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- Appl. Name : <unknown>
- Tot Packets : 122132
- Tot Pkt Lost : 0
- Appl. Name : snort-cluster-52-socket-0
- Tot Packets : 122387
- Tot Pkt Lost : 21315
- -------------------------------------------------------------------------
- IDS Engine (snort) packet drops:
- ERROR: No stats found in /nsm/sensor_data/SO-server-eth1/snort-1.stats
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.000000
- bro: 1523543060.857155 recvd=122132 dropped=0 link=122132
- No capture loss reported.
- -------------------------------------------------------------------------
- Netsniff-NG:
- 0 Loss
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.6.0 (unknown)
- Total rings : 2
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Cluster Fragment Queue : 0
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/SO-server-eth0/dailylogs/ - 0 days
- 4.0K .
- /nsm/sensor_data/SO-server-eth1/dailylogs/ - 1 days
- 9.0M .
- 9.0M ./2018-04-12
- /nsm/bro/logs/ - 1 days
- 108K .
- 84K ./2018-04-12
- 20K ./stats
- =========================================================================
- Sguil Uncategorized Events
- =========================================================================
- COUNT(*)
- 85
- =========================================================================
- Sguil events summary for yesterday
- =========================================================================
- Total
- 0
- =========================================================================
- Top 50 All time Sguil Events
- =========================================================================
- Totals GenID:SigID Signature
- 51 1:2100366 GPL ICMP_INFO PING *NIX
- Total
- 51
- =========================================================================
- Last update
- =========================================================================
- Start-Date: 2018-04-12 14:56:11
- Commandline: aptdaemon role='role-commit-packages' sender=':1.83'
- Install: linux-image-extra-4.4.0-119-generic:amd64 (4.4.0-119.143~14.04.1), linux-image-4.4.0-119-generic:amd64 (4.4.0-119.143~14.04.1), linux-headers-4.4.0-119-generic:amd64 (4.4.0-119.143~14.04.1), linux-headers-4.4.0-119:amd64 (4.4.0-119.143~14.04.1)
- Upgrade: python-crypto:amd64 (2.6.1-4ubuntu0.2, 2.6.1-4ubuntu0.3), libruby1.9.1:amd64 (X.X.X.X-2ubuntu1.7, X.X.X.X-2ubuntu1.8), avahi-daemon:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), ubuntu-release-upgrader-gtk:amd64 (0.220.9, 0.220.10), libwayland-server0:amd64 (1.4.0-1ubuntu1, 1.4.0-1ubuntu1.1), securityonion-nsmnow-admin-scripts:amd64 (20120724-0ubuntu0securityonion165, 20120724-0ubuntu0securityonion166), linux-generic-lts-xenial:amd64 (X.X.X.X.98, X.X.X.X.100), libavahi-glib1:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), patch:amd64 (2.7.1-4ubuntu2.3, 2.7.1-4ubuntu2.4), libwayland-cursor0:amd64 (1.4.0-1ubuntu1, 1.4.0-1ubuntu1.1), linux-headers-generic-lts-xenial:amd64 (X.X.X.X.98, X.X.X.X.100), libavahi-common-data:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), libavahi-client3:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), libavahi-core7:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), libwayland-client0:amd64 (1.4.0-1ubuntu1, 1.4.0-1ubuntu1.1), libavahi-common3:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), python3-distupgrade:amd64 (0.220.9, 0.220.10), avahi-utils:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2), linux-image-generic-lts-xenial:amd64 (X.X.X.X.98, X.X.X.X.100), ruby1.9.1:amd64 (X.X.X.X-2ubuntu1.7, X.X.X.X-2ubuntu1.8), securityonion-networkminer:amd64 (20170828-1ubuntu1securityonion1, 20180410-1ubuntu1securityonion1), ubuntu-release-upgrader-core:amd64 (0.220.9, 0.220.10), linux-libc-dev:amd64 (3.13.0-143.192, 3.13.0-144.193), avahi-autoipd:amd64 (0.6.31-4ubuntu1.1, 0.6.31-4ubuntu1.2)
- End-Date: 2018-04-12 14:57:28
- =========================================================================
- Elasticsearch
- =========================================================================
- Elasticsearch is running.
- Cluster Name: "SO-server"
- Cluster Status: "green"
- Total Nodes: 1
- Failed Nodes: 0
- Total Indices: 6
- Total Shards: 26
- Total Documents: 532
- Total Size: 1MB
- Free Memory: 4%
- Total Number of Events: 532
- Avg. Event Size (In Bytes): 3730
- CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- 0eaeea57cf6c so-elasticsearch 0.30% 970.8MiB / 2.92GiB 32.46% 9.1MB / 2.22MB 73.8MB / 10MB 38
- =========================================================================
- Logstash
- =========================================================================
- Logstash is not running.
- Try starting it with:
- 'sudo so-elastic-start'
- OR
- 'sudo docker start so-logstash'
- If that does not work, try checking /var/log/logstash/logstash.log for clues.
- =========================================================================
- Kibana
- =========================================================================
- Kibana is running.
- CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- a5ad18aedd36 so-kibana 1.63% 64.75MiB / 2.92GiB 2.17% 9.76MB / 17.2MB 162MB / 53.2kB 10
- =========================================================================
- ElastAlert
- =========================================================================
- ElastAlert is running.
- CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- 2b27abf540bd so-elastalert 0.03% 20.45MiB / 2.92GiB 0.68% 100kB / 126kB 62.7MB / 16.4kB 2
- =========================================================================
- Curator
- =========================================================================
- Curator is running.
- CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- 2adb19d0a241 so-curator 0.00% 32KiB / 2.92GiB 0.00% 310kB / 47kB 74.6MB / 0B 1
- =========================================================================
- Freq Server
- =========================================================================
- Freq_server is running.
- CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- 9f10032d2013 so-freqserver 0.16% 1.098MiB / 2.92GiB 0.04% 24.4kB / 0B 13.7MB / 0B 2
- Testing freq_server now...
- Freq Server is working.
- =========================================================================
- Version Information
- =========================================================================
- Ubuntu 14.04.5 LTS
- securityonion-sostat 20120722-0ubuntu0securityonion95
Add Comment
Please, Sign In to add comment