<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIDS CPU usage in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033776#M739872</link>
    <description>Hi Court -&lt;BR /&gt;&lt;BR /&gt;Just saw your post. It sounds like you were never successful in root causing the high CPU usage.  Information that would be helpful:&lt;BR /&gt;&lt;BR /&gt;1) The number of alerts being generated per minute, hr, day, or week. Before starting idsagent/idscor and the schedule, run wc -l /var/opt/ids/alert.log to see how many alerts you have. Then start the schedule and run top so you can detect when idscor chews up a CPU, at which point run wc -l /var/opt/ids/alert.log again and let me know  the number of new alerts and the time elapsed.   If the schedule is not tuned properly, you might be generating alerts at a high rate, and that can cause the high CPU usage by idscor from frequently constructing alert strings.&lt;BR /&gt;&lt;BR /&gt;2) The contents of /var/opt/ids/schedule on the agent where idscor is using up a CPU.&lt;BR /&gt;&lt;BR /&gt;3) The rate at which idscor is processing events between the time you start a schedule and when you see the CPU spike by idscor. See &lt;A href="http://docs.hp.com/en/5991-6776/apes03.html" target="_blank"&gt;http://docs.hp.com/en/5991-6776/apes03.html&lt;/A&gt; . So, you need to run top to keep an eye on idscor and wait until idscor spikes the CPU usage and then you need to look in /var/opt/ids/error.log where the event rate is captured. I also would like to know if the CPU does *not* spike when running idscor using the -t option.&lt;BR /&gt;&lt;BR /&gt;That should be enough to start root causing this. &lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
    <pubDate>Tue, 20 Mar 2007 15:41:42 GMT</pubDate>
    <dc:creator>Pierre Pasturel</dc:creator>
    <dc:date>2007-03-20T15:41:42Z</dc:date>
    <item>
      <title>HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033769#M739865</link>
      <description>OS: 11.11&lt;BR /&gt;HIDS B.04.00.01&lt;BR /&gt;Patch PHKL_34466 is installed&lt;BR /&gt;IDDS_MODE 3&lt;BR /&gt;&lt;BR /&gt;Religiously the HIDS idscor process will chew up one CPU. I usually stop and start the process to clear the situation. I have searched the forums but have found no resolution or reason as to why this is happening. Anyone have any ideas or insights?</description>
      <pubDate>Tue, 13 Mar 2007 15:14:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033769#M739865</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-03-13T15:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033770#M739866</link>
      <description>Check out the following forum&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=870556" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=870556&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;&lt;BR /&gt;Tommy</description>
      <pubDate>Tue, 13 Mar 2007 15:25:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033770#M739866</guid>
      <dc:creator>Tommy_6</dc:creator>
      <dc:date>2007-03-13T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033771#M739867</link>
      <description>Seen it but thanks.</description>
      <pubDate>Tue, 13 Mar 2007 15:27:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033771#M739867</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-03-13T15:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033772#M739868</link>
      <description>How about this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/7001/HIDS3.1SizingandTuningPrimer.pdf" target="_blank"&gt;http://docs.hp.com/en/7001/HIDS3.1SizingandTuningPrimer.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It mentions:&lt;BR /&gt;&lt;BR /&gt;For the majority of deployments, the performance bottleneck for HIDS will typically occur at CPU, primarily from the idscor process. The idscor process is multi-threaded and can therefore utilize over 100% CPU. HIDS will generally reach the CPU limit before other constraints such as disk or memory are realized.&lt;BR /&gt;&lt;BR /&gt;Tommy</description>
      <pubDate>Tue, 13 Mar 2007 15:36:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033772#M739868</guid>
      <dc:creator>Tommy_6</dc:creator>
      <dc:date>2007-03-13T15:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033773#M739869</link>
      <description>thanks for the pdf Tommy, but that is for an older version of HIDS.</description>
      <pubDate>Wed, 14 Mar 2007 12:57:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033773#M739869</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-03-14T12:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033774#M739870</link>
      <description>Closing thread as it seems no one has an answer. I guess I would have better luck figuring out how many licks it takes to get to the center of a tootsie roll tootsie pop.</description>
      <pubDate>Wed, 14 Mar 2007 12:59:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033774#M739870</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-03-14T12:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033775#M739871</link>
      <description>HIDS is an intrusion detection software.  Are you noticing any odd network traffic going to your server?  &lt;BR /&gt;&lt;BR /&gt;From &lt;A href="http://docs.hp.com/en/5991-6775/ch01s05.html" target="_blank"&gt;http://docs.hp.com/en/5991-6775/ch01s05.html&lt;/A&gt; are you noticing any of the following:&lt;BR /&gt;&lt;BR /&gt;Vulnerability:   Unauthorized File Modification&lt;BR /&gt; &lt;BR /&gt;Monitors:   Critical system and application programs and configuration files&lt;BR /&gt;&lt;BR /&gt;System and application log files&lt;BR /&gt;&lt;BR /&gt;File additions and deletion&lt;BR /&gt;&lt;BR /&gt;Critical files made world writable&lt;BR /&gt;&lt;BR /&gt;Privileged â  setuidâ   programs created&lt;BR /&gt;&lt;BR /&gt;Files modified by non-owners&lt;BR /&gt; &lt;BR /&gt;Vulnerability:   Poorly written privileged programs&lt;BR /&gt; &lt;BR /&gt;Monitors:   Buffer overflows and Race conditions&lt;BR /&gt; &lt;BR /&gt;Vulnerability:   Weak password or unauthorized access&lt;BR /&gt; &lt;BR /&gt;Monitors:   Logins/Logouts&lt;BR /&gt; &lt;BR /&gt;Vulnerability:   Password guessing&lt;BR /&gt; &lt;BR /&gt;Monitors:   Failed logins and failed su attempts&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Wed, 14 Mar 2007 15:11:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033775#M739871</guid>
      <dc:creator>Tommy_6</dc:creator>
      <dc:date>2007-03-14T15:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: HIDS CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033776#M739872</link>
      <description>Hi Court -&lt;BR /&gt;&lt;BR /&gt;Just saw your post. It sounds like you were never successful in root causing the high CPU usage.  Information that would be helpful:&lt;BR /&gt;&lt;BR /&gt;1) The number of alerts being generated per minute, hr, day, or week. Before starting idsagent/idscor and the schedule, run wc -l /var/opt/ids/alert.log to see how many alerts you have. Then start the schedule and run top so you can detect when idscor chews up a CPU, at which point run wc -l /var/opt/ids/alert.log again and let me know  the number of new alerts and the time elapsed.   If the schedule is not tuned properly, you might be generating alerts at a high rate, and that can cause the high CPU usage by idscor from frequently constructing alert strings.&lt;BR /&gt;&lt;BR /&gt;2) The contents of /var/opt/ids/schedule on the agent where idscor is using up a CPU.&lt;BR /&gt;&lt;BR /&gt;3) The rate at which idscor is processing events between the time you start a schedule and when you see the CPU spike by idscor. See &lt;A href="http://docs.hp.com/en/5991-6776/apes03.html" target="_blank"&gt;http://docs.hp.com/en/5991-6776/apes03.html&lt;/A&gt; . So, you need to run top to keep an eye on idscor and wait until idscor spikes the CPU usage and then you need to look in /var/opt/ids/error.log where the event rate is captured. I also would like to know if the CPU does *not* spike when running idscor using the -t option.&lt;BR /&gt;&lt;BR /&gt;That should be enough to start root causing this. &lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 20 Mar 2007 15:41:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hids-cpu-usage/m-p/5033776#M739872</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2007-03-20T15:41:42Z</dc:date>
    </item>
  </channel>
</rss>

