Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- =========================================================================
- Service Status
- =========================================================================
- so-autossh is running:
- 4344 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -o ExitOnForwardFailure yes -i /root/.ssh/securityonion -L 6050:localhost:6050 SO-user@X.X.X.X
- Status: HIDS
- * ossec_agent (SO-user)[ OK ]
- Status: Bro
- Name Type Host Status Pid Started
- logger logger localhost running 2892 19 Jun 19:58:00
- manager manager localhost running 3211 19 Jun 19:58:03
- proxy proxy localhost running 3405 19 Jun 19:58:05
- SO-server-ens224-1 worker localhost running 4066 19 Jun 19:58:08
- SO-server-ens224-2 worker localhost running 4068 19 Jun 19:58:08
- SO-server-ens224-3 worker localhost running 4070 19 Jun 19:58:08
- SO-server-ens224-4 worker localhost running 4072 19 Jun 19:58:08
- Status: SO-server-ens224
- * netsniff-ng (full packet data)[ OK ]
- * pcap_agent (SO-user)[ OK ]
- * snort_agent (SO-user)[ OK ]
- * suricata (alert data)[ OK ]
- * barnyard2 (spooler, unified2 format)[ OK ]
- =========================================================================
- Interface Status
- =========================================================================
- br-c6bb3a338335 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- UP BROADCAST MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- docker0 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- UP BROADCAST MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:0
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- ens160 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- inet addr:X.X.X.X Bcast:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/64 Scope:Link
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:50080 errors:0 dropped:0 overruns:0 frame:0
- TX packets:63590 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:3944684 (3.9 MB) TX bytes:364501785 (364.5 MB)
- ens192 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:12082 errors:0 dropped:0 overruns:0 frame:0
- TX packets:187 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:1477439 (1.4 MB) TX bytes:39250 (39.2 KB)
- ens224 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
- RX packets:50784979 errors:0 dropped:0 overruns:0 frame:0
- TX packets:184 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:42771942591 (42.7 GB) TX bytes:38224 (38.2 KB)
- ens256 Link encap:Ethernet HWaddr MM:MM:MM:MM:MM:MM
- UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
- RX packets:12081 errors:0 dropped:0 overruns:0 frame:0
- TX packets:185 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:1477943 (1.4 MB) TX bytes:38566 (38.5 KB)
- lo Link encap:Local Loopback
- inet addr:X.X.X.X Mask:X.X.X.X
- inet6 addr: X.X.X.X/128 Scope:Host
- UP LOOPBACK RUNNING MTU:65536 Metric:1
- RX packets:547758 errors:0 dropped:0 overruns:0 frame:0
- TX packets:547758 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:1274361446 (1.2 GB) TX bytes:1274361446 (1.2 GB)
- =========================================================================
- Link Statistics
- =========================================================================
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
- link/loopback MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1274361446 547758 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 1274361446 547758 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 0
- 2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 3944684 50080 0 0 0 18
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 364501785 63590 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- 3: ens192: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1477439 12082 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 39250 187 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- 4: ens224: <BROADCAST,MULTICAST,PROMISC,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 42771942591 50784979 0 0 0 82720
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 38224 184 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- 5: ens256: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 1477943 12081 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 38566 185 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- 6: br-c6bb3a338335: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- 7: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN mode DEFAULT group default
- link/ether MM:MM:MM:MM:MM:MM brd MM:MM:MM:MM:MM:MM
- RX: bytes packets errors dropped overrun mcast
- 0 0 0 0 0 0
- RX errors: length crc frame fifo missed
- 0 0 0 0 0
- TX: bytes packets errors dropped carrier collsns
- 0 0 0 0 0 0
- TX errors: aborted fifo window heartbeat transns
- 0 0 0 0 1
- =========================================================================
- Disk Usage
- =========================================================================
- Filesystem Size Used Avail Use% Mounted on
- udev 7,9G 0 7,9G 0% /dev
- tmpfs 1,6G 9,4M 1,6G 1% /run
- /dev/sda1 49G 8,4G 38G 19% /
- tmpfs 7,9G 0 7,9G 0% /dev/shm
- tmpfs 5,0M 0 5,0M 0% /run/lock
- tmpfs 7,9G 0 7,9G 0% /sys/fs/cgroup
- /dev/sdb 197G 169G 19G 90% /nsm
- tmpfs 1,6G 0 1,6G 0% /run/user/1001
- tmpfs 1,6G 4,0K 1,6G 1% /run/user/114
- tmpfs 1,6G 0 1,6G 0% /run/user/1000
- =========================================================================
- Network Sockets
- =========================================================================
- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
- syslog-ng 1343 root 7u IPv4 22635 0t0 TCP *:514 (LISTEN)
- syslog-ng 1343 root 8u IPv4 22636 0t0 UDP *:514
- syslog-ng 1343 root 25u IPv4 26418 0t0 TCP X.X.X.X:39723->X.X.X.X:6050 (ESTABLISHED)
- sshd 1791 root 3u IPv4 24049 0t0 TCP *:ssh_port (LISTEN)
- sshd 1791 root 4u IPv6 24051 0t0 TCP *:ssh_port (LISTEN)
- ntpd 2117 ntp 16u IPv6 26761 0t0 UDP *:123
- ntpd 2117 ntp 17u IPv4 26764 0t0 UDP *:123
- ntpd 2117 ntp 18u IPv4 26769 0t0 UDP X.X.X.X:123
- ntpd 2117 ntp 19u IPv4 26771 0t0 UDP X.X.X.X:123
- ntpd 2117 ntp 20u IPv6 26773 0t0 UDP [X.X.X.X]:123
- ntpd 2117 ntp 21u IPv6 26775 0t0 UDP [X.X.X.X]:123
- tclsh 2357 SO-user 3u IPv4 27716 0t0 TCP X.X.X.X:32845->X.X.X.X:7736 (ESTABLISHED)
- bro 2892 SO-user 4u IPv4 28928 0t0 UDP X.X.X.X:46458->X.X.X.X:53
- bro 2892 SO-user 19u IPv6 30772 0t0 TCP *:47761 (LISTEN)
- bro 2892 SO-user 22u IPv6 27160 0t0 TCP X.X.X.X:47761->X.X.X.X:37620 (ESTABLISHED)
- bro 2892 SO-user 24u IPv6 27177 0t0 TCP X.X.X.X:47761->X.X.X.X:37622 (ESTABLISHED)
- bro 2892 SO-user 25u IPv6 27301 0t0 TCP X.X.X.X:47761->X.X.X.X:37626 (ESTABLISHED)
- bro 2892 SO-user 26u IPv6 27302 0t0 TCP X.X.X.X:47761->X.X.X.X:37632 (ESTABLISHED)
- bro 2892 SO-user 27u IPv6 27303 0t0 TCP X.X.X.X:47761->X.X.X.X:37638 (ESTABLISHED)
- bro 2892 SO-user 29u IPv6 27304 0t0 TCP X.X.X.X:47761->X.X.X.X:37642 (ESTABLISHED)
- bro 3211 SO-user 4u IPv4 28001 0t0 UDP X.X.X.X:33275->X.X.X.X:53
- bro 3211 SO-user 18u IPv6 27158 0t0 TCP *:47762 (LISTEN)
- bro 3211 SO-user 19u IPv4 27159 0t0 TCP X.X.X.X:37620->X.X.X.X:47761 (ESTABLISHED)
- bro 3211 SO-user 20u IPv6 25458 0t0 TCP X.X.X.X:47762->X.X.X.X:53224 (ESTABLISHED)
- bro 3211 SO-user 21u IPv6 25580 0t0 TCP X.X.X.X:47762->X.X.X.X:53230 (ESTABLISHED)
- bro 3211 SO-user 22u IPv6 25581 0t0 TCP X.X.X.X:47762->X.X.X.X:53236 (ESTABLISHED)
- bro 3211 SO-user 23u IPv6 25582 0t0 TCP X.X.X.X:47762->X.X.X.X:53244 (ESTABLISHED)
- bro 3211 SO-user 24u IPv6 25583 0t0 TCP X.X.X.X:47762->X.X.X.X:53248 (ESTABLISHED)
- bro 3405 SO-user 4u IPv4 28023 0t0 UDP X.X.X.X:59952->X.X.X.X:53
- bro 3405 SO-user 18u IPv6 24255 0t0 TCP *:47763 (LISTEN)
- bro 3405 SO-user 19u IPv4 24256 0t0 TCP X.X.X.X:37622->X.X.X.X:47761 (ESTABLISHED)
- bro 3405 SO-user 20u IPv4 24257 0t0 TCP X.X.X.X:53224->X.X.X.X:47762 (ESTABLISHED)
- bro 3405 SO-user 21u IPv6 25579 0t0 TCP X.X.X.X:47763->X.X.X.X:37182 (ESTABLISHED)
- bro 3405 SO-user 22u IPv6 31049 0t0 TCP X.X.X.X:47763->X.X.X.X:37188 (ESTABLISHED)
- bro 3405 SO-user 23u IPv6 31050 0t0 TCP X.X.X.X:47763->X.X.X.X:37194 (ESTABLISHED)
- bro 3405 SO-user 24u IPv6 31051 0t0 TCP X.X.X.X:47763->X.X.X.X:37200 (ESTABLISHED)
- bro 4066 SO-user 4u IPv4 29084 0t0 UDP X.X.X.X:33534->X.X.X.X:53
- bro 4066 SO-user 18u IPv6 29117 0t0 TCP *:47764 (LISTEN)
- bro 4066 SO-user 19u IPv4 29118 0t0 TCP X.X.X.X:37642->X.X.X.X:47761 (ESTABLISHED)
- bro 4066 SO-user 20u IPv4 29119 0t0 TCP X.X.X.X:37200->X.X.X.X:47763 (ESTABLISHED)
- bro 4066 SO-user 21u IPv4 29120 0t0 TCP X.X.X.X:53248->X.X.X.X:47762 (ESTABLISHED)
- bro 4068 SO-user 4u IPv4 30017 0t0 UDP X.X.X.X:42163->X.X.X.X:53
- bro 4068 SO-user 18u IPv6 30042 0t0 TCP *:47765 (LISTEN)
- bro 4068 SO-user 19u IPv4 30043 0t0 TCP X.X.X.X:37632->X.X.X.X:47761 (ESTABLISHED)
- bro 4068 SO-user 20u IPv4 30044 0t0 TCP X.X.X.X:37188->X.X.X.X:47763 (ESTABLISHED)
- bro 4068 SO-user 21u IPv4 30046 0t0 TCP X.X.X.X:53236->X.X.X.X:47762 (ESTABLISHED)
- bro 4070 SO-user 4u IPv4 29087 0t0 UDP X.X.X.X:58660->X.X.X.X:53
- bro 4070 SO-user 18u IPv6 29106 0t0 TCP *:47766 (LISTEN)
- bro 4070 SO-user 19u IPv4 29107 0t0 TCP X.X.X.X:37626->X.X.X.X:47761 (ESTABLISHED)
- bro 4070 SO-user 20u IPv4 29108 0t0 TCP X.X.X.X:37182->X.X.X.X:47763 (ESTABLISHED)
- bro 4070 SO-user 21u IPv4 29109 0t0 TCP X.X.X.X:53230->X.X.X.X:47762 (ESTABLISHED)
- bro 4072 SO-user 4u IPv4 30020 0t0 UDP X.X.X.X:58657->X.X.X.X:53
- bro 4072 SO-user 18u IPv6 30049 0t0 TCP *:47767 (LISTEN)
- bro 4072 SO-user 19u IPv4 30050 0t0 TCP X.X.X.X:37638->X.X.X.X:47761 (ESTABLISHED)
- bro 4072 SO-user 20u IPv4 30051 0t0 TCP X.X.X.X:37194->X.X.X.X:47763 (ESTABLISHED)
- bro 4072 SO-user 21u IPv4 30052 0t0 TCP X.X.X.X:53244->X.X.X.X:47762 (ESTABLISHED)
- tclsh 4253 SO-user 3u IPv4 27347 0t0 TCP X.X.X.X:33827->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4271 SO-user 3u IPv4 24362 0t0 TCP X.X.X.X:39749->X.X.X.X:7736 (ESTABLISHED)
- tclsh 4271 SO-user 4u IPv4 24363 0t0 TCP X.X.X.X:8200 (LISTEN)
- tclsh 4271 SO-user 6u IPv4 24428 0t0 TCP X.X.X.X:8200->X.X.X.X:55402 (ESTABLISHED)
- barnyard2 4321 SO-user 3u IPv4 31286 0t0 TCP X.X.X.X:55402->X.X.X.X:8200 (ESTABLISHED)
- ssh 4345 root 3u IPv4 31269 0t0 TCP X.X.X.X:47234->X.X.X.X:ssh_port (ESTABLISHED)
- ssh 4345 root 4u IPv6 31283 0t0 TCP [X.X.X.X]:6050 (LISTEN)
- ssh 4345 root 5u IPv4 31284 0t0 TCP X.X.X.X:6050 (LISTEN)
- ssh 4345 root 6u IPv4 31285 0t0 TCP X.X.X.X:6050->X.X.X.X:39723 (ESTABLISHED)
- sshd 4642 root 3u IPv4 24575 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:37732 (ESTABLISHED)
- sshd 4667 SO-user 3u IPv4 24575 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:37732 (ESTABLISHED)
- sshd 4667 SO-user 9u IPv6 32806 0t0 TCP [X.X.X.X]:6010 (LISTEN)
- sshd 4667 SO-user 10u IPv4 32807 0t0 TCP X.X.X.X:6010 (LISTEN)
- sshd 19317 root 3u IPv4 58180 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:46928 (ESTABLISHED)
- sshd 19331 SO-user 3u IPv4 58180 0t0 TCP X.X.X.X:ssh_port->X.X.X.X:46928 (ESTABLISHED)
- sshd 19331 SO-user 9u IPv6 67795 0t0 TCP [X.X.X.X]:6011 (LISTEN)
- sshd 19331 SO-user 10u IPv4 67796 0t0 TCP X.X.X.X:6011 (LISTEN)
- =========================================================================
- IDS Rules Update
- =========================================================================
- mié jun 19 07:01:01 UTC 2019
- Backing up current local_rules.xml file.
- Cleaning up local_rules.xml backup files older than 30 days.
- Backing up current downloaded.rules file before it gets overwritten.
- Cleaning up downloaded.rules backup files older than 30 days.
- Backing up current local.rules file before it gets overwritten.
- Cleaning up local.rules backup files older than 30 days.
- Sleeping for 60 minutes to allow master time to download new rules.
- Copying rules from X.X.X.X.
- Restarting Barnyard2.
- Restarting: SO-server-ens224
- * stopping: barnyard2 (spooler, unified2 format)[ OK ]
- * starting: barnyard2 (spooler, unified2 format)[ OK ]
- Restarting IDS Engine.
- Restarting: SO-server-ens224
- * stopping: suricata (alert data)[ OK ]
- * starting: suricata (alert data)[ OK ]
- =========================================================================
- CPU Usage
- =========================================================================
- Load average for the last 1, 5, and 15 minutes:
- 3.12 4.99 4.87
- Processing units: 8
- If load average is higher than processing units,
- then tune until load average is lower than processing units.
- top - 20:28:09 up 30 min, 2 users, load average: 3,12, 4,99, 4,87
- Tasks: 259 total, 2 running, 157 sleeping, 0 stopped, 0 zombie
- %Cpu(s): 24,9 us, 5,9 sy, 0,1 ni, 54,3 id, 11,5 wa, 0,0 hi, 3,4 si, 0,0 st
- KiB Mem : 16425140 total, 275840 free, 3150744 used, 12998556 buff/cache
- KiB Swap: 998396 total, 998396 free, 0 used. 12820468 avail Mem
- %CPU %MEM COMMAND
- 103 5.7 suricata --user SO-user --group SO-user -c /etc/nsm/SO-server-ens224/suricata.yaml --af-packet=ens224 -l /nsm/sensor_data/SO-server-ens224
- 34.2 2.5 /opt/bro/bin/bro -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-3 local.bro broctl base/frameworks/cluster broctl/auto
- 34.1 2.6 /opt/bro/bin/bro -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-1 local.bro broctl base/frameworks/cluster broctl/auto
- 34.1 2.3 /opt/bro/bin/bro -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-2 local.bro broctl base/frameworks/cluster broctl/auto
- 34.0 2.3 /opt/bro/bin/bro -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-4 local.bro broctl base/frameworks/cluster broctl/auto
- 8.3 0.6 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p logger local.bro broctl base/frameworks/cluster broctl/auto
- 7.6 0.6 netsniff-ng --no-hwtimestamp -i ens224 -o /nsm/sensor_data/SO-server-ens224/dailylogs/2019-06-19/ --user 1001 --group 1001 -s --prefix snort.log. --verbose --ring-size 64MiB --interval 150MiB --mmap
- 4.9 0.6 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster broctl/auto
- 2.7 0.5 /opt/bro/bin/bro -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster broctl/auto
- 2.4 0.1 /usr/sbin/syslog-ng -F
- 1.6 0.0 barnyard2 -c /etc/nsm/SO-server-ens224/barnyard2.conf -u SO-user -g SO-user -d /nsm/sensor_data/SO-server-ens224 -f snort.unified2 -w /etc/nsm/SO-server-ens224/barnyard2.waldo -i SO-server-ens224 -U
- 1.0 0.0 /bin/bash /usr/sbin/sostat
- 0.6 0.0 [kswapd0]
- 0.5 0.0 /usr/bin/ssh -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -o ExitOnForwardFailure yes -i /root/.ssh/securityonion -L 6050:localhost:6050 SO-user@X.X.X.X
- 0.3 0.0 [ksoftirqd/1]
- 0.3 0.0 [jbd2/sdb-8]
- 0.2 0.0 [ksoftirqd/2]
- 0.2 0.0 [ksoftirqd/4]
- 0.2 0.0 [ksoftirqd/5]
- 0.2 0.0 [ksoftirqd/6]
- 0.2 0.0 [ksoftirqd/7]
- 0.2 0.0 tclsh /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-ens224/snort_agent.conf
- 0.1 0.0 /sbin/init splash
- 0.1 0.0 [ksoftirqd/3]
- 0.1 0.0 [kworker/u16:27]
- 0.1 0.0 [kworker/u16:0]
- 0.0 0.0 [kthreadd]
- 0.0 0.0 [kworker/0:0H]
- 0.0 0.0 [mm_percpu_wq]
- 0.0 0.0 [ksoftirqd/0]
- 0.0 0.0 [rcu_sched]
- 0.0 0.0 [rcu_bh]
- 0.0 0.0 [migration/0]
- 0.0 0.0 [watchdog/0]
- 0.0 0.0 [cpuhp/0]
- 0.0 0.0 [cpuhp/1]
- 0.0 0.0 [watchdog/1]
- 0.0 0.0 [migration/1]
- 0.0 0.0 [kworker/1:0H]
- 0.0 0.0 [cpuhp/2]
- 0.0 0.0 [watchdog/2]
- 0.0 0.0 [migration/2]
- 0.0 0.0 [kworker/2:0H]
- 0.0 0.0 [cpuhp/3]
- 0.0 0.0 [watchdog/3]
- 0.0 0.0 [migration/3]
- 0.0 0.0 [kworker/3:0H]
- 0.0 0.0 [cpuhp/4]
- 0.0 0.0 [watchdog/4]
- 0.0 0.0 [migration/4]
- 0.0 0.0 [kworker/4:0H]
- 0.0 0.0 [cpuhp/5]
- 0.0 0.0 [watchdog/5]
- 0.0 0.0 [migration/5]
- 0.0 0.0 [kworker/5:0H]
- 0.0 0.0 [cpuhp/6]
- 0.0 0.0 [watchdog/6]
- 0.0 0.0 [migration/6]
- 0.0 0.0 [kworker/6:0H]
- 0.0 0.0 [cpuhp/7]
- 0.0 0.0 [watchdog/7]
- 0.0 0.0 [migration/7]
- 0.0 0.0 [kworker/7:0H]
- 0.0 0.0 [kdevtmpfs]
- 0.0 0.0 [netns]
- 0.0 0.0 [rcu_tasks_kthre]
- 0.0 0.0 [kauditd]
- 0.0 0.0 [khungtaskd]
- 0.0 0.0 [oom_reaper]
- 0.0 0.0 [writeback]
- 0.0 0.0 [kcompactd0]
- 0.0 0.0 [ksmd]
- 0.0 0.0 [khugepaged]
- 0.0 0.0 [crypto]
- 0.0 0.0 [kintegrityd]
- 0.0 0.0 [kblockd]
- 0.0 0.0 [ata_sff]
- 0.0 0.0 [md]
- 0.0 0.0 [edac-poller]
- 0.0 0.0 [devfreq_wq]
- 0.0 0.0 [watchdogd]
- 0.0 0.0 [kworker/3:1]
- 0.0 0.0 [kworker/4:1]
- 0.0 0.0 [kworker/6:1]
- 0.0 0.0 [kworker/7:1]
- 0.0 0.0 [kworker/5:1]
- 0.0 0.0 [kworker/u17:0]
- 0.0 0.0 [ecryptfs-kthrea]
- 0.0 0.0 [kthrotld]
- 0.0 0.0 [acpi_thermal_pm]
- 0.0 0.0 [scsi_eh_0]
- 0.0 0.0 [scsi_tmf_0]
- 0.0 0.0 [scsi_eh_1]
- 0.0 0.0 [scsi_tmf_1]
- 0.0 0.0 [ipv6_addrconf]
- 0.0 0.0 [kstrp]
- 0.0 0.0 [charger_manager]
- 0.0 0.0 [mpt_poll_0]
- 0.0 0.0 [mpt/0]
- 0.0 0.0 [scsi_eh_2]
- 0.0 0.0 [scsi_tmf_2]
- 0.0 0.0 [scsi_eh_3]
- 0.0 0.0 [scsi_tmf_3]
- 0.0 0.0 [scsi_eh_4]
- 0.0 0.0 [scsi_tmf_4]
- 0.0 0.0 [scsi_eh_5]
- 0.0 0.0 [scsi_tmf_5]
- 0.0 0.0 [scsi_eh_6]
- 0.0 0.0 [scsi_tmf_6]
- 0.0 0.0 [scsi_eh_7]
- 0.0 0.0 [scsi_tmf_7]
- 0.0 0.0 [scsi_eh_8]
- 0.0 0.0 [scsi_tmf_8]
- 0.0 0.0 [scsi_eh_9]
- 0.0 0.0 [scsi_tmf_9]
- 0.0 0.0 [scsi_eh_10]
- 0.0 0.0 [scsi_tmf_10]
- 0.0 0.0 [scsi_eh_11]
- 0.0 0.0 [scsi_tmf_11]
- 0.0 0.0 [scsi_eh_12]
- 0.0 0.0 [scsi_tmf_12]
- 0.0 0.0 [scsi_eh_13]
- 0.0 0.0 [scsi_tmf_13]
- 0.0 0.0 [scsi_eh_14]
- 0.0 0.0 [scsi_tmf_14]
- 0.0 0.0 [scsi_eh_15]
- 0.0 0.0 [scsi_tmf_15]
- 0.0 0.0 [scsi_eh_16]
- 0.0 0.0 [scsi_tmf_16]
- 0.0 0.0 [scsi_eh_17]
- 0.0 0.0 [scsi_tmf_17]
- 0.0 0.0 [scsi_eh_18]
- 0.0 0.0 [scsi_tmf_18]
- 0.0 0.0 [scsi_eh_19]
- 0.0 0.0 [scsi_tmf_19]
- 0.0 0.0 [scsi_eh_20]
- 0.0 0.0 [scsi_tmf_20]
- 0.0 0.0 [scsi_eh_21]
- 0.0 0.0 [scsi_tmf_21]
- 0.0 0.0 [scsi_eh_22]
- 0.0 0.0 [scsi_tmf_22]
- 0.0 0.0 [scsi_eh_23]
- 0.0 0.0 [scsi_tmf_23]
- 0.0 0.0 [scsi_eh_24]
- 0.0 0.0 [scsi_tmf_24]
- 0.0 0.0 [scsi_eh_25]
- 0.0 0.0 [scsi_tmf_25]
- 0.0 0.0 [scsi_eh_26]
- 0.0 0.0 [scsi_tmf_26]
- 0.0 0.0 [scsi_eh_27]
- 0.0 0.0 [scsi_tmf_27]
- 0.0 0.0 [scsi_eh_28]
- 0.0 0.0 [scsi_tmf_28]
- 0.0 0.0 [scsi_eh_29]
- 0.0 0.0 [scsi_tmf_29]
- 0.0 0.0 [scsi_eh_30]
- 0.0 0.0 [scsi_tmf_30]
- 0.0 0.0 [scsi_eh_31]
- 0.0 0.0 [scsi_tmf_31]
- 0.0 0.0 [scsi_eh_32]
- 0.0 0.0 [scsi_tmf_32]
- 0.0 0.0 [ttm_swap]
- 0.0 0.0 [irq/16-vmwgfx]
- 0.0 0.0 [kworker/6:1H]
- 0.0 0.0 [kworker/3:1H]
- 0.0 0.0 [kworker/2:1H]
- 0.0 0.0 [kworker/4:1H]
- 0.0 0.0 [raid5wq]
- 0.0 0.0 [kworker/0:1H]
- 0.0 0.0 [kworker/5:1H]
- 0.0 0.0 [kworker/1:1H]
- 0.0 0.0 [jbd2/sda1-8]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 [kworker/7:1H]
- 0.0 0.0 [kworker/6:2]
- 0.0 0.0 /lib/systemd/systemd-journald
- 0.0 0.0 [iscsi_eh]
- 0.0 0.0 [ib-comp-wq]
- 0.0 0.0 [ib_mcast]
- 0.0 0.0 [ib_nl_sa_wq]
- 0.0 0.0 [rdma_cm]
- 0.0 0.0 /lib/systemd/systemd-udevd
- 0.0 0.0 [kworker/7:2]
- 0.0 0.0 [kworker/2:2]
- 0.0 0.0 /sbin/lvmetad -f
- 0.0 0.0 [kworker/1:2]
- 0.0 0.0 [kworker/0:2]
- 0.0 0.0 [ext4-rsv-conver]
- 0.0 0.0 /usr/sbin/atd -f
- 0.0 0.0 /usr/lib/accountsservice/accounts-daemon
- 0.0 0.0 /usr/sbin/acpid
- 0.0 0.0 /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation
- 0.0 0.0 /lib/systemd/systemd-logind
- 0.0 0.1 /usr/sbin/NetworkManager --no-daemon
- 0.0 0.0 /usr/sbin/cron -f
- 0.0 0.0 /sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan --syslog
- 0.0 0.0 /usr/lib/policykit-1/polkitd --no-debug
- 0.0 0.1 /usr/bin/python3 /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal
- 0.0 0.2 /usr/bin/containerd
- 0.0 0.0 /usr/sbin/sshd -D
- 0.0 0.4 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
- 0.0 0.0 /sbin/iscsid
- 0.0 0.0 /sbin/iscsid
- 0.0 0.0 /usr/sbin/lightdm
- 0.0 0.0 /usr/sbin/irqbalance --pid=/var/run/irqbalance.pid
- 0.0 0.0 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 111:118
- 0.0 0.2 /usr/lib/xorg/Xorg -core :0 -seat seat0 -auth /var/run/lightdm/root/:0 -nolisten tcp vt7 -novtswitch
- 0.0 0.0 /sbin/agetty --noclear tty1 linux
- 0.0 0.0 su - SO-user -- /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 /lib/systemd/systemd --user
- 0.0 0.0 (sd-pam)
- 0.0 0.0 tclsh /usr/bin/ossec_agent.tcl -o -f /var/ossec/logs/alerts/alerts.log -i X.X.X.X -p 5 -c /etc/nsm/ossec/ossec_agent.conf
- 0.0 0.0 lightdm --session-child 16 19
- 0.0 0.0 /lib/systemd/systemd --user
- 0.0 0.0 (sd-pam)
- 0.0 0.0 /bin/sh /usr/lib/lightdm/lightdm-greeter-session /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 tail -n 0 -F /var/ossec/logs/alerts/alerts.log
- 0.0 0.0 /usr/bin/dbus-daemon --fork --print-pid 5 --print-address 7 --session
- 0.0 0.3 /usr/sbin/lightdm-gtk-greeter
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi-bus-launcher --launch-immediately
- 0.0 0.0 /usr/lib/gvfs/gvfsd
- 0.0 0.0 /usr/bin/dbus-daemon --config-file=/etc/at-spi2/accessibility.conf --nofork --print-address 3
- 0.0 0.0 /usr/lib/at-spi2-core/at-spi2-registryd --use-gnome-session
- 0.0 0.0 lightdm --session-child 12 19
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p logger local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p manager local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro -1 -U .status -p broctl -p broctl-live -p local -p proxy local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro 6 -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-1 local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro 7 -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-2 local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro 6 -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-3 local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 bash /opt/bro/share/broctl/scripts/run-bro 7 -i af_packetX.X.X.Xens224 -U .status -p broctl -p broctl-live -p local -p SO-server-ens224-4 local.bro broctl base/frameworks/cluster broctl/auto
- 0.0 0.0 su - SO-user -- /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-ens224/pcap_agent.conf
- 0.0 0.0 tclsh /usr/bin/pcap_agent.tcl -c /etc/nsm/SO-server-ens224/pcap_agent.conf
- 0.0 0.0 su - SO-user -- /usr/bin/snort_agent.tcl -c /etc/nsm/SO-server-ens224/snort_agent.conf
- 0.0 0.0 tail -n 1 -f /nsm/sensor_data/SO-server-ens224/snort.stats
- 0.0 0.0 /usr/lib/autossh/autossh -M 0 -q -N -o ServerAliveInterval 60 -o ServerAliveCountMax 3 -o ExitOnForwardFailure yes -i /root/.ssh/securityonion -L 6050:localhost:6050 SO-user@X.X.X.X
- 0.0 0.0 sshd: SO-user [priv]
- 0.0 0.0 /lib/systemd/systemd --user
- 0.0 0.0 (sd-pam)
- 0.0 0.0 sshd: SO-user@pts/0
- 0.0 0.0 -bash
- 0.0 0.0 fish
- 0.0 0.0 [kworker/2:0]
- 0.0 0.0 [kworker/3:0]
- 0.0 0.0 [kworker/0:0]
- 0.0 0.0 [kworker/1:0]
- 0.0 0.0 [kworker/u16:2]
- 0.0 0.0 [kworker/4:0]
- 0.0 0.0 [kworker/5:0]
- 0.0 0.0 sshd: SO-user [priv]
- 0.0 0.0 sshd: SO-user@pts/1
- 0.0 0.0 [kworker/1:1]
- 0.0 0.0 [kworker/1:3]
- 0.0 0.0 -bash
- 0.0 0.0 fish
- 0.0 0.0 sudo sostat-redacted
- 0.0 0.0 /bin/bash /usr/sbin/sostat-redacted
- 0.0 0.0 ps -eo pcpu,pmem,args --sort -pcpu
- =========================================================================
- Packets received during last monitoring interval (600 seconds)
- =========================================================================
- Stats not yet available for ens224.
- Please wait until the current monitoring interval has completed.
- =========================================================================
- Packet Loss Stats
- =========================================================================
- NIC:
- ens224:
- RX packets:50784979 dropped:0 TX packets:184 dropped:0
- -------------------------------------------------------------------------
- pf_ring:
- -------------------------------------------------------------------------
- IDS Engine (suricata) packet drops:
- /nsm/sensor_data/SO-server-ens224/stats.log
- tcp.segment_memcap_drop | Total | 101
- -------------------------------------------------------------------------
- Bro:
- Average packet loss as percent across all Bro workers: 0.000000
- SO-server-ens224-1: 1560976089.989201 recvd=10832116 dropped=0 link=10832116
- SO-server-ens224-2: 1560976089.996037 recvd=14016446 dropped=0 link=14016446
- SO-server-ens224-3: 1560976090.004580 recvd=14827989 dropped=0 link=14827989
- SO-server-ens224-4: 1560976090.015636 recvd=11108593 dropped=0 link=11108593
- Capture Loss:
- SO-server-ens224-1: 1.540934
- 1.549479
- 1.700134
- 1.705217
- SO-server-ens224-2: 1.540934
- 1.549479
- 1.700134
- 1.705217
- SO-server-ens224-3: 1.540934
- 1.549479
- 1.700134
- 1.705217
- SO-server-ens224-4: 1.540934
- 1.549479
- 1.700134
- 1.705217
- If you are seeing capture loss without dropped packets, this
- may indicate that an upstream device is dropping packets (tap or SPAN port).
- -------------------------------------------------------------------------
- Netsniff-NG:
- This may take a second...
- Percentage of packets dropped:
- /var/log/nsm/SO-server-ens224/netsniff-ng.log -- .39
- =========================================================================
- PF_RING
- =========================================================================
- PF_RING Version : 6.6.0 (unknown)
- Total rings : 0
- Standard (non ZC) Options
- Ring slots : 4096
- Slot version : 16
- Capture TX : Yes [RX+TX]
- IP Defragment : No
- Socket Mode : Standard
- Cluster Fragment Queue : 0
- Cluster Fragment Discard : 0
- =========================================================================
- Log Archive
- =========================================================================
- /nsm/sensor_data/SO-server-ens160/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/SO-server-ens192/dailylogs/ - 0 days
- 4,0K .
- /nsm/sensor_data/SO-server-ens224/dailylogs/ - 1 days
- 167G .
- 167G ./2019-06-19
- /nsm/bro/logs/ - 1 days
- 327M .
- 323M ./2019-06-19
- 3,8M ./stats
- =========================================================================
- Last update
- =========================================================================
- Commandline: apt install sysstat
- Requested-By: SO-user (1000)
- Install: sysstat:amd64 (11.2.0-1ubuntu0.2)
- End-Date: 2019-06-14 19:23:23
- Start-Date: 2019-06-14 19:23:37
- Commandline: apt autoremove
- Requested-By: SO-user (1000)
- Remove: gir1.2-appindicator3-0.1:amd64 (12.10.1+16.04.20170215-0ubuntu1), libtimezonemap1:amd64 (0.4.5), gir1.2-timezonemap-1.0:amd64 (0.4.5), gir1.2-webkit2-4.0:amd64 (2.20.5-0ubuntu0.16.04.1), libtimezonemap-data:amd64 (0.4.5), gir1.2-nma-1.0:amd64 (1.2.6-0ubuntu0.16.04.4), gir1.2-javascriptcoregtk-4.0:amd64 (2.20.5-0ubuntu0.16.04.1)
- End-Date: 2019-06-14 19:23:38
- =========================================================================
- Available updates
- =========================================================================
- 46 packages can be updated.
- 28 updates are security updates.
- Run 'sudo soup' to install the latest updates.
- =========================================================================
- Version Information
- =========================================================================
- Ubuntu 16.04.6 LTS
- securityonion-sostat 20120722-0ubuntu0securityonion126
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement