Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- (standard_in) 1: syntax error
- (standard_in) 1: syntax error
- % Total % Received % Xferd Average Speed Time Time Time Current
- Dload Upload Total Spent Left Speed
- 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0
- 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0
- 100 13 0 13 0 0 6 0 --:--:-- 0:00:01 --:--:-- 6
- 100 13 0 13 0 0 6 0 --:--:-- 0:00:01 --:--:-- 6
- % Total % Received % Xferd Average Speed Time Time Time Current
- Dload Upload Total Spent Left Speed
- 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0
- 100 1 0 1 0 0 2 0 --:--:-- --:--:-- --:--:-- 2
- =========================================================================
- Service Status
- =========================================================================
- Status: securityonion
- * SO-user server[ OK ]
- Status: HIDS
- * ossec_agent (SO-user)[ OK ]
- Status: Bro
- Name Type Host Status Pid Started
- manager manager localhost running 3716 19 Sep 12:12:53
- proxy proxy localhost running 3901 19 Sep 12:12:55
- securityonion-eth5-1 worker localhost running 6040 19 Sep 12:12:57
- securityonion-eth5-2 worker localhost running 6063 19 Sep 12:12:57
- securityonion-eth5-3 worker localhost running 6079 19 Sep 12:12:57
- securityonion-eth5-4 worker localhost running 6096 19 Sep 12:12:57
- securityonion-eth5-5 worker localhost running 6080 19 Sep 12:12:57
- securityonion-eth5-6 worker localhost running 6108 19 Sep 12:12:57
- securityonion-eth5-7 worker localhost running 6112 19 Sep 12:12:57
- securityonion-eth5-8 worker localhost running 6134 19 Sep 12:12:57
- securityonion-eth5-9 worker localhost running 6124 19 Sep 12:12:57
- securityonion-eth5-10 worker localhost running 6141 19 Sep 12:12:57
- securityonion-eth5-11 worker localhost running 6138 19 Sep 12:12:57
- securityonion-eth5-12 worker localhost running 6140 19 Sep 12:12:57
- securityonion-eth5-13 worker localhost running 6151 19 Sep 12:12:57
- securityonion-eth5-14 worker localhost running 6152 19 Sep 12:12:57
- securityonion-eth5-15 worker localhost running 6153 19 Sep 12:12:57
- Status: securityonion-eth5
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (SO-user)[ OK ]
- * snort_agent-1 (SO-user)[ OK ]
- * snort_agent-2 (SO-user)[ OK ]
- * snort_agent-3 (SO-user)[ OK ]
- * snort_agent-4 (SO-user)[ OK ]
- * snort_agent-5 (SO-user)[ OK ]
- * snort_agent-6 (SO-user)[ OK ]
- * snort_agent-7 (SO-user)[ OK ]
- * snort_agent-8 (SO-user)[ OK ]
- * snort_agent-9 (SO-user)[ OK ]
- * snort_agent-10 (SO-user)[ OK ]
- * snort_agent-11 (SO-user)[ OK ]
- * snort_agent-12 (SO-user)[ OK ]
- * snort_agent-13 (SO-user)[ OK ]
- * snort_agent-14 (SO-user)[ OK ]
- * snort_agent-15 (SO-user)[ OK ]
- * snort-1 (alert data)[ OK ]
- * snort-2 (alert data)[ OK ]
- * snort-3 (alert data)[ OK ]
- * snort-4 (alert data)[ OK ]
- * snort-5 (alert data)[ OK ]
- * snort-6 (alert data)[ OK ]
- * snort-7 (alert data)[ OK ]
- * snort-8 (alert data)[ OK ]
- * snort-9 (alert data)[ OK ]
- * snort-10 (alert data)[ OK ]
- * snort-11 (alert data)[ OK ]
- * snort-12 (alert data)[ OK ]
- * snort-13 (alert data)[ OK ]
- * snort-14 (alert data)[ OK ]
- * snort-15 (alert data)[ OK ]
- * barnyard2-1 (spooler, unified2 format)[ OK ]
- * barnyard2-2 (spooler, unified2 format)[ OK ]
- * barnyard2-3 (spooler, unified2 format)[ OK ]
- * barnyard2-4 (spooler, unified2 format)[ OK ]
- * barnyard2-5 (spooler, unified2 format)[ OK ]
- * barnyard2-6 (spooler, unified2 format)[ OK ]
- * barnyard2-7 (spooler, unified2 format)[ OK ]
- * barnyard2-8 (spooler, unified2 format)[ OK ]
- * barnyard2-9 (spooler, unified2 format)[ OK ]
- * barnyard2-10 (spooler, unified2 format)[ OK ]
- * barnyard2-11 (spooler, unified2 format)[ OK ]
- * barnyard2-12 (spooler, unified2 format)[ OK ]
- * barnyard2-13 (spooler, unified2 format)[ OK ]
- * barnyard2-14 (spooler, unified2 format)[ OK ]
- * barnyard2-15 (spooler, unified2 format)[ OK ]
- * http_agent (SO-user)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:44904 errors:0 dropped:0 overruns:0 frame:0
- TX packets:46065 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:2677645 (2.6 MB) TX bytes:6658691 (6.6 MB)
- eth0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:81829 errors:0 dropped:0 overruns:0 frame:0
- TX packets:92603 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:6365355 (6.3 MB) TX bytes:34054024 (34.0 MB)
- Interrupt:26
- eth5 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:225922888 errors:0 dropped:0 overruns:102912 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:169288373994 (169.2 GB) TX bytes:0 (0.0 B)
- Memory:f77c0000-f77dffff
- lo Link encap:Local Loopback
- inet addr:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:1719581 errors:0 dropped:0 overruns:0 frame:0
- TX packets:1719581 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1
- RX bytes:1860154800 (1.8 GB) TX bytes:1860154800 (1.8 GB)
- veth27ff45f Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:1914 errors:0 dropped:0 overruns:0 frame:0
- TX packets:3028 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:132680 (132.6 KB) TX bytes:3503735 (3.5 MB)
- veth2cfc8f0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:34323 errors:0 dropped:0 overruns:0 frame:0
- TX packets:34370 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:2498046 (2.4 MB) TX bytes:2504196 (2.5 MB)
- veth6219cc9 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:84 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:11966 (11.9 KB)
- veth6df0aeb Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:167 errors:0 dropped:0 overruns:0 frame:0
- TX packets:249 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:28082 (28.0 KB) TX bytes:26106 (26.1 KB)
- veth7306f14 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:7212 errors:0 dropped:0 overruns:0 frame:0
- TX packets:7290 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:557685 (557.6 KB) TX bytes:554793 (554.7 KB)
- vethb6ace5d Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:73 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:10521 (10.5 KB)
- vethc0c0c6a Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:1288 errors:0 dropped:0 overruns:0 frame:0
- TX packets:1336 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:89808 (89.8 KB) TX bytes:96102 (96.1 KB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1
- link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1860154905 1719582 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 1860154905 1719582 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 6365355 81829 0 0 0 5595
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 34054024 92603 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 3: eth1: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 4: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 5: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 6: eth4: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 7: eth5: <BROADCAST,MULTICAST,NOARP,PROMISC,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 169288446250 225922985 0 0 0 5491
- RX errors: length crc frame fifo missed
- 0 0 0 102912 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 8: docker0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 2677645 44904 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 6658691 46065 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 10: veth6219cc9@if9: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 11966 84 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 12: vethb6ace5d@if11: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 10521 73 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 14: veth6df0aeb@if13: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 28082 167 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 26106 249 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 16: veth27ff45f@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 132680 1914 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 3503735 3028 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 18: veth7306f14@if17: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 557685 7212 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 554793 7290 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 20: veth2cfc8f0@if19: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 2498046 34323 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 2504196 34370 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- 22: vethc0c0c6a@if21: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master docker0 state UP mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 89808 1288 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 96102 1336 0 0 0 0
- TX errors: aborted fifo window heartbeat
- 0 0 0 0
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 16G 4,0K 16G 1% /dev
- tmpfs 3,2G 2,0M 3,2G 1% /run
- /dev/sda1 244G 8,3G 223G 4% /
- none 4,0K 0 4,0K 0% /sys/fs/cgroup
- none 5,0M 0 5,0M 0% /run/lock
- none 16G 2,5M 16G 1% /run/shm
- none 100M 28K 100M 1% /run/user
- /dev/sdb 2,2T 246G 1,8T 12% /nsm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/a5d99d64894bd6c04d3d744d3ec4a76039085d9b1afc3c8852703252745842cb
- shm 64M 0 64M 0% /var/lib/docker/containers/949e6698dea7ba79f467f5b19f3a2660937c4604c021a45525fba74af0604021/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/dc0e4bb8e8929843ba1d7f249267c5c2f94bb040324474d5efac6608c8369902
- shm 64M 0 64M 0% /var/lib/docker/containers/609c9bcb5a9a0e635472627377480418fae6ce97437ea5371bcd7404607c1f66/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/f581ead38d71d98fba4a83002956239bbab8599af786d38c3ea2aacee23dde65
- shm 64M 0 64M 0% /var/lib/docker/containers/81abd74f44d8245556d59793e662931953a6579264cbb751cc3d55e685d08866/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/c95dc676103fb7c6436da8ca6bd209f26238130eec2558124d09ee0c0317d27b
- shm 64M 0 64M 0% /var/lib/docker/containers/123d773694200c1b0da1662345a5b349b0487a6cee748f76b595d6ae9f8e4977/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/d9c845e6a840423e926252d948b6bcad4a5ba3c3ce7c8541dde1ff33a13ec7c2
- shm 64M 0 64M 0% /var/lib/docker/containers/f62e3a514bd009178f948dec9feb6c1cc7c14f41d4e2c23b456dbb747511a40e/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/97c2515ba8541b2bd09a5d0e09ebff27312d97de3cc1914f840d91d241dd40f7
- shm 64M 0 64M 0% /var/lib/docker/containers/e48987198190f16eb9299363bf6ba87381994a200006de215b582bd26e7f8a3a/shm
- none 244G 8,3G 223G 4% /var/lib/docker/aufs/mnt/c6fed1ca13d844d332913f45fcfe1956ef52a28e8c9517117dcd42495b3cb343
- shm 64M 0 64M 0% /var/lib/docker/containers/310badede7252463b052496e32ce744d54ed89982b3e7d62a51829fcf1b75b2c/shm
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- avahi-dae 1036 avahi 12u IPv4 38950 0t0 UDP *:5353
- avahi-dae 1036 avahi 13u IPv6 38951 0t0 UDP *:5353
- avahi-dae 1036 avahi 14u IPv4 38952 0t0 UDP *:36150
- avahi-dae 1036 avahi 15u IPv6 38953 0t0 UDP *:38927
- sshd 1911 root 3u IPv4 27751 0t0 TCP *:ssh_port (LISTEN)
- sshd 1911 root 4u IPv6 27753 0t0 TCP *:ssh_port (LISTEN)
- cups-brow 1972 root 6u IPv6 9765 0t0 TCP [X.X.X.X]:43372->[X.X.X.X]:631 (CLOSE_WAIT)
- cups-brow 1972 root 8u IPv4 9767 0t0 UDP *:631
- syslog-ng 2021 root 9u IPv4 32872 0t0 TCP *:514 (LISTEN)
- syslog-ng 2021 root 10u IPv4 32873 0t0 UDP *:514
- syslog-ng 2021 root 38u IPv4 52976 0t0 TCP X.X.X.X:43179->X.X.X.X:6050 (ESTABLISHED)
- mysqld 2067 mysql 10u IPv4 42124 0t0 TCP X.X.X.X:3306 (LISTEN)
- ossec-csy 2110 ossecm 5u IPv4 16562 0t0 UDP X.X.X.X:47552->X.X.X.X:514
- ossec-rem 2133 ossecr 4u IPv4 24689 0t0 UDP *:1514
- salt-mast 2168 root 12u IPv4 11451 0t0 TCP *:4505 (LISTEN)
- salt-mast 2188 root 20u IPv4 30764 0t0 TCP *:4506 (LISTEN)
- ntpd 3114 ntp 16u IPv4 17639 0t0 UDP *:123
- ntpd 3114 ntp 17u IPv6 17640 0t0 UDP *:123
- ntpd 3114 ntp 18u IPv4 17646 0t0 UDP X.X.X.X:123
- ntpd 3114 ntp 19u IPv4 17647 0t0 UDP X.X.X.X:123
- ntpd 3114 ntp 20u IPv4 17648 0t0 UDP X.X.X.X:123
- ntpd 3114 ntp 21u IPv6 17649 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 22u IPv6 17650 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 24u IPv6 26944 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 25u IPv6 26945 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 26u IPv6 26946 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 27u IPv6 26947 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 28u IPv6 38351 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 29u IPv6 47177 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 30u IPv6 47178 0t0 UDP [X.X.X.X]:123
- ntpd 3114 ntp 31u IPv6 47179 0t0 UDP [X.X.X.X]:123
- apache2 3167 root 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3167 root 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3172 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3172 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3172 www-data 21u IPv4 180491 0t0 TCP X.X.X.X:39654->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3172 www-data 22u IPv4 168427 0t0 TCP X.X.X.X:39690->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3172 www-data 23u IPv4 184844 0t0 TCP X.X.X.X:39716->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3173 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3173 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3174 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3174 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3174 www-data 21u IPv4 179427 0t0 TCP X.X.X.X:39700->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3174 www-data 22u IPv4 179425 0t0 TCP X.X.X.X:39666->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3175 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3175 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3175 www-data 21u IPv4 168421 0t0 TCP X.X.X.X:39656->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3175 www-data 22u IPv4 181927 0t0 TCP X.X.X.X:39672->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3175 www-data 23u IPv4 190771 0t0 TCP X.X.X.X:39696->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3295 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 3295 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 3295 www-data 21u IPv4 36688 0t0 TCP X.X.X.X:38732->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 3295 www-data 22u IPv4 167913 0t0 TCP X.X.X.X:39642->X.X.X.X:5601 (CLOSE_WAIT)
- cupsd 3307 root 10u IPv6 20589 0t0 TCP [X.X.X.X]:631 (LISTEN)
- cupsd 3307 root 11u IPv4 20590 0t0 TCP X.X.X.X:631 (LISTEN)
- tclsh 3392 SO-user 13u IPv4 9775 0t0 TCP *:7734 (LISTEN)
- tclsh 3392 SO-user 14u IPv6 9776 0t0 TCP *:7734 (LISTEN)
- tclsh 3392 SO-user 15u IPv4 9779 0t0 TCP *:7736 (LISTEN)
- tclsh 3392 SO-user 16u IPv6 9780 0t0 TCP *:7736 (LISTEN)
- tclsh 3392 SO-user 17u IPv4 9951 0t0 TCP X.X.X.X:7736->X.X.X.X:39823 (ESTABLISHED)
- tclsh 3392 SO-user 18u IPv4 10742 0t0 TCP X.X.X.X:7736->X.X.X.X:46106 (ESTABLISHED)
- tclsh 3392 SO-user 19u IPv4 38211 0t0 TCP X.X.X.X:7736->X.X.X.X:45720 (ESTABLISHED)
- tclsh 3392 SO-user 20u IPv4 33149 0t0 TCP X.X.X.X:7736->X.X.X.X:43160 (ESTABLISHED)
- tclsh 3392 SO-user 21u IPv4 11759 0t0 TCP X.X.X.X:7736->X.X.X.X:37382 (ESTABLISHED)
- tclsh 3392 SO-user 22u IPv4 11760 0t0 TCP X.X.X.X:7736->X.X.X.X:41150 (ESTABLISHED)
- tclsh 3392 SO-user 23u IPv4 28391 0t0 TCP X.X.X.X:7736->X.X.X.X:45280 (ESTABLISHED)
- tclsh 3392 SO-user 24u IPv4 28392 0t0 TCP X.X.X.X:7736->X.X.X.X:46280 (ESTABLISHED)
- tclsh 3392 SO-user 25u IPv4 28393 0t0 TCP X.X.X.X:7736->X.X.X.X:46360 (ESTABLISHED)
- tclsh 3392 SO-user 26u IPv4 22086 0t0 TCP X.X.X.X:7736->X.X.X.X:39275 (ESTABLISHED)
- tclsh 3392 SO-user 27u IPv4 16803 0t0 TCP X.X.X.X:7736->X.X.X.X:32891 (ESTABLISHED)
- tclsh 3392 SO-user 28u IPv4 22087 0t0 TCP X.X.X.X:7736->X.X.X.X:38317 (ESTABLISHED)
- tclsh 3392 SO-user 29u IPv4 37170 0t0 TCP X.X.X.X:7736->X.X.X.X:42149 (ESTABLISHED)
- tclsh 3392 SO-user 30u IPv4 22924 0t0 TCP X.X.X.X:7736->X.X.X.X:40310 (ESTABLISHED)
- tclsh 3392 SO-user 31u IPv4 22925 0t0 TCP X.X.X.X:7736->X.X.X.X:45052 (ESTABLISHED)
- tclsh 3392 SO-user 32u IPv4 22926 0t0 TCP X.X.X.X:7736->X.X.X.X:39369 (ESTABLISHED)
- tclsh 3392 SO-user 33u IPv4 22947 0t0 TCP X.X.X.X:7736->X.X.X.X:32964 (ESTABLISHED)
- tclsh 3392 SO-user 34u IPv4 14752 0t0 TCP X.X.X.X:7736->X.X.X.X:33396 (ESTABLISHED)
- tclsh 3392 SO-user 35u IPv4 51931 0t0 TCP X.X.X.X:7734->X.X.X.X:64828 (ESTABLISHED)
- tclsh 3439 SO-user 3u IPv4 12871 0t0 TCP X.X.X.X:39823->X.X.X.X:7736 (ESTABLISHED)
- bro 3716 SO-user 4u IPv4 14531 0t0 UDP X.X.X.X:57464->X.X.X.X:53
- bro 3718 SO-user 0u IPv4 16675 0t0 TCP *:47761 (LISTEN)
- bro 3718 SO-user 1u IPv6 16676 0t0 TCP *:47761 (LISTEN)
- bro 3718 SO-user 2u IPv4 16714 0t0 TCP X.X.X.X:47761->X.X.X.X:60394 (ESTABLISHED)
- bro 3718 SO-user 4u IPv4 14531 0t0 UDP X.X.X.X:57464->X.X.X.X:53
- bro 3718 SO-user 14u IPv4 9905 0t0 TCP X.X.X.X:47761->X.X.X.X:60398 (ESTABLISHED)
- bro 3718 SO-user 19u IPv4 33939 0t0 TCP X.X.X.X:47761->X.X.X.X:60400 (ESTABLISHED)
- bro 3718 SO-user 24u IPv4 33942 0t0 TCP X.X.X.X:47761->X.X.X.X:60404 (ESTABLISHED)
- bro 3718 SO-user 29u IPv4 33945 0t0 TCP X.X.X.X:47761->X.X.X.X:60408 (ESTABLISHED)
- bro 3718 SO-user 34u IPv4 33948 0t0 TCP X.X.X.X:47761->X.X.X.X:60412 (ESTABLISHED)
- bro 3718 SO-user 39u IPv4 33951 0t0 TCP X.X.X.X:47761->X.X.X.X:60416 (ESTABLISHED)
- bro 3718 SO-user 44u IPv4 33954 0t0 TCP X.X.X.X:47761->X.X.X.X:60422 (ESTABLISHED)
- bro 3718 SO-user 49u IPv4 33957 0t0 TCP X.X.X.X:47761->X.X.X.X:60424 (ESTABLISHED)
- bro 3718 SO-user 54u IPv4 33960 0t0 TCP X.X.X.X:47761->X.X.X.X:60428 (ESTABLISHED)
- bro 3718 SO-user 59u IPv4 33963 0t0 TCP X.X.X.X:47761->X.X.X.X:60432 (ESTABLISHED)
- bro 3718 SO-user 64u IPv4 33966 0t0 TCP X.X.X.X:47761->X.X.X.X:60436 (ESTABLISHED)
- bro 3718 SO-user 69u IPv4 33969 0t0 TCP X.X.X.X:47761->X.X.X.X:60442 (ESTABLISHED)
- bro 3718 SO-user 74u IPv4 33972 0t0 TCP X.X.X.X:47761->X.X.X.X:60446 (ESTABLISHED)
- bro 3718 SO-user 79u IPv4 33975 0t0 TCP X.X.X.X:47761->X.X.X.X:60448 (ESTABLISHED)
- bro 3718 SO-user 84u IPv4 28096 0t0 TCP X.X.X.X:47761->X.X.X.X:60452 (ESTABLISHED)
- bro 3901 SO-user 4u IPv4 27995 0t0 UDP X.X.X.X:48232->X.X.X.X:53
- bro 3903 SO-user 0u IPv4 33055 0t0 TCP X.X.X.X:60394->X.X.X.X:47761 (ESTABLISHED)
- bro 3903 SO-user 4u IPv4 27995 0t0 UDP X.X.X.X:48232->X.X.X.X:53
- bro 3903 SO-user 12u IPv4 33060 0t0 TCP *:47762 (LISTEN)
- bro 3903 SO-user 13u IPv6 33061 0t0 TCP *:47762 (LISTEN)
- bro 3903 SO-user 14u IPv4 28961 0t0 TCP X.X.X.X:47762->X.X.X.X:47226 (ESTABLISHED)
- bro 3903 SO-user 19u IPv4 28964 0t0 TCP X.X.X.X:47762->X.X.X.X:47232 (ESTABLISHED)
- bro 3903 SO-user 24u IPv4 28967 0t0 TCP X.X.X.X:47762->X.X.X.X:47236 (ESTABLISHED)
- bro 3903 SO-user 29u IPv4 28970 0t0 TCP X.X.X.X:47762->X.X.X.X:47240 (ESTABLISHED)
- bro 3903 SO-user 34u IPv4 28973 0t0 TCP X.X.X.X:47762->X.X.X.X:47244 (ESTABLISHED)
- bro 3903 SO-user 39u IPv4 28976 0t0 TCP X.X.X.X:47762->X.X.X.X:47248 (ESTABLISHED)
- bro 3903 SO-user 44u IPv4 28072 0t0 TCP X.X.X.X:47762->X.X.X.X:47250 (ESTABLISHED)
- bro 3903 SO-user 49u IPv4 28075 0t0 TCP X.X.X.X:47762->X.X.X.X:47256 (ESTABLISHED)
- bro 3903 SO-user 54u IPv4 28078 0t0 TCP X.X.X.X:47762->X.X.X.X:47260 (ESTABLISHED)
- bro 3903 SO-user 59u IPv4 28081 0t0 TCP X.X.X.X:47762->X.X.X.X:47264 (ESTABLISHED)
- bro 3903 SO-user 64u IPv4 28084 0t0 TCP X.X.X.X:47762->X.X.X.X:47268 (ESTABLISHED)
- bro 3903 SO-user 69u IPv4 28087 0t0 TCP X.X.X.X:47762->X.X.X.X:47270 (ESTABLISHED)
- bro 3903 SO-user 74u IPv4 28090 0t0 TCP X.X.X.X:47762->X.X.X.X:47274 (ESTABLISHED)
- bro 3903 SO-user 79u IPv4 28093 0t0 TCP X.X.X.X:47762->X.X.X.X:47280 (ESTABLISHED)
- bro 3903 SO-user 84u IPv4 28099 0t0 TCP X.X.X.X:47762->X.X.X.X:47284 (ESTABLISHED)
- bro 6040 SO-user 4u IPv4 34993 0t0 UDP X.X.X.X:60272->X.X.X.X:53
- bro 6063 SO-user 4u IPv4 30928 0t0 UDP X.X.X.X:60905->X.X.X.X:53
- bro 6079 SO-user 4u IPv4 19874 0t0 UDP X.X.X.X:58147->X.X.X.X:53
- bro 6080 SO-user 4u IPv4 33118 0t0 UDP X.X.X.X:37315->X.X.X.X:53
- bro 6096 SO-user 4u IPv4 39053 0t0 UDP X.X.X.X:41588->X.X.X.X:53
- bro 6108 SO-user 4u IPv4 20651 0t0 UDP X.X.X.X:39657->X.X.X.X:53
- bro 6112 SO-user 4u IPv4 42207 0t0 UDP X.X.X.X:43426->X.X.X.X:53
- bro 6124 SO-user 4u IPv4 22844 0t0 UDP X.X.X.X:53553->X.X.X.X:53
- bro 6134 SO-user 4u IPv4 37078 0t0 UDP X.X.X.X:47527->X.X.X.X:53
- bro 6138 SO-user 4u IPv4 26796 0t0 UDP X.X.X.X:58973->X.X.X.X:53
- bro 6140 SO-user 4u IPv4 21886 0t0 UDP X.X.X.X:56607->X.X.X.X:53
- bro 6141 SO-user 4u IPv4 26227 0t0 UDP X.X.X.X:33445->X.X.X.X:53
- bro 6151 SO-user 4u IPv4 14679 0t0 UDP X.X.X.X:45648->X.X.X.X:53
- bro 6152 SO-user 4u IPv4 11674 0t0 UDP X.X.X.X:51781->X.X.X.X:53
- bro 6153 SO-user 4u IPv4 9902 0t0 UDP X.X.X.X:45577->X.X.X.X:53
- bro 6154 SO-user 0u IPv4 12832 0t0 TCP X.X.X.X:47226->X.X.X.X:47762 (ESTABLISHED)
- bro 6154 SO-user 4u IPv4 14679 0t0 UDP X.X.X.X:45648->X.X.X.X:53
- bro 6154 SO-user 12u IPv4 12835 0t0 TCP X.X.X.X:60398->X.X.X.X:47761 (ESTABLISHED)
- bro 6154 SO-user 17u IPv4 12840 0t0 TCP *:47775 (LISTEN)
- bro 6154 SO-user 18u IPv6 12841 0t0 TCP *:47775 (LISTEN)
- bro 6155 SO-user 0u IPv4 37093 0t0 TCP X.X.X.X:60404->X.X.X.X:47761 (ESTABLISHED)
- bro 6155 SO-user 4u IPv4 37078 0t0 UDP X.X.X.X:47527->X.X.X.X:53
- bro 6155 SO-user 12u IPv4 37096 0t0 TCP X.X.X.X:47236->X.X.X.X:47762 (ESTABLISHED)
- bro 6155 SO-user 17u IPv4 37101 0t0 TCP *:47770 (LISTEN)
- bro 6155 SO-user 18u IPv6 37102 0t0 TCP *:47770 (LISTEN)
- bro 6156 SO-user 0u IPv4 37083 0t0 TCP X.X.X.X:60400->X.X.X.X:47761 (ESTABLISHED)
- bro 6156 SO-user 4u IPv4 9902 0t0 UDP X.X.X.X:45577->X.X.X.X:53
- bro 6156 SO-user 12u IPv4 37086 0t0 TCP X.X.X.X:47232->X.X.X.X:47762 (ESTABLISHED)
- bro 6156 SO-user 17u IPv4 37091 0t0 TCP *:47777 (LISTEN)
- bro 6156 SO-user 18u IPv6 37092 0t0 TCP *:47777 (LISTEN)
- bro 6157 SO-user 0u IPv4 37103 0t0 TCP X.X.X.X:60412->X.X.X.X:47761 (ESTABLISHED)
- bro 6157 SO-user 4u IPv4 33118 0t0 UDP X.X.X.X:37315->X.X.X.X:53
- bro 6157 SO-user 12u IPv4 37106 0t0 TCP X.X.X.X:47244->X.X.X.X:47762 (ESTABLISHED)
- bro 6157 SO-user 17u IPv4 37111 0t0 TCP *:47767 (LISTEN)
- bro 6157 SO-user 18u IPv6 37112 0t0 TCP *:47767 (LISTEN)
- bro 6160 SO-user 0u IPv4 38179 0t0 TCP X.X.X.X:60408->X.X.X.X:47761 (ESTABLISHED)
- bro 6160 SO-user 4u IPv4 22844 0t0 UDP X.X.X.X:53553->X.X.X.X:53
- bro 6160 SO-user 12u IPv4 38182 0t0 TCP X.X.X.X:47240->X.X.X.X:47762 (ESTABLISHED)
- bro 6160 SO-user 17u IPv4 38187 0t0 TCP *:47771 (LISTEN)
- bro 6160 SO-user 18u IPv6 38188 0t0 TCP *:47771 (LISTEN)
- bro 6162 SO-user 0u IPv4 37113 0t0 TCP X.X.X.X:60416->X.X.X.X:47761 (ESTABLISHED)
- bro 6162 SO-user 4u IPv4 30928 0t0 UDP X.X.X.X:60905->X.X.X.X:53
- bro 6162 SO-user 12u IPv4 37116 0t0 TCP X.X.X.X:47248->X.X.X.X:47762 (ESTABLISHED)
- bro 6162 SO-user 17u IPv4 37121 0t0 TCP *:47764 (LISTEN)
- bro 6162 SO-user 18u IPv6 37122 0t0 TCP *:47764 (LISTEN)
- bro 6163 SO-user 0u IPv4 37123 0t0 TCP X.X.X.X:60428->X.X.X.X:47761 (ESTABLISHED)
- bro 6163 SO-user 4u IPv4 34993 0t0 UDP X.X.X.X:60272->X.X.X.X:53
- bro 6163 SO-user 12u IPv4 37126 0t0 TCP X.X.X.X:47260->X.X.X.X:47762 (ESTABLISHED)
- bro 6163 SO-user 17u IPv4 37131 0t0 TCP *:47763 (LISTEN)
- bro 6163 SO-user 18u IPv6 37132 0t0 TCP *:47763 (LISTEN)
- bro 6168 SO-user 0u IPv4 12842 0t0 TCP X.X.X.X:47250->X.X.X.X:47762 (ESTABLISHED)
- bro 6168 SO-user 4u IPv4 39053 0t0 UDP X.X.X.X:41588->X.X.X.X:53
- bro 6168 SO-user 12u IPv4 12845 0t0 TCP X.X.X.X:60422->X.X.X.X:47761 (ESTABLISHED)
- bro 6168 SO-user 17u IPv4 12850 0t0 TCP *:47766 (LISTEN)
- bro 6168 SO-user 18u IPv6 12851 0t0 TCP *:47766 (LISTEN)
- bro 6173 SO-user 0u IPv4 40541 0t0 TCP X.X.X.X:60424->X.X.X.X:47761 (ESTABLISHED)
- bro 6173 SO-user 4u IPv4 11674 0t0 UDP X.X.X.X:51781->X.X.X.X:53
- bro 6173 SO-user 12u IPv4 40544 0t0 TCP X.X.X.X:47256->X.X.X.X:47762 (ESTABLISHED)
- bro 6173 SO-user 17u IPv4 40549 0t0 TCP *:47776 (LISTEN)
- bro 6173 SO-user 18u IPv6 40550 0t0 TCP *:47776 (LISTEN)
- bro 6175 SO-user 0u IPv4 37133 0t0 TCP X.X.X.X:60436->X.X.X.X:47761 (ESTABLISHED)
- bro 6175 SO-user 4u IPv4 26227 0t0 UDP X.X.X.X:33445->X.X.X.X:53
- bro 6175 SO-user 12u IPv4 37136 0t0 TCP X.X.X.X:47268->X.X.X.X:47762 (ESTABLISHED)
- bro 6175 SO-user 17u IPv4 37141 0t0 TCP *:47772 (LISTEN)
- bro 6175 SO-user 18u IPv6 37142 0t0 TCP *:47772 (LISTEN)
- bro 6176 SO-user 0u IPv4 38189 0t0 TCP X.X.X.X:60432->X.X.X.X:47761 (ESTABLISHED)
- bro 6176 SO-user 4u IPv4 26796 0t0 UDP X.X.X.X:58973->X.X.X.X:53
- bro 6176 SO-user 12u IPv4 38192 0t0 TCP X.X.X.X:47264->X.X.X.X:47762 (ESTABLISHED)
- bro 6176 SO-user 17u IPv4 38197 0t0 TCP *:47773 (LISTEN)
- bro 6176 SO-user 18u IPv6 38198 0t0 TCP *:47773 (LISTEN)
- bro 6179 SO-user 0u IPv4 42216 0t0 TCP X.X.X.X:47270->X.X.X.X:47762 (ESTABLISHED)
- bro 6179 SO-user 4u IPv4 20651 0t0 UDP X.X.X.X:39657->X.X.X.X:53
- bro 6179 SO-user 12u IPv4 42219 0t0 TCP X.X.X.X:60442->X.X.X.X:47761 (ESTABLISHED)
- bro 6179 SO-user 17u IPv4 42224 0t0 TCP *:47768 (LISTEN)
- bro 6179 SO-user 18u IPv6 42225 0t0 TCP *:47768 (LISTEN)
- bro 6183 SO-user 0u IPv4 14690 0t0 TCP X.X.X.X:47274->X.X.X.X:47762 (ESTABLISHED)
- bro 6183 SO-user 4u IPv4 42207 0t0 UDP X.X.X.X:43426->X.X.X.X:53
- bro 6183 SO-user 12u IPv4 14693 0t0 TCP X.X.X.X:60446->X.X.X.X:47761 (ESTABLISHED)
- bro 6183 SO-user 17u IPv4 14698 0t0 TCP *:47769 (LISTEN)
- bro 6183 SO-user 18u IPv6 14699 0t0 TCP *:47769 (LISTEN)
- bro 6185 SO-user 0u IPv4 12852 0t0 TCP X.X.X.X:60448->X.X.X.X:47761 (ESTABLISHED)
- bro 6185 SO-user 4u IPv4 19874 0t0 UDP X.X.X.X:58147->X.X.X.X:53
- bro 6185 SO-user 12u IPv4 12855 0t0 TCP X.X.X.X:47280->X.X.X.X:47762 (ESTABLISHED)
- bro 6185 SO-user 17u IPv4 12860 0t0 TCP *:47765 (LISTEN)
- bro 6185 SO-user 18u IPv6 12861 0t0 TCP *:47765 (LISTEN)
- bro 6196 SO-user 0u IPv4 10714 0t0 TCP X.X.X.X:60452->X.X.X.X:47761 (ESTABLISHED)
- bro 6196 SO-user 4u IPv4 21886 0t0 UDP X.X.X.X:56607->X.X.X.X:53
- bro 6196 SO-user 12u IPv4 10717 0t0 TCP X.X.X.X:47284->X.X.X.X:47762 (ESTABLISHED)
- bro 6196 SO-user 17u IPv4 10722 0t0 TCP *:47774 (LISTEN)
- bro 6196 SO-user 18u IPv6 10723 0t0 TCP *:47774 (LISTEN)
- tclsh 6467 SO-user 3u IPv4 29880 0t0 TCP X.X.X.X:46106->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6486 SO-user 3u IPv4 29890 0t0 TCP X.X.X.X:45720->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6486 SO-user 4u IPv4 29891 0t0 TCP X.X.X.X:8501 (LISTEN)
- tclsh 6486 SO-user 6u IPv4 36156 0t0 TCP X.X.X.X:8501->X.X.X.X:38310 (ESTABLISHED)
- tclsh 6504 SO-user 3u IPv4 13545 0t0 TCP X.X.X.X:43160->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6504 SO-user 4u IPv4 14730 0t0 TCP X.X.X.X:8502 (LISTEN)
- tclsh 6504 SO-user 6u IPv4 18773 0t0 TCP X.X.X.X:8502->X.X.X.X:55532 (ESTABLISHED)
- tclsh 6526 SO-user 3u IPv4 17797 0t0 TCP X.X.X.X:37382->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6526 SO-user 4u IPv4 17798 0t0 TCP X.X.X.X:8503 (LISTEN)
- tclsh 6526 SO-user 6u IPv4 12008 0t0 TCP X.X.X.X:8503->X.X.X.X:46260 (ESTABLISHED)
- tclsh 6544 SO-user 3u IPv4 23811 0t0 TCP X.X.X.X:41150->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6544 SO-user 4u IPv4 23812 0t0 TCP X.X.X.X:8504 (LISTEN)
- tclsh 6544 SO-user 6u IPv4 12009 0t0 TCP X.X.X.X:8504->X.X.X.X:44900 (ESTABLISHED)
- tclsh 6563 SO-user 3u IPv4 34026 0t0 TCP X.X.X.X:45280->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6563 SO-user 4u IPv4 34027 0t0 TCP X.X.X.X:8505 (LISTEN)
- tclsh 6563 SO-user 6u IPv4 28414 0t0 TCP X.X.X.X:8505->X.X.X.X:37604 (ESTABLISHED)
- tclsh 6583 SO-user 3u IPv4 34036 0t0 TCP X.X.X.X:46280->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6583 SO-user 4u IPv4 34037 0t0 TCP X.X.X.X:8506 (LISTEN)
- tclsh 6583 SO-user 6u IPv4 12007 0t0 TCP X.X.X.X:8506->X.X.X.X:39944 (ESTABLISHED)
- tclsh 6601 SO-user 3u IPv4 35013 0t0 TCP X.X.X.X:46360->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6601 SO-user 4u IPv4 35014 0t0 TCP X.X.X.X:8507 (LISTEN)
- tclsh 6601 SO-user 6u IPv4 37421 0t0 TCP X.X.X.X:8507->X.X.X.X:52402 (ESTABLISHED)
- tclsh 6619 SO-user 3u IPv4 20715 0t0 TCP X.X.X.X:39275->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6619 SO-user 4u IPv4 26414 0t0 TCP X.X.X.X:8508 (LISTEN)
- tclsh 6619 SO-user 6u IPv4 12005 0t0 TCP X.X.X.X:8508->X.X.X.X:39172 (ESTABLISHED)
- tclsh 6637 SO-user 3u IPv4 36111 0t0 TCP X.X.X.X:32891->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6637 SO-user 4u IPv4 36112 0t0 TCP X.X.X.X:8509 (LISTEN)
- tclsh 6637 SO-user 6u IPv4 33338 0t0 TCP X.X.X.X:8509->X.X.X.X:48876 (ESTABLISHED)
- tclsh 6655 SO-user 3u IPv4 32242 0t0 TCP X.X.X.X:38317->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6655 SO-user 4u IPv4 13065 0t0 TCP X.X.X.X:8510 (LISTEN)
- tclsh 6655 SO-user 6u IPv4 20899 0t0 TCP X.X.X.X:8510->X.X.X.X:48382 (ESTABLISHED)
- tclsh 6674 SO-user 3u IPv4 16810 0t0 TCP X.X.X.X:42149->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6674 SO-user 4u IPv4 16811 0t0 TCP X.X.X.X:8511 (LISTEN)
- tclsh 6674 SO-user 6u IPv4 18044 0t0 TCP X.X.X.X:8511->X.X.X.X:45624 (ESTABLISHED)
- tclsh 6692 SO-user 3u IPv4 24942 0t0 TCP X.X.X.X:40310->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6692 SO-user 4u IPv4 24943 0t0 TCP X.X.X.X:8512 (LISTEN)
- tclsh 6692 SO-user 6u IPv4 25034 0t0 TCP X.X.X.X:8512->X.X.X.X:39450 (ESTABLISHED)
- tclsh 6711 SO-user 3u IPv4 35057 0t0 TCP X.X.X.X:45052->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6711 SO-user 4u IPv4 35058 0t0 TCP X.X.X.X:8513 (LISTEN)
- tclsh 6711 SO-user 6u IPv4 37420 0t0 TCP X.X.X.X:8513->X.X.X.X:51996 (ESTABLISHED)
- tclsh 6729 SO-user 3u IPv4 28401 0t0 TCP X.X.X.X:39369->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6729 SO-user 4u IPv4 28402 0t0 TCP X.X.X.X:8514 (LISTEN)
- tclsh 6729 SO-user 6u IPv4 32362 0t0 TCP X.X.X.X:8514->X.X.X.X:56428 (ESTABLISHED)
- tclsh 6750 SO-user 3u IPv4 16835 0t0 TCP X.X.X.X:32964->X.X.X.X:7736 (ESTABLISHED)
- tclsh 6750 SO-user 4u IPv4 16836 0t0 TCP X.X.X.X:8515 (LISTEN)
- tclsh 6750 SO-user 6u IPv4 16933 0t0 TCP X.X.X.X:8515->X.X.X.X:40458 (ESTABLISHED)
- barnyard2 7017 SO-user 3u IPv4 36155 0t0 TCP X.X.X.X:38310->X.X.X.X:8501 (ESTABLISHED)
- barnyard2 7034 SO-user 3u IPv4 33278 0t0 TCP X.X.X.X:55532->X.X.X.X:8502 (ESTABLISHED)
- barnyard2 7054 SO-user 3u IPv4 13850 0t0 TCP X.X.X.X:46260->X.X.X.X:8503 (ESTABLISHED)
- barnyard2 7072 SO-user 3u IPv4 29355 0t0 TCP X.X.X.X:44900->X.X.X.X:8504 (ESTABLISHED)
- barnyard2 7092 SO-user 3u IPv4 28413 0t0 TCP X.X.X.X:37604->X.X.X.X:8505 (ESTABLISHED)
- barnyard2 7110 SO-user 3u IPv4 45118 0t0 TCP X.X.X.X:39944->X.X.X.X:8506 (ESTABLISHED)
- barnyard2 7127 SO-user 3u IPv4 12004 0t0 TCP X.X.X.X:52402->X.X.X.X:8507 (ESTABLISHED)
- barnyard2 7146 SO-user 3u IPv4 20355 0t0 TCP X.X.X.X:39172->X.X.X.X:8508 (ESTABLISHED)
- barnyard2 7163 SO-user 3u IPv4 33337 0t0 TCP X.X.X.X:48876->X.X.X.X:8509 (ESTABLISHED)
- barnyard2 7181 SO-user 3u IPv4 20898 0t0 TCP X.X.X.X:48382->X.X.X.X:8510 (ESTABLISHED)
- barnyard2 7203 SO-user 3u IPv4 18043 0t0 TCP X.X.X.X:45624->X.X.X.X:8511 (ESTABLISHED)
- barnyard2 7236 SO-user 3u IPv4 23060 0t0 TCP X.X.X.X:39450->X.X.X.X:8512 (ESTABLISHED)
- barnyard2 7254 SO-user 3u IPv4 25033 0t0 TCP X.X.X.X:51996->X.X.X.X:8513 (ESTABLISHED)
- barnyard2 7272 SO-user 3u IPv4 32361 0t0 TCP X.X.X.X:56428->X.X.X.X:8514 (ESTABLISHED)
- barnyard2 7290 SO-user 3u IPv4 32407 0t0 TCP X.X.X.X:40458->X.X.X.X:8515 (ESTABLISHED)
- tclsh 7312 SO-user 3u IPv4 36184 0t0 TCP X.X.X.X:33396->X.X.X.X:7736 (ESTABLISHED)
- docker-pr 7498 root 4u IPv6 26854 0t0 TCP *:10004 (LISTEN)
- docker-pr 7801 root 4u IPv6 44079 0t0 TCP *:20000 (LISTEN)
- docker-pr 8085 root 4u IPv6 26904 0t0 TCP *:9300 (LISTEN)
- docker-pr 8110 root 4u IPv6 32370 0t0 TCP *:9200 (LISTEN)
- docker-pr 8433 root 4u IPv6 35261 0t0 TCP *:6053 (LISTEN)
- docker-pr 8445 root 4u IPv6 11994 0t0 TCP *:6052 (LISTEN)
- docker-pr 8457 root 4u IPv6 43320 0t0 TCP *:6051 (LISTEN)
- docker-pr 8469 root 3u IPv6 46315 0t0 TCP X.X.X.X:6050->X.X.X.X:43179 (ESTABLISHED)
- docker-pr 8469 root 4u IPv6 12001 0t0 TCP *:6050 (LISTEN)
- docker-pr 8469 root 6u IPv4 46317 0t0 TCP X.X.X.X:49380->X.X.X.X:6050 (ESTABLISHED)
- sshd 8700 root 3u IPv4 18849 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:64746 (ESTABLISHED)
- sshd 8883 SO-user 3u IPv4 18849 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:64746 (ESTABLISHED)
- docker-pr 9047 root 3u IPv6 189556 0t0 TCP X.X.X.X:5601->X.X.X.X:39642 (FIN_WAIT2)
- docker-pr 9047 root 4u IPv6 45161 0t0 TCP *:5601 (LISTEN)
- docker-pr 9047 root 6u IPv4 189558 0t0 TCP X.X.X.X:44818->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 10u IPv6 45252 0t0 TCP X.X.X.X:5601->X.X.X.X:38698 (FIN_WAIT2)
- docker-pr 9047 root 11u IPv4 45254 0t0 TCP X.X.X.X:43874->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 12u IPv6 52924 0t0 TCP X.X.X.X:5601->X.X.X.X:38708 (FIN_WAIT2)
- docker-pr 9047 root 13u IPv4 52926 0t0 TCP X.X.X.X:43884->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 14u IPv6 178044 0t0 TCP X.X.X.X:5601->X.X.X.X:39662 (FIN_WAIT2)
- docker-pr 9047 root 16u IPv4 178046 0t0 TCP X.X.X.X:44838->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 18u IPv6 52929 0t0 TCP X.X.X.X:5601->X.X.X.X:38730 (FIN_WAIT2)
- docker-pr 9047 root 19u IPv4 52931 0t0 TCP X.X.X.X:43908->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 20u IPv6 33643 0t0 TCP X.X.X.X:5601->X.X.X.X:38732 (FIN_WAIT2)
- docker-pr 9047 root 21u IPv4 33645 0t0 TCP X.X.X.X:43910->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 24u IPv6 189561 0t0 TCP X.X.X.X:5601->X.X.X.X:39700 (FIN_WAIT2)
- docker-pr 9047 root 25u IPv6 189562 0t0 TCP X.X.X.X:5601->X.X.X.X:39702 (FIN_WAIT2)
- docker-pr 9047 root 26u IPv4 195647 0t0 TCP X.X.X.X:44878->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 27u IPv4 189564 0t0 TCP X.X.X.X:44880->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 28u IPv6 195648 0t0 TCP X.X.X.X:5601->X.X.X.X:39708 (FIN_WAIT2)
- docker-pr 9047 root 29u IPv4 195650 0t0 TCP X.X.X.X:44884->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 30u IPv6 176900 0t0 TCP X.X.X.X:5601->X.X.X.X:39654 (FIN_WAIT2)
- docker-pr 9047 root 31u IPv6 176901 0t0 TCP X.X.X.X:5601->X.X.X.X:39656 (FIN_WAIT2)
- docker-pr 9047 root 32u IPv4 176903 0t0 TCP X.X.X.X:44832->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 33u IPv4 192543 0t0 TCP X.X.X.X:44834->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 34u IPv6 183782 0t0 TCP X.X.X.X:5601->X.X.X.X:39666 (FIN_WAIT2)
- docker-pr 9047 root 35u IPv4 183784 0t0 TCP X.X.X.X:44842->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 36u IPv6 188725 0t0 TCP X.X.X.X:5601->X.X.X.X:39672 (FIN_WAIT2)
- docker-pr 9047 root 37u IPv4 188727 0t0 TCP X.X.X.X:44848->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 38u IPv6 146371 0t0 TCP X.X.X.X:5601->X.X.X.X:39684 (FIN_WAIT2)
- docker-pr 9047 root 39u IPv4 146373 0t0 TCP X.X.X.X:44860->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 40u IPv6 171717 0t0 TCP X.X.X.X:5601->X.X.X.X:39690 (FIN_WAIT2)
- docker-pr 9047 root 41u IPv4 171719 0t0 TCP X.X.X.X:44866->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 42u IPv6 180492 0t0 TCP X.X.X.X:5601->X.X.X.X:39696 (FIN_WAIT2)
- docker-pr 9047 root 43u IPv4 180494 0t0 TCP X.X.X.X:44872->X.X.X.X:5601 (CLOSE_WAIT)
- docker-pr 9047 root 44u IPv6 183788 0t0 TCP X.X.X.X:5601->X.X.X.X:39716 (FIN_WAIT2)
- docker-pr 9047 root 45u IPv4 183790 0t0 TCP X.X.X.X:44892->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10523 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 10523 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 10523 www-data 20u IPv4 39493 0t0 TCP X.X.X.X:38698->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10523 www-data 22u IPv4 189559 0t0 TCP X.X.X.X:39662->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10523 www-data 23u IPv4 56333 0t0 TCP X.X.X.X:38730->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10523 www-data 24u IPv4 188730 0t0 TCP X.X.X.X:39684->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10524 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 10524 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 10524 www-data 19u IPv6 406087 0t0 TCP X.X.X.X:443->X.X.X.X:62401 (ESTABLISHED)
- apache2 10524 www-data 20u IPv4 178362 0t0 TCP X.X.X.X:39702->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10525 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 10525 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- apache2 10525 www-data 20u IPv4 31353 0t0 TCP X.X.X.X:38708->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10525 www-data 22u IPv4 168428 0t0 TCP X.X.X.X:39708->X.X.X.X:5601 (CLOSE_WAIT)
- apache2 10526 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 10526 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- sshd 13147 root 3u IPv4 67143 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:53109 (ESTABLISHED)
- sshd 13599 SO-user 3u IPv4 67143 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:53109 (ESTABLISHED)
- apache2 31483 www-data 4u IPv6 35920 0t0 TCP *:443 (LISTEN)
- apache2 31483 www-data 6u IPv6 35924 0t0 TCP *:9876 (LISTEN)
- =========================================================================
- IDS Rules Update
- =========================================================================
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 7.91 9.01 9.63
- Processing units: 32
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 13:27:15 up 1:15, 3 users, load average: 8,00, 9,01, 9,62
- Tasks: 592 total, 17 running, 575 sleeping, 0 stopped, 0 zombie
- %Cpu(s): 31,9 us, 3,8 sy, 0,0 ni, 63,5 id, 0,4 wa, 0,0 hi, 0,3 si, 0,0 st
- KiB Mem: 32903884 total, 32719352 used, 184532 free, 254668 buffers
- KiB Swap: 33518332 total, 7656744 used, 25861588 free. 13835256 cached Mem
- %CPU %MEM COMMAND
- 77.7 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-11 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-11.stats -U --snaplen 1524
- 55.2 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-4 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-4.stats -U --snaplen 1524
- 51.3 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-5 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-5.stats -U --snaplen 1524
- 51.1 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-7 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-7.stats -U --snaplen 1524
- 49.8 0.7 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-6 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-6.stats -U --snaplen 1524
- 47.6 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-1 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-1.stats -U --snaplen 1524
- 44.4 0.5 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-2 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-2.stats -U --snaplen 1524
- 42.4 0.6 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-3 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-3.stats -U --snaplen 1524
- 40.4 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-10 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-10.stats -U --snaplen 1524
- 39.9 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-15 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-15.stats -U --snaplen 1524
- 36.6 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-13 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-13.stats -U --snaplen 1524
- 35.3 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-9 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-9.stats -U --snaplen 1524
- 31.1 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-15 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 30.5 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-8 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-8.stats -U --snaplen 1524
- 30.0 12.9 netsniff-ng -i eth5 -o /nsm/sensor_data/securityonion-eth5/dailylogs/2017-09-19/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 4024 iB --interval 150 iB --mmap
- 29.3 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-12 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-12.stats -U --snaplen 1524
- 28.5 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.6 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.3 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-4 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.3 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-8 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.1 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-7 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.1 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-11 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.1 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-12 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 27.0 0.9 snort -c /etc/nsm/securityonion-eth5/snort.conf -u SO-user -g SO-user -i eth5 -l /nsm/sensor_data/securityonion-eth5/snort-14 --perfmon-file /nsm/sensor_data/securityonion-eth5/snort-14.stats -U --snaplen 1524
- 26.9 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-10 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.9 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-13 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.8 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-9 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.7 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-6 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.5 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-5 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.3 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-3 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 26.3 0.3 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-14 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 20.8 0.0 tclsh /usr/bin/http_agent.tcl -c /etc/nsm/securityonion-eth5/http_agent.conf -e /etc/nsm/securityonion-eth5/http_agent.exclude -f /nsm/bro/logs/current/http_eth5.log
- 14.9 8.5 /usr/bin/java -XX:+UseParNewGC -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+DisableExplicitGC -Djava.awt.headless=true -Dfile.encoding=UTF-8 -XX:+HeapDumpOnOutOfMemoryError -Djava.security.egd=file:/dev/urandom -Xmx8225m -Xms8225m -Xss2048k -Djffi.boot.library.path=/usr/share/logstash/vendor/jruby/lib/jni -Xbootclasspath/a:/usr/share/logstash/vendor/jruby/lib/jruby.jar -classpath : -Djruby.home=/usr/share/logstash/vendor/jruby -Djruby.lib=/usr/share/logstash/vendor/jruby/lib -Djruby.script=jruby -Djruby.shell=/bin/sh org.jruby.Main /usr/share/logstash/lib/bootstrap/environment.rb logstash/runner.rb
- 14.1 0.4 /usr/sbin/mysqld
- 11.4 0.2 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 9.6 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 6.8 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 4.5 0.0 [ksoftirqd/20]
- 3.1 0.0 [kworker/14:1]
- 3.1 0.0 [kworker/11:1]
- 3.1 0.0 [kworker/13:1]
- 3.1 0.0 [kworker/4:0]
- 3.0 0.0 [kworker/12:1]
- 3.0 0.0 [kworker/10:1]
- 3.0 0.0 [kworker/9:0]
- 2.9 0.0 [kworker/5:1]
- 2.9 0.0 [kworker/15:1]
- 2.8 0.0 [kworker/8:1]
- 2.5 0.0 [rcu_sched]
- 2.5 0.0 [kworker/20:1]
- 2.5 0.0 [kworker/28:1]
- 2.5 0.0 [kworker/29:1]
- 2.5 0.0 [kworker/0:2]
- 2.5 0.0 [kworker/7:1]
- 2.4 0.0 [kworker/27:1]
- 2.4 0.0 [kworker/9:1]
- 2.4 0.0 [kworker/26:2]
- 2.4 0.0 [kworker/24:2]
- 2.4 0.0 [kworker/30:2]
- 2.4 0.0 [kworker/2:0]
- 2.3 0.0 [kworker/31:1]
- 2.3 0.0 [kworker/25:1]
- 2.2 0.0 [kworker/6:2]
- 2.2 0.0 [kworker/3:0]
- 2.1 0.0 [kworker/1:1]
- 2.0 0.0 [kworker/21:1]
- 2.0 9.2 /usr/lib/jvm/jre-1.8.0-openjdk/bin/java -Xms2g -Xmx2g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -XX:+AlwaysPreTouch -server -Xss1m -Djava.awt.headless=true -Dfile.encoding=UTF-8 -Djna.nosys=true -Djdk.io.permissionsUseCanonicalPath=true -Dio.netty.noUnsafe=true -Dio.netty.noKeySetOptimization=true -Dio.netty.recycler.maxCapacityPerThread=0 -Dlog4j.shutdownHookEnabled=false -Dlog4j2.disable.jmx=true -Dlog4j.skipJansi=true -XX:+HeapDumpOnOutOfMemoryError -Des.cgroups.hierarchy.override=/ -Xms8225m -Xmx8225m -Des.path.home=/usr/share/elasticsearch -cp /usr/share/elasticsearch/lib/* org.elasticsearch.bootstrap.Elasticsearch -Etransport.host=X.X.X.X -Ehttp.host=X.X.X.X
- 2.0 0.0 [kworker/16:2]
- 2.0 0.0 [kworker/7:2]
- 1.8 0.0 [kworker/6:0]
- 1.7 0.0 [kworker/17:1]
- 1.7 0.0 [kworker/19:1]
- 1.7 0.0 [kworker/23:2]
- 1.7 0.0 [kworker/18:0]
- 1.6 0.0 [kworker/22:1]
- 1.5 0.0 [kworker/0:1]
- 1.5 0.0 /var/ossec/bin/ossec-syscheckd
- 0.9 0.0 [kswapd0]
- 0.9 0.0 [kswapd1]
- 0.9 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-3.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-3 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-3 -i securityonion-eth5-3 -U
- 0.8 0.0 /usr/sbin/syslog-ng -p /var/run/syslog-ng.pid
- 0.8 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-4.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-4 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-4 -i securityonion-eth5-4 -U
- 0.7 0.0 [jbd2/sda1-8]
- 0.7 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-6.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-6 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-6 -i securityonion-eth5-6 -U
- 0.7 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-7.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-7 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-7 -i securityonion-eth5-7 -U
- 0.7 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-8.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-8 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-8 -i securityonion-eth5-8 -U
- 0.7 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-11.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-11 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-11 -i securityonion-eth5-11 -U
- 0.6 0.0 [kworker/23:1]
- 0.6 0.0 [kworker/30:1]
- 0.6 0.0 [jbd2/sdb-8]
- 0.6 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-12.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-12 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-12 -i securityonion-eth5-12 -U
- 0.6 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-13.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-13 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-13 -i securityonion-eth5-13 -U
- 0.6 0.2 /usr/share/kibana/bin/../node/bin/node --no-warnings /usr/share/kibana/bin/../src/cli --cpu.cgroup.path.override=/ --cpuacct.cgroup.path.override=/ --kibana.defaultAppId=dashboard/94b52620-342a-11e7-9d52-4f090484f59e
- 0.5 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-9.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-9 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-9 -i securityonion-eth5-9 -U
- 0.5 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-10.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-10 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-10 -i securityonion-eth5-10 -U
- 0.5 0.0 [kworker/15:0]
- 0.5 0.0 [kworker/u129:1]
- 0.4 0.0 /usr/bin/python /usr/bin/salt-master
- 0.4 0.1 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.4 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-1.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-1 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-1 -i securityonion-eth5-1 -U
- 0.4 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-2.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-2 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-2 -i securityonion-eth5-2 -U
- 0.4 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-5.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-5 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-5 -i securityonion-eth5-5 -U
- 0.4 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-15.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-15 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-15 -i securityonion-eth5-15 -U
- 0.4 0.9 /usr/bin/python /opt/domain_stats/domain_stats.py -ip X.X.X.X 20000 -a /opt/domain_stats/top-1m.csv --preload 0
- 0.3 0.1 /usr/bin/dockerd --raw-logs
- 0.3 0.0 barnyard2 -c /etc/nsm/securityonion-eth5/barnyard2-14.conf -u SO-user -g SO-user -d /nsm/sensor_data/securityonion-eth5/snort-14 -f snort.unified2 -w /etc/nsm/securityonion-eth5/barnyard2.waldo-14 -i securityonion-eth5-14 -U
- 0.3 0.0 /usr/bin/python /opt/freq_server/freq/freq_server.py -ip X.X.X.X 10004 /opt/freq_server/freq/freq_table.freq
- 0.2 0.0 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.2 0.0 [kworker/u129:0]
- 0.1 0.0 [ksoftirqd/0]
- 0.1 0.0 docker-containerd -l unix:///var/run/docker/libcontainerd/docker-containerd.sock --metrics-interval=0 --start-timeout 2m --state-dir /var/run/docker/libcontainerd/containerd --shim docker-containerd-shim --runtime docker-runc
- 0.1 0.0 /var/ossec/bin/ossec-analysisd
- 0.1 0.0 tail -n 0 -F /nsm/bro/logs/current/http_eth5.log
- 0.1 0.0 docker-containerd-shim e48987198190f16eb9299363bf6ba87381994a200006de215b582bd26e7f8a3a /var/run/docker/libcontainerd/e48987198190f16eb9299363bf6ba87381994a200006de215b582bd26e7f8a3a docker-runc
- 0.1 0.0 /bin/sh /opt/start-elastalert.sh
- 0.0 0.0 /sbin/init
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [kworker/u128:0]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [watchdog/1]
- 0.0 0.0 [migration/1]
- 0.0 0.0 [ksoftirqd/1]
- 0.0 0.0 [kworker/1:0H]
- 0.0 0.0 [watchdog/2]
- 0.0 0.0 [migration/2]
- 0.0 0.0 [ksoftirqd/2]
- 0.0 0.0 [kworker/2:0H]
- 0.0 0.0 [watchdog/3]
- 0.0 0.0 [migration/3]
- 0.0 0.0 [ksoftirqd/3]
- 0.0 0.0 [kworker/3:0H]
- 0.0 0.0 [watchdog/4]
- 0.0 0.0 [migration/4]
- 0.0 0.0 [ksoftirqd/4]
- 0.0 0.0 [kworker/4:0H]
- 0.0 0.0 [watchdog/5]
- 0.0 0.0 [migration/5]
- 0.0 0.0 [ksoftirqd/5]
- 0.0 0.0 [kworker/5:0H]
- 0.0 0.0 [watchdog/6]
- 0.0 0.0 [migration/6]
- 0.0 0.0 [ksoftirqd/6]
- 0.0 0.0 [kworker/6:0H]
- 0.0 0.0 [watchdog/7]
- 0.0 0.0 [migration/7]
- 0.0 0.0 [ksoftirqd/7]
- 0.0 0.0 [kworker/7:0H]
- 0.0 0.0 [watchdog/8]
- 0.0 0.0 [migration/8]
- 0.0 0.0 [ksoftirqd/8]
- 0.0 0.0 [kworker/8:0]
- 0.0 0.0 [kworker/8:0H]
- 0.0 0.0 [watchdog/9]
- 0.0 0.0 [migration/9]
- 0.0 0.0 [ksoftirqd/9]
- 0.0 0.0 [kworker/9:0H]
- 0.0 0.0 [watchdog/10]
- 0.0 0.0 [migration/10]
- 0.0 0.0 [ksoftirqd/10]
- 0.0 0.0 [kworker/10:0]
- 0.0 0.0 [kworker/10:0H]
- 0.0 0.0 [watchdog/11]
- 0.0 0.0 [migration/11]
- 0.0 0.0 [ksoftirqd/11]
- 0.0 0.0 [kworker/11:0]
- 0.0 0.0 [kworker/11:0H]
- 0.0 0.0 [watchdog/12]
- 0.0 0.0 [migration/12]
- 0.0 0.0 [ksoftirqd/12]
- 0.0 0.0 [kworker/12:0]
- 0.0 0.0 [kworker/12:0H]
- 0.0 0.0 [watchdog/13]
- 0.0 0.0 [migration/13]
- 0.0 0.0 [ksoftirqd/13]
- 0.0 0.0 [kworker/13:0H]
- 0.0 0.0 [watchdog/14]
- 0.0 0.0 [migration/14]
- 0.0 0.0 [ksoftirqd/14]
- 0.0 0.0 [kworker/14:0]
- 0.0 0.0 [kworker/14:0H]
- 0.0 0.0 [watchdog/15]
- 0.0 0.0 [migration/15]
- 0.0 0.0 [ksoftirqd/15]
- 0.0 0.0 [kworker/15:0H]
- 0.0 0.0 [watchdog/16]
- 0.0 0.0 [migration/16]
- 0.0 0.0 [ksoftirqd/16]
- 0.0 0.0 [kworker/16:0H]
- 0.0 0.0 [watchdog/17]
- 0.0 0.0 [migration/17]
- 0.0 0.0 [ksoftirqd/17]
- 0.0 0.0 [kworker/17:0H]
- 0.0 0.0 [watchdog/18]
- 0.0 0.0 [migration/18]
- 0.0 0.0 [ksoftirqd/18]
- 0.0 0.0 [kworker/18:0H]
- 0.0 0.0 [watchdog/19]
- 0.0 0.0 [migration/19]
- 0.0 0.0 [ksoftirqd/19]
- 0.0 0.0 [kworker/19:0H]
- 0.0 0.0 [watchdog/20]
- 0.0 0.0 [migration/20]
- 0.0 0.0 [kworker/20:0H]
- 0.0 0.0 [watchdog/21]
- 0.0 0.0 [migration/21]
- 0.0 0.0 [ksoftirqd/21]
- 0.0 0.0 [kworker/21:0]
- 0.0 0.0 [kworker/21:0H]
- 0.0 0.0 [watchdog/22]
- 0.0 0.0 [migration/22]
- 0.0 0.0 [ksoftirqd/22]
- 0.0 0.0 [kworker/22:0H]
- 0.0 0.0 [watchdog/23]
- 0.0 0.0 [migration/23]
- 0.0 0.0 [ksoftirqd/23]
- 0.0 0.0 [kworker/23:0H]
- 0.0 0.0 [watchdog/24]
- 0.0 0.0 [migration/24]
- 0.0 0.0 [ksoftirqd/24]
- 0.0 0.0 [kworker/24:0]
- 0.0 0.0 [kworker/24:0H]
- 0.0 0.0 [watchdog/25]
- 0.0 0.0 [migration/25]
- 0.0 0.0 [ksoftirqd/25]
- 0.0 0.0 [kworker/25:0]
- 0.0 0.0 [kworker/25:0H]
- 0.0 0.0 [watchdog/26]
- 0.0 0.0 [migration/26]
- 0.0 0.0 [ksoftirqd/26]
- 0.0 0.0 [kworker/26:0]
- 0.0 0.0 [kworker/26:0H]
- 0.0 0.0 [watchdog/27]
- 0.0 0.0 [migration/27]
- 0.0 0.0 [ksoftirqd/27]
- 0.0 0.0 [kworker/27:0]
- 0.0 0.0 [kworker/27:0H]
- 0.0 0.0 [watchdog/28]
- 0.0 0.0 [migration/28]
- 0.0 0.0 [ksoftirqd/28]
- 0.0 0.0 [kworker/28:0]
- 0.0 0.0 [kworker/28:0H]
- 0.0 0.0 [watchdog/29]
- 0.0 0.0 [migration/29]
- 0.0 0.0 [ksoftirqd/29]
- 0.0 0.0 [kworker/29:0]
- 0.0 0.0 [kworker/29:0H]
- 0.0 0.0 [watchdog/30]
- 0.0 0.0 [migration/30]
- 0.0 0.0 [ksoftirqd/30]
- 0.0 0.0 [kworker/30:0H]
- 0.0 0.0 [watchdog/31]
- 0.0 0.0 [migration/31]
- 0.0 0.0 [ksoftirqd/31]
- 0.0 0.0 [kworker/31:0]
- 0.0 0.0 [kworker/31:0H]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [perf]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [writeback]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [khugepaged]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [bioset]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [vmstat]
- 0.0 0.0 [fsnotify_mark]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [deferwq]
- 0.0 0.0 [kworker/u128:1]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [kpsmoused]
- 0.0 0.0 [scsi_eh_2]
- 0.0 0.0 [scsi_tmf_2]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [bioset]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kworker/10:1H]
- 0.0 0.0 upstart-udev-bridge --daemon
- 0.0 0.0 /lib/systemd/systemd-udevd --daemon
- 0.0 0.0 [edac-poller]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kmpathd]
- 0.0 0.0 [kmpath_handlerd]
- 0.0 0.0 [kvm-irqfd-clean]
- 0.0 0.0 [kipmi0]
- 0.0 0.0 dbus-daemon --system --fork
- 0.0 0.0 [kworker/3:1H]
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.0 avahi-daemon: running [SO-server.local]
- 0.0 0.0 avahi-daemon: chroot helper
- 0.0 0.0 /usr/sbin/bluetoothd
- 0.0 0.0 [krfcommd]
- 0.0 0.0 upstart-file-bridge --daemon
- 0.0 0.0 upstart-socket-bridge --daemon
- 0.0 0.0 [kworker/6:1H]
- 0.0 0.0 [kworker/4:1H]
- 0.0 0.0 /usr/sbin/ModemManager
- 0.0 0.0 /sbin/getty -8 38400 tty4
- 0.0 0.0 /sbin/getty -8 38400 tty5
- 0.0 0.0 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /sbin/getty -8 38400 tty2
- 0.0 0.0 /sbin/getty -8 38400 tty3
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /sbin/getty -8 38400 tty6
- 0.0 0.0 NetworkManager
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.0 /usr/sbin/irqbalance
- 0.0 0.0 lightdm
- 0.0 0.0 cron
- 0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.0 /usr/sbin/cups-browsed
- 0.0 0.1 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.0 [kworker/5:1H]
- 0.0 0.0 acpid -c /etc/acpi/events -s /var/run/acpid.socket
- 0.0 0.0 supervising syslog-ng
- 0.0 0.0 /usr/sbin/kerneloops
- 0.0 0.0 [kworker/17:1H]
- 0.0 0.0 /usr/bin/python /usr/bin/salt-minion
- 0.0 0.0 /var/ossec/bin/ossec-csyslogd
- 0.0 0.0 /var/ossec/bin/ossec-maild
- 0.0 0.0 /var/ossec/bin/ossec-execd
- 0.0 0.0 [kworker/13:1H]
- 0.0 0.0 /var/ossec/bin/ossec-logcollector
- 0.0 0.0 /var/ossec/bin/ossec-remoted
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /usr/bin/python /usr/bin/salt-master
- 0.0 0.0 /var/ossec/bin/ossec-monitord
- 0.0 0.0 [kauditd]
- 0.0 0.0 [kworker/2:1H]
- 0.0 0.0 [kworker/7:1H]
- 0.0 0.0 [kworker/12:1H]
- 0.0 0.0 [kworker/9:1H]
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 117:126
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /sbin/getty -8 38400 tty1
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/cupsd -f
- 0.0 0.0 [kworker/1:1H]
- 0.0 0.0 [kworker/18:1H]
- 0.0 0.0 su - SO-user -- /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 tclsh /usr/bin/SO-userd -c /etc/nsm/securityonion/SO-userd.conf -a /etc/nsm/securityonion/autocat.conf -g /etc/nsm/securityonion/SO-userd.queries -A /etc/nsm/securityonion/SO-userd.access -C /etc/nsm/securityonion/certs
- 0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 [kworker/14:1H]
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster local-manager.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster local-proxy broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-5 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-4 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-3 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-6 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-7 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-9 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-8 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-10 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-11 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-12 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-14 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-13 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 /bin/bash /opt/bro/share/broctl/scripts/run-bro -1 -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-15 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-13 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-8 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-15 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-5 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-9 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-2 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-1 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-4 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-14 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-10 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-11 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-6 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-7 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-3 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.1 /opt/bro/bin/bro -i eth5 -U .status -p broctl -p broctl-live -p local -p securityonion-eth5-12 local.bro broctl base/frameworks/cluster local-worker.bro broctl/auto
- 0.0 0.0 [kworker/11:1H]
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c /etc/nsm/securityonion-eth5/pcap_agent.conf
- 0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/securityonion-eth5/pcap_agent.conf
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-1.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-1.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-1.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-2.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-2.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-2.stats
- 0.0 0.0 [kworker/27:1H]
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-3.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-3.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-3.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-4.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-4.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-4.stats
- 0.0 0.0 [kworker/8:1H]
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-5.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-5.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-5.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-6.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-6.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-6.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-7.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-7.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-7.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-8.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-8.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-8.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-9.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-9.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-9.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-10.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-10.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-10.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-11.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-11.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-11.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-12.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-12.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-12.stats
- 0.0 0.0 [kworker/28:1H]
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-13.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-13.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-13.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-14.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-14.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-14.stats
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-15.conf
- 0.0 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/securityonion-eth5/snort_agent-15.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/securityonion-eth5/snort-15.stats
- 0.0 0.0 [kworker/31:1H]
- 0.0 0.0 [kworker/24:1H]
- 0.0 0.0 [kworker/22:1H]
- 0.0 0.0 su - SO-user -- /usr/bin/http_agent.tcl -c /etc/nsm/securityonion-eth5/http_agent.conf -e /etc/nsm/securityonion-eth5/http_agent.exclude -f /nsm/bro/logs/current/http_eth5.log
- 0.0 0.0 [kworker/19:1H]
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 10004 -container-ip X.X.X.X -container-port 10004
- 0.0 0.0 docker-containerd-shim 949e6698dea7ba79f467f5b19f3a2660937c4604c021a45525fba74af0604021 /var/run/docker/libcontainerd/949e6698dea7ba79f467f5b19f3a2660937c4604c021a45525fba74af0604021 docker-runc
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 20000 -container-ip X.X.X.X -container-port 20000
- 0.0 0.0 docker-containerd-shim 609c9bcb5a9a0e635472627377480418fae6ce97437ea5371bcd7404607c1f66 /var/run/docker/libcontainerd/609c9bcb5a9a0e635472627377480418fae6ce97437ea5371bcd7404607c1f66 docker-runc
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9300 -container-ip X.X.X.X -container-port 9300
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 9200 -container-ip X.X.X.X -container-port 9200
- 0.0 0.0 docker-containerd-shim 81abd74f44d8245556d59793e662931953a6579264cbb751cc3d55e685d08866 /var/run/docker/libcontainerd/81abd74f44d8245556d59793e662931953a6579264cbb751cc3d55e685d08866 docker-runc
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 6053 -container-ip X.X.X.X -container-port 6053
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 6052 -container-ip X.X.X.X -container-port 6052
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 6051 -container-ip X.X.X.X -container-port 6051
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 6050 -container-ip X.X.X.X -container-port 6050
- 0.0 0.0 docker-containerd-shim 123d773694200c1b0da1662345a5b349b0487a6cee748f76b595d6ae9f8e4977 /var/run/docker/libcontainerd/123d773694200c1b0da1662345a5b349b0487a6cee748f76b595d6ae9f8e4977 docker-runc
- 0.0 0.0 [kworker/15:1H]
- 0.0 0.0 [kworker/26:1H]
- 0.0 0.0 [kworker/25:1H]
- 0.0 0.0 [kworker/29:1H]
- 0.0 0.0 [kworker/30:1H]
- 0.0 0.0 sshd: SO-user [priv]
- 0.0 0.0 [kworker/23:1H]
- 0.0 0.0 sshd: SO-user@pts/1
- 0.0 0.0 -bash
- 0.0 0.0 /usr/bin/docker-proxy -proto tcp -host-ip X.X.X.X -host-port 5601 -container-ip X.X.X.X -container-port 5601
- 0.0 0.0 docker-containerd-shim f62e3a514bd009178f948dec9feb6c1cc7c14f41d4e2c23b456dbb747511a40e /var/run/docker/libcontainerd/f62e3a514bd009178f948dec9feb6c1cc7c14f41d4e2c23b456dbb747511a40e docker-runc
- 0.0 0.0 docker-containerd-shim 310badede7252463b052496e32ce744d54ed89982b3e7d62a51829fcf1b75b2c /var/run/docker/libcontainerd/310badede7252463b052496e32ce744d54ed89982b3e7d62a51829fcf1b75b2c docker-runc
- 0.0 0.0 /bin/bash
- 0.0 0.0 su
- 0.0 0.0 bash
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 [kworker/16:1H]
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 [kworker/21:1H]
- 0.0 0.0 [kworker/20:1H]
- 0.0 0.0 lightdm --session-child 12 21
- 0.0 0.0 /usr/bin/gnome-keyring-daemon --daemonize --login
- 0.0 0.0 init --user
- 0.0 0.0 dbus-daemon --fork --session --address=unix:abstract=/tmp/dbus-102J1iuxlt
- 0.0 0.0 upstart-event-bridge
- 0.0 0.0 upstart-dbus-bridge --daemon --system --user --bus-name system
- 0.0 0.0 upstart-dbus-bridge --daemon --session --user --bus-name session
- 0.0 0.0 upstart-file-bridge --daemon --user
- 0.0 0.0 /bin/sh /etc/xdg/xfce4/xinitrc -- /etc/X11/xinit/xserverrc
- 0.0 0.0 xfce4-session
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
- 0.0 0.0 /usr/bin/ssh-agent -s
- 0.0 0.0 xfwm4
- 0.0 0.0 xfce4-panel
- 0.0 0.0 Thunar --daemon
- 0.0 0.0 xfdesktop
- 0.0 0.0 /usr/bin/python /usr/share/system-config-printer/applet.py
- 0.0 0.0 update-notifier
- 0.0 0.1 /usr/bin/python /usr/bin/blueman-applet
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-power/indicator-power-service
- 0.0 0.0 light-locker
- 0.0 0.0 nm-applet
- 0.0 0.0 /usr/lib/policykit-1-gnome/polkit-gnome-authentication-agent-1
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-application/indicator-application-service
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 xfsettingsd
- 0.0 0.0 xfce4-power-manager
- 0.0 0.0 xfce4-volumed
- 0.0 0.0 /usr/lib/upower/upowerd
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/1000/gvfs -f -o big_writes
- 0.0 0.0 /usr/bin/pulseaudio --start --log-target=syslog
- 0.0 0.0 /usr/lib/rtkit/rtkit-daemon
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libwhiskermenu.so 1 12582944 whiskermenu Whisker Menu Show a menu to easily access installed applications
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-1.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 4 12582945 systray Notification Area Area where notification icons appear
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libindicator-plugin.so 5 12582946 indicator Indicator Plugin Provides a panel area for Unity indicators. Indicators allow applications and system services to display their status and interact with the user.
- 0.0 0.0 init --user --startup-event indicator-services-start
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/indicator-messages/indicator-messages-service
- 0.0 0.0 /usr/lib/gvfs/gvfs-udisks2-volume-monitor
- 0.0 0.0 /usr/lib/udisks2/udisksd --no-debug
- 0.0 0.0 /usr/lib/x86_64-linux-gnu/gconf/gconfd-2
- 0.0 0.0 sshd: SO-user [priv]
- 0.0 0.0 /usr/lib/gvfs/gvfs-gphoto2-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfs-afc-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfs-mtp-volume-monitor
- 0.0 0.0 /usr/lib/gvfs/gvfsd-trash --spawner :1.15 /org/gtk/gvfs/exec_spaw/0
- 0.0 0.0 /usr/bin/obex-data-server --no-daemon
- 0.0 0.0 sshd: SO-user@pts/7
- 0.0 0.0 -bash
- 0.0 0.0 su
- 0.0 0.0 bash
- 0.0 0.0 [kworker/20:2]
- 0.0 0.1 /usr/lib/xorg/Xorg -core :1 -seat seat0 -auth /var/run/lightdm/root/:1 -nolisten tcp vt8 -novtswitch
- 0.0 0.0 lightdm --session-child 17 22
- 0.0 0.0 /bin/sh /usr/lib/lightdm/lightdm-greeter-session /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 //bin/dbus-daemon --fork --print-pid 5 --print-address 7 --session
- 0.0 0.0 /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher
- 0.0 0.0 /bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 /usr/lib/gvfs/gvfsd-fuse /run/user/112/gvfs -f -o big_writes
- 0.0 0.0 lightdm --session-child 13 22
- 0.0 0.0 [kworker/1:2]
- 0.0 0.0 [kworker/16:0]
- 0.0 0.0 /usr/sbin/apache2 -k start
- 0.0 0.0 [kworker/19:0]
- 0.0 0.0 [kworker/18:1]
- 0.0 0.0 [kworker/4:1]
- 0.0 0.0 [kworker/22:0]
- 0.0 0.0 [kworker/2:2]
- 0.0 0.0 [kworker/u130:2]
- 0.0 0.0 [kworker/13:2]
- 0.0 0.0 [kworker/3:2]
- 0.0 0.0 [kworker/u130:1]
- 0.0 0.0 [kworker/17:0]
- 0.0 0.0 [kworker/5:2]
- 0.0 0.0 [kworker/u130:0]
- 0.0 0.0 [kworker/1:0]
- 0.0 0.0 [kworker/6:1]
- 0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
- 0.0 0.0 /bin/bash /usr/sbin/sostat
- 0.0 0.0 sleep 1
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- eth5: 25155129
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- eth5:
- RX packets:225934055 dropped:0 TX packets:0 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- Appl. Name : bro-eth5
- Tot Packets : 14674880
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 14441597
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 11651421
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 12390514
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 11015484
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 10333591
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 14135288
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 13772934
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 14267720
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 16884773
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 12403044
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 10375336
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 10462557
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 12134321
- Tot Pkt Lost : 0
- Appl. Name : bro-eth5
- Tot Packets : 43224611
- Tot Pkt Lost : 0
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 10561551
- Tot Pkt Lost : 482409
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 13989676
- Tot Pkt Lost : 602354
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 12383340
- Tot Pkt Lost : 1139819
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 43117667
- Tot Pkt Lost : 2200083
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 13704746
- Tot Pkt Lost : 887457
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 14623414
- Tot Pkt Lost : 1767633
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 14414443
- Tot Pkt Lost : 2041826
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 11023521
- Tot Pkt Lost : 123622
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 10218650
- Tot Pkt Lost : 427547
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 11887195
- Tot Pkt Lost : 118050
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 16720116
- Tot Pkt Lost : 2314997
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 10244401
- Tot Pkt Lost : 126094
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 13762091
- Tot Pkt Lost : 963874
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 11510314
- Tot Pkt Lost : 31979
- Appl. Name : snort-cluster-56-socket-0
- Tot Packets : 12184142
- Tot Pkt Lost : 117871
- -------------------------------------------------------------------------
- IDS Engine (snort) packet drops:
- /nsm/sensor_data/securityonion-eth5/snort-10.stats last reported pkt_drop_percent as 0.000
- /nsm/sensor_data/securityonion-eth5/snort-11.stats last reported pkt_drop_percent as 0.000
- /nsm/sensor_data/securityonion-eth5/snort-12.stats last reported pkt_drop_percent as 0.000
- /nsm/sensor_data/securityonion-eth5/snort-13.stats last reported pkt_drop_percent as 0.443
- /nsm/sensor_data/securityonion-eth5/snort-14.stats last reported pkt_drop_percent as 0.000
- /nsm/sensor_data/securityonion-eth5/snort-15.stats last reported pkt_drop_percent as 2.276
- /nsm/sensor_data/securityonion-eth5/snort-1.stats last reported pkt_drop_percent as 0.029
- /nsm/sensor_data/securityonion-eth5/snort-2.stats last reported pkt_drop_percent as 0.129
- /nsm/sensor_data/securityonion-eth5/snort-3.stats last reported pkt_drop_percent as 0.000
- /nsm/sensor_data/securityonion-eth5/snort-4.stats last reported pkt_drop_percent as 0.684
- /nsm/sensor_data/securityonion-eth5/snort-5.stats last reported pkt_drop_percent as 2.530
- /nsm/sensor_data/securityonion-eth5/snort-6.stats last reported pkt_drop_percent as 0.958
- /nsm/sensor_data/securityonion-eth5/snort-7.stats last reported pkt_drop_percent as 4.045
- /nsm/sensor_data/securityonion-eth5/snort-8.stats last reported pkt_drop_percent as 2.222
- /nsm/sensor_data/securityonion-eth5/snort-9.stats last reported pkt_drop_percent as 1.639
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.000000
- securityonion-eth5-1: 1505827637.610031 recvd=14677896 dropped=0 link=14677896
- securityonion-eth5-2: 1505827639.907888 recvd=14471795 dropped=0 link=14471795
- securityonion-eth5-3: 1505827642.913935 recvd=11658939 dropped=0 link=11658939
- securityonion-eth5-4: 1505827644.116536 recvd=11023921 dropped=0 link=11023921
- securityonion-eth5-5: 1505827645.118083 recvd=12416561 dropped=0 link=12416561
- securityonion-eth5-6: 1505827646.120856 recvd=10341181 dropped=0 link=10341181
- securityonion-eth5-7: 1505827647.122667 recvd=14158557 dropped=0 link=14158557
- securityonion-eth5-8: 1505827648.326707 recvd=14284727 dropped=0 link=14284727
- securityonion-eth5-9: 1505827649.931020 recvd=13789856 dropped=0 link=13789856
- securityonion-eth5-10: 1505827650.934033 recvd=10398417 dropped=0 link=10398417
- securityonion-eth5-11: 1505827651.460123 recvd=16922816 dropped=0 link=16922816
- securityonion-eth5-12: 1505827652.363852 recvd=12448316 dropped=0 link=12448316
- securityonion-eth5-13: 1505827656.345810 recvd=10502061 dropped=0 link=10502061
- securityonion-eth5-14: 1505827658.149342 recvd=12156907 dropped=0 link=12156907
- securityonion-eth5-15: 1505827659.151160 recvd=43269547 dropped=0 link=43269547
- Capture Loss:
- securityonion-eth5-10 0.003343
- securityonion-eth5-1 0.000551
- securityonion-eth5-11 0.003944
- securityonion-eth5-12 0.033575
- securityonion-eth5-13 0.0264
- securityonion-eth5-14 0.002065
- securityonion-eth5-15 0.001718
- securityonion-eth5-2 0.002293
- securityonion-eth5-3 0.001227
- securityonion-eth5-4 0.001813
- securityonion-eth5-5 0.004762
- securityonion-eth5-6 0.001512
- securityonion-eth5-7 0.014542
- securityonion-eth5-8 0.001326
- securityonion-eth5-9 0.009635
- If you are seeing capture loss without dropped packets, this
- may indicate that an upstream device is dropping packets (tap or SPAN port).
- -------------------------------------------------------------------------
- Netsniff-NG:
- Percentage of packets dropped:
- /var/log/nsm/securityonion-eth5/netsniff-ng.log --
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.6.0 (unknown)
- Total rings : 30
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Cluster Fragment Queue : 0
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/securityonion-eth0/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/securityonion-eth1/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/securityonion-eth2/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/securityonion-eth3/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/securityonion-eth4/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/securityonion-eth5/dailylogs/ - 2 days
- 244G .
- 85G ./2017-09-18
- 159G ./2017-09-19
- /nsm/bro/logs/ - 2 days
- 198M .
- 118M ./2017-09-18
- 80M ./2017-09-19
- 880K ./stats
- =========================================================================
- Sguil Uncategorized Events
- =========================================================================
- COUNT(*)
- 104508
- =========================================================================
- Sguil events summary for yesterday
- =========================================================================
- Totals GenID:SigID Signature
- 16860 1:2015898 ET INFO Suspicious Windows NT version 1 User-Agent
- 16270 1:2101411 GPL SNMP public access udp
- 4056 1:2100480 GPL ICMP_INFO PING speedera
- 4056 1:2100368 GPL ICMP_INFO PING BSDtype
- 4056 1:2100366 GPL ICMP_INFO PING *NIX
- 3537 1:2008120 ET TFTP Outbound TFTP Read Request
- 1535 1:2000419 ET POLICY PE EXE or DLL Windows file download
- 550 1:2013222 ET SHELLCODE Excessive Use of HeapLib Objects Likely Malicious Heap Spray Attempt
- 509 1:2009702 ET POLICY DNS Update From External net
- 258 1:2012086 ET SHELLCODE Possible Call with No Offset TCP Shellcode
- 200 1:2014726 ET POLICY Outdated Windows Flash Version IE
- 182 1:2015744 ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
- 172 1:2102650 GPL SQL user name buffer overflow attempt
- 120 1:2016149 ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
- 120 1:2017282 ET INFO Microsoft Script Encoder Encoded File
- 99 1:2016150 ET INFO Session Traversal Utilities for NAT (STUN Binding Response)
- 99 1:2006380 ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted
- 58 1:2010936 ET POLICY Suspicious inbound to Oracle SQL port 1521
- 54 1:2101201 GPL WEB_SERVER 403 Forbidden
- 53 1:2006402 ET POLICY Incoming Basic Auth Base64 HTTP Password detected unencrypted
- 50 1:2101390 GPL SHELLCODE x86 inc ebx NOOP
- 48 1:2014819 ET INFO Packed Executable Download
- 44 1:2012087 ET SHELLCODE Possible Call with No Offset UDP Shellcode
- 40 1:2010517 ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)
- 37 1:2016360 ET INFO JAVA - ClassID
- 32 1:2019401 ET POLICY Vulnerable Java Version 1.8.x Detected
- 32 1:2013273 ET SHELLCODE Hex Obfuscated JavaScript Heap Spray 41414141
- 30 1:2008581 ET P2P BitTorrent DHT ping request
- 29 1:2019707 ET WEB_CLIENT GENERIC VB ShellExecute Function Inside of VBSCRIPT tag
- 25 1:2002157 ET CHAT Skype User-Agent detected
- 22 1:2014920 ET POLICY Microsoft Online Storage Client Hello TLSv1 Possible SkyDrive (2)
- 22 1:2014919 ET POLICY Microsoft Online Storage Client Hello TLSv1 Possible SkyDrive (1)
- 20 1:2015561 ET INFO PDF Using CCITTFax Filter
- 20 1:2012888 ET POLICY Http Client Body contains pwd= in cleartext
- 19 1:2000418 ET POLICY Executable and linking format (ELF) file download
- 16 1:2015743 ET INFO Revoked Adobe Code Signing Certificate Seen
- 16 1:2011582 ET POLICY Vulnerable Java Version 1.6.x Detected
- 15 1:2010935 ET POLICY Suspicious inbound to MSSQL port 1433
- 15 1:2101892 GPL SNMP null community string attempt
- 15 1:2103003 GPL NETBIOS SMB-DS Session Setup NTMLSSP unicode asn1 overflow attempt
- 14 1:2014520 ET INFO EXE - Served Attached HTTP
- 14 1:2002878 ET POLICY iTunes User Agent
- 12 1:2001343 ET WEB_SERVER IIS ASP.net Auth Bypass / Canonicalization % 5 C
- 11 1:2100651 GPL SHELLCODE x86 stealth NOOP
- 10 1:2102466 GPL NETBIOS SMB-DS IPC$ unicode share access
- 8 1:2013505 ET POLICY GNU/Linux YUM User-Agent Outbound likely related to package management
- 8 1:2014297 ET POLICY Vulnerable Java Version 1.7.x Detected
- 8 1:2102314 GPL SHELLCODE x86 0x90 NOOP unicode
- 5 1:2001329 ET POLICY RDP connection request
- 5 1:2001330 ET POLICY RDP connection confirm
- 3 1:2016104 ET TROJAN DNS Reply for unallocated address space - Potentially Malicious X.X.X.X/24
- 3 1:2013410 ET POLICY Outbound MSSQL Connection to Standard port (1433)
- 3 1:2100230 GPL CHAT Jabber/Google Talk Outgoing Traffic
- 3 1:2001239 ET POLICY Cisco Device in Config Mode
- 2 1:2002327 ET CHAT Google Talk (Jabber) Client Login
- 2 1:2001240 ET POLICY Cisco Device New Config Built
- 2 1:2016670 ET WEB_SERVER SQL Errors in HTTP 200 Response (SqlException)
- 2 1:2012887 ET POLICY Http Client Body contains pass= in cleartext
- 2 1:2019584 ET TROJAN CORESHELL Malware Response from server
- 2 1:2100232 GPL CHAT Google Talk Logon
- 2 1:2010937 ET POLICY Suspicious inbound to mySQL port 3306
- 2 1:2002334 ET CHAT Google IM traffic Jabber client sign-on
- 2 1:2013031 ET POLICY Python-urllib/ Suspicious User Agent
- 2 1:2522827 ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic group 414
- 1 1:2012709 ET POLICY MS Remote Desktop Administrator Login Request
- 1 1:2003310 ET P2P Edonkey Publicize File
- 1 1:2012247 ET P2P BTWebClient UA uTorrent in use
- 1 1:2018959 ET POLICY PE EXE or DLL Windows file download HTTP
- 1 1:2003317 ET P2P Edonkey Search Request (any type file)
- 1 1:2014169 ET POLICY DNS Query for .su TLD (Soviet Union) Often Malware Related
- 1 1:2008052 ET MALWARE User-Agent (Internet Explorer)
- 1 1:2000340 ET P2P Kaaza Media desktop p2pnetworking.exe Activity
- 1 1:2002945 ET POLICY Java Url Lib User Agent Web Crawl
- Total
- 53527
- =========================================================================
- Top 50 All time Sguil Events
- =========================================================================
- Totals GenID:SigID Signature
- 34314 1:2101411 GPL SNMP public access udp
- 30837 1:2015898 ET INFO Suspicious Windows NT version 1 User-Agent
- 7848 1:2100368 GPL ICMP_INFO PING BSDtype
- 7846 1:2100366 GPL ICMP_INFO PING *NIX
- 7842 1:2100480 GPL ICMP_INFO PING speedera
- 7088 1:2008120 ET TFTP Outbound TFTP Read Request
- 2004 1:2000419 ET POLICY PE EXE or DLL Windows file download
- 943 1:2009702 ET POLICY DNS Update From External net
- 679 1:2013222 ET SHELLCODE Excessive Use of HeapLib Objects Likely Malicious Heap Spray Attempt
- 544 1:2012086 ET SHELLCODE Possible Call with No Offset TCP Shellcode
- 482 1:2016149 ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
- 449 1:2102650 GPL SQL user name buffer overflow attempt
- 406 1:2014726 ET POLICY Outdated Windows Flash Version IE
- 381 1:2016150 ET INFO Session Traversal Utilities for NAT (STUN Binding Response)
- 189 1:2003068 ET SCAN Potential SSH Scan OUTBOUND
- 187 1:2006380 ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted
- 182 1:2015744 ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
- 168 1:2017282 ET INFO Microsoft Script Encoder Encoded File
- 160 1:2101201 GPL WEB_SERVER 403 Forbidden
- 148 1:2102649 GPL SQL service_name buffer overflow attempt
- 125 1:2019707 ET WEB_CLIENT GENERIC VB ShellExecute Function Inside of VBSCRIPT tag
- 101 1:2010936 ET POLICY Suspicious inbound to Oracle SQL port 1521
- 100 1:2101424 GPL SHELLCODE x86 0xEB0C NOOP
- 98 1:2019401 ET POLICY Vulnerable Java Version 1.8.x Detected
- 92 1:2006402 ET POLICY Incoming Basic Auth Base64 HTTP Password detected unencrypted
- 78 1:2101390 GPL SHELLCODE x86 inc ebx NOOP
- 60 1:2008581 ET P2P BitTorrent DHT ping request
- 60 1:2014919 ET POLICY Microsoft Online Storage Client Hello TLSv1 Possible SkyDrive (1)
- 60 1:2014920 ET POLICY Microsoft Online Storage Client Hello TLSv1 Possible SkyDrive (2)
- 57 1:2001219 ET SCAN Potential SSH Scan
- 48 1:2014819 ET INFO Packed Executable Download
- 48 1:2015561 ET INFO PDF Using CCITTFax Filter
- 44 1:2002157 ET CHAT Skype User-Agent detected
- 44 1:2012087 ET SHELLCODE Possible Call with No Offset UDP Shellcode
- 41 1:2012888 ET POLICY Http Client Body contains pwd= in cleartext
- 40 1:2010517 ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)
- 38 1:2016360 ET INFO JAVA - ClassID
- 34 1:2010935 ET POLICY Suspicious inbound to MSSQL port 1433
- 32 1:2013273 ET SHELLCODE Hex Obfuscated JavaScript Heap Spray 41414141
- 31 1:2000418 ET POLICY Executable and linking format (ELF) file download
- 30 1:2103003 GPL NETBIOS SMB-DS Session Setup NTMLSSP unicode asn1 overflow attempt
- 20 1:2011582 ET POLICY Vulnerable Java Version 1.6.x Detected
- 19 1:2102466 GPL NETBIOS SMB-DS IPC$ unicode share access
- 19 1:2001330 ET POLICY RDP connection confirm
- 18 1:2001329 ET POLICY RDP connection request
- 16 1:2101892 GPL SNMP null community string attempt
- 16 1:2015743 ET INFO Revoked Adobe Code Signing Certificate Seen
- 16 1:2012887 ET POLICY Http Client Body contains pass= in cleartext
- 16 1:2014297 ET POLICY Vulnerable Java Version 1.7.x Detected
- 15 1:2001343 ET WEB_SERVER IIS ASP.net Auth Bypass / Canonicalization % 5 C
- Total
- 104308
- =========================================================================
- Top 50 URLs for yesterday
- =========================================================================
- Totals Signature
- Total
- 370953
- =========================================================================
- Last update
- =========================================================================
- Start-Date: 2017-09-18 14:17:05
- End-Date: 2017-09-18 14:17:05
- Start-Date: 2017-09-18 14:17:15
- Purge: ubiquity-frontend-gtk:amd64 (X.X.X.X)
- End-Date: 2017-09-18 14:17:15
- Start-Date: 2017-09-18 14:17:16
- End-Date: 2017-09-18 14:17:16
- =========================================================================
- Elasticsearch
- =========================================================================
- Elasticsearch is running.
- Cluster Name: "docker-cluster"
- Cluster Status: "green"
- Total Nodes: 1
- Failed Nodes: 0
- Total Indices: 1
- Total Shards: 1
- Total Documents: 530
- Total Size (in bytes): 0MB
- Free Memory: 1%
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-elasticsearch 2.37% 3.096GiB / 31.38GiB 9.87% 30.6kB / 59.6kB 160MB / 659MB 106
- =========================================================================
- Logstash
- =========================================================================
- Logstash is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-logstash 4.36% 2.644GiB / 31.38GiB 8.42% 3.51MB / 134kB 1.4GB / 596MB 187
- =========================================================================
- Kibana
- =========================================================================
- Kibana is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-kibana 0.00% 68.99MiB / 31.38GiB 0.21% 560kB / 563kB 75.5MB / 4.1kB 10
- =========================================================================
- ElastAlert
- =========================================================================
- ElastAlert is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-elastalert 1.54% 544KiB / 31.38GiB 0.00% 2.53MB / 2.52MB 2.96MB / 0B 2
- =========================================================================
- Curator
- =========================================================================
- Curator is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-curator 14.24% 6.559MiB / 31.38GiB 0.02% 96.2kB / 89.8kB 17.1MB / 0B 2
- =========================================================================
- Freq Server
- =========================================================================
- Freq_server is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-freqserver 0.20% 3.742MiB / 31.38GiB 0.01% 12kB / 0B 14.1MB / 0B 2
- Testing freq_server now...
- Freq Server is working
- =========================================================================
- Domain Stats
- =========================================================================
- Domain_stats is running.
- CONTAINER CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
- so-domainstats 0.47% 313.9MiB / 31.38GiB 0.98% 10.6kB / 0B 26.3MB / 0B 2
- Testing domain_stats now...
- Domain_stats is working
- =========================================================================
- Version Information
- =========================================================================
- Ubuntu 14.04.5 LTS
- securityonion-sostat 20120722-0ubuntu0securityonion74
Add Comment
Please, Sign In to add comment