- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: HIDS enhancements
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-04-2004 02:32 PM
11-04-2004 02:32 PM
HIDS enhancements
We are currently evaluating the HIDS product. I am a little concerned on system performance and the time it takes to have things reported.
From this below posting Pierre Pasturel (HP) has mentioned that the version 3 of the product will be available before the end of the year.
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=727910
I was wondering what list of enhancements and fixes are in the new version.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-04-2004 06:45 PM
11-04-2004 06:45 PM
Re: HIDS enhancements
here is a statement from Pierre from another post:
Here are the major improvements/enhancements in v3.0:
- Significant performance (throughput and CPU utilization) and scalability improvements.
- New template property syntax, full support of Unix regular expressions, and almost complete reduction of "Unknown" program alerts for better alert filtering capabilities.
- Support of idsadmin command line tool that now supports a new option to automate the pushing of schedules to remote agents.
- A toolkit of conversion utilities to migrate customized v2.x surveillance schedules to the new v3.0 schedule format in order to preserve existing deployment efforts
Regards
Rainer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2004 10:22 AM
11-07-2004 10:22 AM
Re: HIDS enhancements
I was also wanting to know what server requirements are needed to run this beast. I've browsed the release notes and there not really anything in there that gives this info.
amount of RAM
server level A class L class ??
From what I've been shown by my collegue, I'll wait for V3
There seems to be too many problems in it's current form to place this beast into production.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2004 12:23 PM
11-07-2004 12:23 PM
Re: HIDS enhancements
At Internet Security Class we did a full series of tests using D220 machines. I recall there was 512 MB of RAM. This was v 2.1
Fully configured to collect all data, the CPU was over 50% busy on the workstations that were configured as servers. We teamed up, one set up the client, the other set up the server.
What they recommended was that instead of trashing older hardware, take a workstation(maybe) or older server class box and make it a dedicated HIDS server.
While the response on the dedicated server was not great, the client boxes were able to function more or less normally. The overhead was not so bad.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2004 12:43 PM
11-07-2004 12:43 PM
Re: HIDS enhancements
From the performance I see (A400 1Gb RAM) the system is running 100% CPU ALL the time.
Mind you I did not set this up, but it certainly does not give me any warm and fuzzy feelings about rolling it out. There is nothing else on this system except for HIDS. At the moment I could not possibly approach my manager with a rollout plan until some of these performance issues are sorted.
In my previous posting, I should have included about how much grunt is required to run a client as well. Anyone got any ideas? I am looking at running somewhere in the vicinity of 30 clients.
Regards
Michael
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2004 02:57 PM
11-07-2004 02:57 PM
Re: HIDS enhancements
Both there and in class the performance of the server was substantially changed by what level of monitoring you set up.
Setting this up with 30 clients and maxmimum monitoring is going to eat up a lot of CPU and bandwidth.
If you can get a review of what is being monitored and make some intelligent choices as to what matters to your organization it can be done. Back in 2002 I sat in class with a few Admins from larger shops. They had dozens of HP-UX HIDS(i think it was called IDS then) connected to a K class server being the HIDS monitor box.
It was 100% CPU but it did keep up. I talked with tem after class and they fine tuned the monitoring.
If you throw enough CPU and memory at the problem, that will work too. I've been told by sources at HP, maybe Pierre that v3 does solve some of the performance problems of earlier versions.
You're in for some fun. Please zero point this. I seem to like the way my words look when posted tonight. Hope I helped a bit.
Good Luck,
Steve
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2004 09:26 AM
11-08-2004 09:26 AM
Re: HIDS enhancements
What I found out was that every single possible monitor was actually turned on ....
So I did the next best thing, turned everything off and selectively started turning things on. I now have a server that is running at less than 5% CPU. Now that I have it running in the manner that I should have expected in the first place, I'm going to turn on a few more monitors and deploy to a few more servers to see how it goes.
What was happening as well (before I turned the monitors off) was that many of the 'mock' alerts from me trying things were not getting logged at all.
Regards
Michael
(who looks like I'm learning HIDS whether I like it or not ;^)