<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS/9000 causes high CPU usage in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349333#M747052</link>
    <description>The best course of action is to set up filters and collect a subset of information. In Internet Security class we were able to stop IDS/9000 servers cold with a default or full data collection.&lt;BR /&gt;&lt;BR /&gt;If you drill in and collect only a subset of the data, CPU use on the server and client can be drastically reduced.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Wed, 04 Aug 2004 09:26:27 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-08-04T09:26:27Z</dc:date>
    <item>
      <title>IDS/9000 causes high CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349331#M747050</link>
      <description>Hi, &lt;BR /&gt; &lt;BR /&gt;We have six new rp4440-8 servers set-up with IDS/9000.  It's functioning correctly but the IDS process (on each machine) is taking up about 99% of one of the CPUs.  The second CPU is relatively idle.  The load average on all of the machines is about 0.5 with IDS running. &lt;BR /&gt; &lt;BR /&gt;We are receiving many errors of the following form: &lt;BR /&gt; &lt;BR /&gt;Code: 10002 &lt;BR /&gt;Message: KernelIDSP:idskerndsp: Dropping  &lt;BR /&gt;audit records due to heavy load. First  &lt;BR /&gt;notice. &lt;BR /&gt; &lt;BR /&gt;Followed a little later by: &lt;BR /&gt; &lt;BR /&gt;Code: 10002 &lt;BR /&gt;Message: KernelIDSP:idskerndsp: No longer  &lt;BR /&gt;dropping audit records. &lt;BR /&gt; &lt;BR /&gt;The machines are on their own network and are not running anything else. &lt;BR /&gt; &lt;BR /&gt;The second problem is that we are generating severity 1 filename mapping change alerts every so often.  Any idea what causes these events? &lt;BR /&gt; &lt;BR /&gt;Thanks, &lt;BR /&gt;Simon</description>
      <pubDate>Wed, 04 Aug 2004 09:19:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349331#M747050</guid>
      <dc:creator>Ian Little</dc:creator>
      <dc:date>2004-08-04T09:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: IDS/9000 causes high CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349332#M747051</link>
      <description>There are some known problems with CPU usage when using both the "buffer overflow" and "race condition" settings if used together.&lt;BR /&gt;&lt;BR /&gt;I believe the only workaround is to use only one of the above settings at a time.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;Kent M. Ostby&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Aug 2004 09:25:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349332#M747051</guid>
      <dc:creator>Kent Ostby</dc:creator>
      <dc:date>2004-08-04T09:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: IDS/9000 causes high CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349333#M747052</link>
      <description>The best course of action is to set up filters and collect a subset of information. In Internet Security class we were able to stop IDS/9000 servers cold with a default or full data collection.&lt;BR /&gt;&lt;BR /&gt;If you drill in and collect only a subset of the data, CPU use on the server and client can be drastically reduced.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 04 Aug 2004 09:26:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349333#M747052</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-08-04T09:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: IDS/9000 causes high CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349334#M747053</link>
      <description>Hi Ian just in case this maybe more than a coincidence &lt;BR /&gt;&lt;BR /&gt;do you know a simon james ... if yes have a quick chat with him as we are both investigating this issue.&lt;BR /&gt;&lt;BR /&gt;If not I'd await for version 3.0 or if you have a support contract with HP log a call so we can look into this in more detail.&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Aug 2004 11:28:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349334#M747053</guid>
      <dc:creator>Alex Glennie</dc:creator>
      <dc:date>2004-08-04T11:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: IDS/9000 causes high CPU usage</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349335#M747054</link>
      <description>Hello Simon,&lt;BR /&gt;&lt;BR /&gt;  Indeed early versions of HIDS have known performance limitations (especially when the Race Condition and Buffer Overflow templates are deployed).   The replies to your post have been correct in that it's best to set up filters to fine-tune the product's configuration and if possible to turn off these most resource intensive templates to improve performance.&lt;BR /&gt;&lt;BR /&gt;  That said, we have specifically addressed the performance and scalability concerns you raise in our upcoming v3.0 release of the product.   If you are interested in beta testing this release, the beta will be available in a matter of weeks (contact me for more information).   We are planning to make the final release later this calendar year and will be strongly recommending to our customers to upgrade to this version in order to take advantage of the redesigned template engine for dramatic performance improvements.   The new release will also have utilities available to ensure any custom configurations you've made in your existing installation wll be converted without loss for v3.0&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Stephanie&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Aug 2004 12:40:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-9000-causes-high-cpu-usage/m-p/3349335#M747054</guid>
      <dc:creator>Stephanie Miller</dc:creator>
      <dc:date>2004-08-25T12:40:09Z</dc:date>
    </item>
  </channel>
</rss>

