<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS9000 - idsagent: an error occurred parsing the schedule in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175745#M738892</link>
    <description>Hi all,&lt;BR /&gt;I am having problems with activating Survellance schedule in IDS9000. After renewing certificates i know get a parsing error. I have tried to do the renewing process again but without success. I have also searched the se forums but nothing have helped. I have checked with swlist -l fileset -a state to see if IDS is installed properly. Appreciate any help. Thanks&lt;BR /&gt;&lt;BR /&gt;Error messages:&lt;BR /&gt;- idsagent: an error occurred parsing the    &lt;BR /&gt;schedule&lt;BR /&gt;- idsagent: Surveillance Schedule does not contain any surveillance group periods&lt;BR /&gt;- syntax error on line 10 of schedule file /var/opt/ids/: error:syntax error&lt;BR /&gt;&lt;BR /&gt;My schedule file contains as follows:&lt;BR /&gt;&lt;BR /&gt;SCHEDULE Edi&lt;BR /&gt;GROUPPERIOD&lt;BR /&gt;NAME Edi&lt;BR /&gt;PRIORITY 0&lt;BR /&gt;SPECIFIEDTIME no&lt;BR /&gt;GMT 0&lt;BR /&gt;STARTTIME 0:00:0&lt;BR /&gt;ENDTIME 23:59:6&lt;BR /&gt;GROUP Edi&lt;BR /&gt;ENDGROUP&lt;BR /&gt;ENDGROUPPERIOD&lt;BR /&gt;ENDSCHEDULE&lt;BR /&gt;endOnly_files&lt;BR /&gt;ADD DATA ("appendonlyFiles", ["/var/adm/btmp", "/var/adm/wtmp", "/etc/btmp", "/etc/wtmp", "/var/adm/messages", "/var/adm/syslog/mail.log", "/var/adm/syslog/syslog.log", "/var/adm&lt;BR /&gt;/pacct", "/var/adm/sulog"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE megaReadOnly&lt;BR /&gt;ADD DATA ("read_only_files_to_watch", ["/stand/vmunix", "/stand/kernrel", "/stand/bootconf", "/etc/passwd", "/etc/group", "/.rhosts", "/.shosts", "/etc/hosts.equiv", "/etc/hosts.&lt;BR /&gt;allow", "/etc/hosts.deny", "/etc/inetd.conf"])&lt;BR /&gt;ADD DATA ("read_only_files_to_not_watch", ["/etc/ptmp", "/etc/.pwd.lock", "/etc/utmp", "/etc/utmpx", "/etc/rc.log", "/etc/lvmconf/lvm_lock"])&lt;BR /&gt;ADD DATA ("read_only_dirs_to_watch", ["/etc", "/bin", "/sbin", "/stand", "/lib", "/usr/bin", "/opt"])&lt;BR /&gt;ADD DATA ("read_only_dirs_to_not_watch", [" "])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE suid&lt;BR /&gt;ADD DATA ("criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE modify_non_owned_files&lt;BR /&gt;ADD DATA ("modify_files_to_not_watch", ["/dev/null", "/etc/rc.log", "/etc/lvmconf/lvm_lock", "/dev/diag"])&lt;BR /&gt;ADD DATA ("modify_dirs_to_not_watch", ["/var/opt/OV/tmp/OpC"])&lt;BR /&gt;ADD DATA ("modify_UIDs_to_ignore", [-314159])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE bufferOverflow&lt;BR /&gt;ADD DATA ("bufferOverflow_UIDList", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;ENDGROUP&lt;BR /&gt;ENDGROUPPERIOD&lt;BR /&gt;ENDSCHEDULE&lt;BR /&gt;not_watch", ["/dev/diag", "/var/spool/sockets/pwgr", "/dev/pts", "/tcb/files/auth", "/tmp/files", "/var/spool/cron/tmp", "/prog/cdftp/product/cd3500/work/st.sthk.unx.edib"])&lt;BR /&gt;ADD DATA ("modify_UIDs_to_ignore", [-314159])&lt;BR /&gt;ADD DATA ("modify_files_one", ["/var/adm/wtmp$", "/dev/tty$"])&lt;BR /&gt;ADD DATA ("modify_prog_one", ["/usr/lbin/rlogind", "/usr/bin/login"])&lt;BR /&gt;ADD DATA ("modify_files_two", ["/prog/signatur/local/profile/Statoil_&amp;lt;*&amp;gt;", "/prog/signatur/product/ediseq/etc/&amp;lt;*&amp;gt;"])&lt;BR /&gt;ADD DATA ("modify_prog_two", ["/prog/signatur/product/filedrive/bin/fdx", "/prog/signatur/product/entcmd-6_0/bin/entcmd", "/prog/signatur/product/ediseq/bin/cryptcli"])&lt;BR /&gt;ADD DATA ("modify_files_three", ["/var/spool/mqueue/&amp;lt;*&amp;gt;", "/var/tmp/sh&amp;lt;*&amp;gt;", "/prog/cdftp/product/cd3500/work/st.sthk.unx.edib/&amp;lt;*&amp;gt;", "/etc/lvmconf/lvm_lock", "/var/opt/ignite/loca&lt;BR /&gt;l/manifest/manifest.info", "/dev/pts/&amp;lt;*&amp;gt;"])&lt;BR /&gt;ADD DATA ("modify_prog_three", ["/usr/sbin/sendmail", "/prog/amtrix/packages/bin/whupstate.sh", "/prog/cdftp/product/cd3500/ndm/bin/ndmsmgr", "/prog/cdftp/product/cd3500/ndm/bin/&lt;BR /&gt;ndmcmgr", "/prog/cdftp/product/cd3500/ndm/bin/cdstatm", "/usr/sbin/vgdisplay", "/opt/ignite/binpa/print_manifest", "/opt/ssh2/sbin/sshd2"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE suid&lt;BR /&gt;ADD DATA ("criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE worldWritable&lt;BR /&gt;ADD DATA ("worldWritable_criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ADD DATA ("worldWritable_excludeFiles", ["/.dt.down", "/dev/pts/2", "/dev/pts/0"])&lt;BR /&gt;ADD DATA ("worldWritable_excludeDirs", ["/var/opt/scr/tmp", "/var/tmp"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE megaReadOnly&lt;BR /&gt;ADD DATA ("read_only_files_to_watch", ["/stand/vmunix", "/stand/kernrel", "/stand/bootconf", "/etc/passwd", "/etc/group", "/.rhosts", "/.shosts", "/etc/inetd.conf"])&lt;BR /&gt;</description>
    <pubDate>Tue, 08 Apr 2008 08:34:07 GMT</pubDate>
    <dc:creator>ejac</dc:creator>
    <dc:date>2008-04-08T08:34:07Z</dc:date>
    <item>
      <title>IDS9000 - idsagent: an error occurred parsing the schedule</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175745#M738892</link>
      <description>Hi all,&lt;BR /&gt;I am having problems with activating Survellance schedule in IDS9000. After renewing certificates i know get a parsing error. I have tried to do the renewing process again but without success. I have also searched the se forums but nothing have helped. I have checked with swlist -l fileset -a state to see if IDS is installed properly. Appreciate any help. Thanks&lt;BR /&gt;&lt;BR /&gt;Error messages:&lt;BR /&gt;- idsagent: an error occurred parsing the    &lt;BR /&gt;schedule&lt;BR /&gt;- idsagent: Surveillance Schedule does not contain any surveillance group periods&lt;BR /&gt;- syntax error on line 10 of schedule file /var/opt/ids/: error:syntax error&lt;BR /&gt;&lt;BR /&gt;My schedule file contains as follows:&lt;BR /&gt;&lt;BR /&gt;SCHEDULE Edi&lt;BR /&gt;GROUPPERIOD&lt;BR /&gt;NAME Edi&lt;BR /&gt;PRIORITY 0&lt;BR /&gt;SPECIFIEDTIME no&lt;BR /&gt;GMT 0&lt;BR /&gt;STARTTIME 0:00:0&lt;BR /&gt;ENDTIME 23:59:6&lt;BR /&gt;GROUP Edi&lt;BR /&gt;ENDGROUP&lt;BR /&gt;ENDGROUPPERIOD&lt;BR /&gt;ENDSCHEDULE&lt;BR /&gt;endOnly_files&lt;BR /&gt;ADD DATA ("appendonlyFiles", ["/var/adm/btmp", "/var/adm/wtmp", "/etc/btmp", "/etc/wtmp", "/var/adm/messages", "/var/adm/syslog/mail.log", "/var/adm/syslog/syslog.log", "/var/adm&lt;BR /&gt;/pacct", "/var/adm/sulog"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE megaReadOnly&lt;BR /&gt;ADD DATA ("read_only_files_to_watch", ["/stand/vmunix", "/stand/kernrel", "/stand/bootconf", "/etc/passwd", "/etc/group", "/.rhosts", "/.shosts", "/etc/hosts.equiv", "/etc/hosts.&lt;BR /&gt;allow", "/etc/hosts.deny", "/etc/inetd.conf"])&lt;BR /&gt;ADD DATA ("read_only_files_to_not_watch", ["/etc/ptmp", "/etc/.pwd.lock", "/etc/utmp", "/etc/utmpx", "/etc/rc.log", "/etc/lvmconf/lvm_lock"])&lt;BR /&gt;ADD DATA ("read_only_dirs_to_watch", ["/etc", "/bin", "/sbin", "/stand", "/lib", "/usr/bin", "/opt"])&lt;BR /&gt;ADD DATA ("read_only_dirs_to_not_watch", [" "])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE suid&lt;BR /&gt;ADD DATA ("criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE modify_non_owned_files&lt;BR /&gt;ADD DATA ("modify_files_to_not_watch", ["/dev/null", "/etc/rc.log", "/etc/lvmconf/lvm_lock", "/dev/diag"])&lt;BR /&gt;ADD DATA ("modify_dirs_to_not_watch", ["/var/opt/OV/tmp/OpC"])&lt;BR /&gt;ADD DATA ("modify_UIDs_to_ignore", [-314159])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE bufferOverflow&lt;BR /&gt;ADD DATA ("bufferOverflow_UIDList", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;ENDGROUP&lt;BR /&gt;ENDGROUPPERIOD&lt;BR /&gt;ENDSCHEDULE&lt;BR /&gt;not_watch", ["/dev/diag", "/var/spool/sockets/pwgr", "/dev/pts", "/tcb/files/auth", "/tmp/files", "/var/spool/cron/tmp", "/prog/cdftp/product/cd3500/work/st.sthk.unx.edib"])&lt;BR /&gt;ADD DATA ("modify_UIDs_to_ignore", [-314159])&lt;BR /&gt;ADD DATA ("modify_files_one", ["/var/adm/wtmp$", "/dev/tty$"])&lt;BR /&gt;ADD DATA ("modify_prog_one", ["/usr/lbin/rlogind", "/usr/bin/login"])&lt;BR /&gt;ADD DATA ("modify_files_two", ["/prog/signatur/local/profile/Statoil_&amp;lt;*&amp;gt;", "/prog/signatur/product/ediseq/etc/&amp;lt;*&amp;gt;"])&lt;BR /&gt;ADD DATA ("modify_prog_two", ["/prog/signatur/product/filedrive/bin/fdx", "/prog/signatur/product/entcmd-6_0/bin/entcmd", "/prog/signatur/product/ediseq/bin/cryptcli"])&lt;BR /&gt;ADD DATA ("modify_files_three", ["/var/spool/mqueue/&amp;lt;*&amp;gt;", "/var/tmp/sh&amp;lt;*&amp;gt;", "/prog/cdftp/product/cd3500/work/st.sthk.unx.edib/&amp;lt;*&amp;gt;", "/etc/lvmconf/lvm_lock", "/var/opt/ignite/loca&lt;BR /&gt;l/manifest/manifest.info", "/dev/pts/&amp;lt;*&amp;gt;"])&lt;BR /&gt;ADD DATA ("modify_prog_three", ["/usr/sbin/sendmail", "/prog/amtrix/packages/bin/whupstate.sh", "/prog/cdftp/product/cd3500/ndm/bin/ndmsmgr", "/prog/cdftp/product/cd3500/ndm/bin/&lt;BR /&gt;ndmcmgr", "/prog/cdftp/product/cd3500/ndm/bin/cdstatm", "/usr/sbin/vgdisplay", "/opt/ignite/binpa/print_manifest", "/opt/ssh2/sbin/sshd2"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE suid&lt;BR /&gt;ADD DATA ("criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE worldWritable&lt;BR /&gt;ADD DATA ("worldWritable_criticalUIDs", [0, 1, 2, 3, 4, 5, 9, 11])&lt;BR /&gt;ADD DATA ("worldWritable_excludeFiles", ["/.dt.down", "/dev/pts/2", "/dev/pts/0"])&lt;BR /&gt;ADD DATA ("worldWritable_excludeDirs", ["/var/opt/scr/tmp", "/var/tmp"])&lt;BR /&gt;ENDTEMPLATE&lt;BR /&gt;TEMPLATE megaReadOnly&lt;BR /&gt;ADD DATA ("read_only_files_to_watch", ["/stand/vmunix", "/stand/kernrel", "/stand/bootconf", "/etc/passwd", "/etc/group", "/.rhosts", "/.shosts", "/etc/inetd.conf"])&lt;BR /&gt;</description>
      <pubDate>Tue, 08 Apr 2008 08:34:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175745#M738892</guid>
      <dc:creator>ejac</dc:creator>
      <dc:date>2008-04-08T08:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: IDS9000 - idsagent: an error occurred parsing the schedule</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175746#M738893</link>
      <description>Additional error messages:&lt;BR /&gt;Unable to open data store file for login_logout&lt;BR /&gt;&lt;BR /&gt;Unable to open fact store file for login_logout&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 08 Apr 2008 09:13:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175746#M738893</guid>
      <dc:creator>ejac</dc:creator>
      <dc:date>2008-04-08T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: IDS9000 - idsagent: an error occurred parsing the schedule</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175747#M738894</link>
      <description>Hi Ejac,&lt;BR /&gt;&lt;BR /&gt;It seems you are using HIDS v2.2 or even older version which is a very old one and not a supported version by HP anymore. We have HIDS v4.1 currently available to customers with lots of improvements compared to HIDS v2.2 which I am listing below. &lt;BR /&gt;&lt;BR /&gt;- Huge performance improvement ( at least 2  times faster in processing )and less CPU consumption&lt;BR /&gt;- Huge alert volume reduction ( at least 5 times lesser compared to v2.2 ) with the help of alert aggregation and duplicate alert suppression features. &lt;BR /&gt;- Auto configuration tool which helps customers configure HIDS easily.&lt;BR /&gt;- Reporting features to generate alert reports based on uid, severity, date, etc..&lt;BR /&gt;- Many critical defect fixes&lt;BR /&gt;&lt;BR /&gt;I suggest you to consider moving to HIDS v4.1 as it would provide you the benifits mentioned above over HIDS v2.2. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;You can download HIDS v4.2 from the following link :&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;please search for "ids" here.&lt;BR /&gt;&lt;BR /&gt;We may be able to provide any help you may require in installing and configuring HIDS v4.1. &lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Vara&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Apr 2008 04:46:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175747#M738894</guid>
      <dc:creator>varap</dc:creator>
      <dc:date>2008-04-09T04:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: IDS9000 - idsagent: an error occurred parsing the schedule</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175748#M738895</link>
      <description>You can download HIDS v4.2 from the following link :&lt;BR /&gt;&lt;BR /&gt;Please read the above sentence as &lt;BR /&gt;&lt;BR /&gt;"You can download HIDS v4.1 from the following link :"&lt;BR /&gt;&lt;BR /&gt;Vara</description>
      <pubDate>Wed, 09 Apr 2008 04:49:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids9000-idsagent-an-error-occurred-parsing-the-schedule/m-p/4175748#M738895</guid>
      <dc:creator>varap</dc:creator>
      <dc:date>2008-04-09T04:49:14Z</dc:date>
    </item>
  </channel>
</rss>

