<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS-ERROR in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403520#M747643</link>
    <description>Sanjay,&lt;BR /&gt;The link is not working.&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Scott, i am not traying to log buffer overflow.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 19 Oct 2004 14:49:06 GMT</pubDate>
    <dc:creator>David_711</dc:creator>
    <dc:date>2004-10-19T14:49:06Z</dc:date>
    <item>
      <title>IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403515#M747638</link>
      <description>HI, my idsagent report the following error:&lt;BR /&gt;Code: 10002&lt;BR /&gt;Message: kerneldsp:idskerndsp: Dropping audit records due to heavy load. First notice.&lt;BR /&gt;&lt;BR /&gt;What that mean?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot&lt;BR /&gt;David</description>
      <pubDate>Tue, 19 Oct 2004 12:31:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403515#M747638</guid>
      <dc:creator>David_711</dc:creator>
      <dc:date>2004-10-19T12:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403516#M747639</link>
      <description>Hi David,&lt;BR /&gt;&lt;BR /&gt;Looks like hp is still working on this issue, fix in the next version.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www2.itrc.hp.com/service/cki/search.do?category=c0&amp;amp;mode=id&amp;amp;searchString=8606337732&amp;amp;searchCrit=allwords&amp;amp;docType=Security&amp;amp;docType=Patch&amp;amp;docType=EngineerNotes&amp;amp;docType=BugReports&amp;amp;docType=Hardware&amp;amp;docType=ReferenceMaterials&amp;amp;docType=ThirdParty&amp;amp;search.x=24&amp;amp;search.y=8" target="_blank"&gt;http://www2.itrc.hp.com/service/cki/search.do?category=c0&amp;amp;mode=id&amp;amp;searchString=8606337732&amp;amp;searchCrit=allwords&amp;amp;docType=Security&amp;amp;docType=Patch&amp;amp;docType=EngineerNotes&amp;amp;docType=BugReports&amp;amp;docType=Hardware&amp;amp;docType=ReferenceMaterials&amp;amp;docType=ThirdParty&amp;amp;search.x=24&amp;amp;search.y=8&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;the doc id is 8606337732&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;regds&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Oct 2004 12:46:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403516#M747639</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2004-10-19T12:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403517#M747640</link>
      <description>Besides the obvious defect acknowledged, it would appear the system is too busy to keep up with data collection requirements.&lt;BR /&gt;&lt;BR /&gt;Consider filtering the data you collect and making it more precise and less broad.  HIDS can overload a server all by itself if configured to collect too much.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 19 Oct 2004 13:01:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403517#M747640</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-10-19T13:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403518#M747641</link>
      <description>This is caused by trying to Monitor buffer overflows.  All of the Literature I have see says turn this feature off and Set the kernel to not allow buffer overflows.  This will also reduce the amount of CPU the idsagent takes from the system.&lt;BR /&gt;&lt;BR /&gt;Sincerely&lt;BR /&gt;&lt;BR /&gt;--Scott Palmer</description>
      <pubDate>Tue, 19 Oct 2004 13:47:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403518#M747641</guid>
      <dc:creator>Scott Palmer_1</dc:creator>
      <dc:date>2004-10-19T13:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403519#M747642</link>
      <description>David -&lt;BR /&gt;&lt;BR /&gt;Performance improvements in V3.0 will reduce the chances of this happening.  And the performance of our race condition template and buffer overflow template in V3.0 has greatly improved, especially for the stack buffer overflow template.  A whitepaper on v3.0 performance will come out after we ship v3.0.&lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Oct 2004 14:49:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403519#M747642</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2004-10-19T14:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403520#M747643</link>
      <description>Sanjay,&lt;BR /&gt;The link is not working.&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Scott, i am not traying to log buffer overflow.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Oct 2004 14:49:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403520#M747643</guid>
      <dc:creator>David_711</dc:creator>
      <dc:date>2004-10-19T14:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403521#M747644</link>
      <description>Pierre,&lt;BR /&gt;What i can do to avoid this error in hids 2.2?&lt;BR /&gt;Do you have some information about it?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;David</description>
      <pubDate>Tue, 19 Oct 2004 15:21:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403521#M747644</guid>
      <dc:creator>David_711</dc:creator>
      <dc:date>2004-10-19T15:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403522#M747645</link>
      <description>David&lt;BR /&gt;&lt;BR /&gt;I noticed those errors in the current version of IDS when i had "Race condition attacks" and "buffer overflow attacks" selected in the template screen.  I did some searching on the web, and I found that there are serious performance Issues when these options are selected.  Specifically the idscor (correlation engine) was chewing up alot of CPU cycles.  I unselected both of these options, re-pushed the schedules, and low and behold I stopped getting the error message you reported.  I believe that the issue is that the idscor process was dropping these packets, but I am not 100% sure.  I currently am running IDS on an A class and and L class server and the idscor process experienced the same issues.&lt;BR /&gt;&lt;BR /&gt;Hope this sheds a bit of light.&lt;BR /&gt;&lt;BR /&gt;Sincerely&lt;BR /&gt;&lt;BR /&gt;--Scott Palmer</description>
      <pubDate>Tue, 19 Oct 2004 16:43:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403522#M747645</guid>
      <dc:creator>Scott Palmer_1</dc:creator>
      <dc:date>2004-10-19T16:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: IDS-ERROR</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403523#M747646</link>
      <description>David -&lt;BR /&gt;&lt;BR /&gt;Please refer to the Admin Guide Chapter 5 and the Section titled "Some Template Configuration Guidelines" on p. 74.  You want to avoid running the buffer overflow and race condition template in V2.x.&lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Oct 2004 14:01:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ids-error/m-p/3403523#M747646</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2004-10-20T14:01:35Z</dc:date>
    </item>
  </channel>
</rss>

