Operating System - HP-UX
1834425 Members
1758 Online
110067 Solutions
New Discussion

Re: HIDS: Problems with GUI

 
TheJuiceman
Super Advisor

HIDS: Problems with GUI

I'm having a problem getting HIDS to come up via GUI. It was working before, but now it does not come up. I do not get any error messages on my screen. I have tried the tricks at the end of the following post with no success...

http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=973386

I have attached the guiError.log. I'm sure it is a security change that happened on the cell server. Does anyone have any ideas? Thanks.
9 REPLIES 9
Sudip Kumar Panda
New Member

Re: HIDS: Problems with GUI

Please provide us the following information : -

1. swlist -l product | grep -i Java
2. swlist HPUX-HIDS

Sudip Kumar Panda
New Member

Re: HIDS: Problems with GUI

Apart from the output of below commands,provide us var/opt/ids/gui/logs/Trace.log. Please make sure to run swverify on HIDS and Java bundles and ensure that no errors are shown.

swlist -l product | grep Java
swlist HPUX-HIDS
TheJuiceman
Super Advisor

Re: HIDS: Problems with GUI

swlist HPUX-HIDS

# HPUX-HIDS E.04.01.23 HP-UX Host IDS E.04.01
HPUX-HIDS.IDS E.04.01.23 HP-UX Host IDS E.04.01
HPUX-HIDS.IDS-KRN E.03.00.00 HP-UX Host IDS E.03.01

swlist -l product|grep -i Java
Jdk14 1.4.2.10.02 Java2 1.4 SDK
Jdk14 1.4.2.17.00 Java2 1.4 SDK
Jdk15 1.5.0.03.01 Java 1.5 JDK
Jdk15 1.5.0.11.00 Java 1.5 JDK
Joob 2.03.07 Java2 Out-of-box
Jre14 1.4.2.10.02 Java2 1.4 RTE
Jre14 1.4.2.17.00 Java2 1.4 RTE
Jre15 1.5.0.03.01 Java 1.5 JRE
Jre15 1.5.0.11.00 Java 1.5 JRE

swverify came back clean on everything
TheJuiceman
Super Advisor

Re: HIDS: Problems with GUI

Attached is the Trace.log. Thanks!!!
Sudip Kumar Panda
New Member

Re: HIDS: Problems with GUI

Thanks for providing required information. After looking at the guiError.log,I think there might be a problem in one of the group files under /etc/opt/ids/schedules/groups/. If possible, please provide the files under /etc/opt/ids/schedules/.

I work for HIDS product.
You can send these files to our support alias
ids9000-support@cup.hp.com
TheJuiceman
Super Advisor

Re: HIDS: Problems with GUI

I sent the requested info. Thanks!!!
TheJuiceman
Super Advisor

Re: HIDS: Problems with GUI

The gui will now open. But now I'm getting the following message...

"Skipping schedule /etc/opt/ids/schedules/Custom.txt due to parse error."

Then when HIDS opens, my Custom script is not there. Where can I check for a problem? Thanks again.
Pierre Pasturel
Respected Contributor

Re: HIDS: Problems with GUI

>I'm getting the following message...
>"Skipping schedule /etc/opt/ids/schedules/Custom.txt due to parse error."
>Where can I check for a problem?

Your best bet is to run the CLUI to attempt to activate your schedule, as the CLUI should give you a more informative message when there is a parsing error.

The sample output below from the CLUI, however, makes it obvious that we can improve the error messages so that both the file and offending line in the file are specified with a short explanation. Something on our list of enhancements.

That said...

For the output below, I modified one of my Surveillance Group's pathnames_1 template properties so that there was not a corresponding programs_1 entry:

> /opt/ids/bin/idsadmin --activate FileAndLoginMonitoringAlwaysOn
Wed Jul 30 16:02:15 2008: libtee: pid=3311 thread_id=1: ERROR: tmpl_files_progs_pairs_check: Unmatched files/progs list #1
Wed Jul 30 16:02:15 2008: libtee: pid=3311 thread_id=1: ERROR: tmpl_get_template_properties: Files/progs property error
ERROR: Unable to parse temp schedule file "/var/opt/ids/tmp/FileAndLoginMonitoringAlwaysOn.txt".
>

For this output, I added some bogus characters for a template property value:
> /opt/ids/bin/idsadmin --activate FileAndLoginMonitoringAlwaysOn
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_create_file_list_link: Regular expression error
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_list_store: Error creating property value file list link, line: "^/sbin/.*display$somejunkhereattheendoftheline"
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_create_files_group_link: string group error
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_list_store: Error creating property value file list link, line: "programs_1 | ^/usr/bin/nfsstat$ & ^/usr/sbin/syncer$ & ^/sbin/mount$ & ^/sbin/umount$ & ^/sbin/fs/.*/mount$ & ^/opt/cifsclient/bin/cifsmount$ & ^/sbin/fs/.*/umount$ & ^/opt/cifsclient/bin/cifsumount$ & ^/usr/bin/df$ & ^/usr/bin/bdf$ | ^/sbin/.*display$ some junk here at the end of the line"
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_files_progs_pairs_store: Error creating list, line: "programs_1 | ^/usr/bin/nfsstat$ & ^/usr/sbin/syncer$ & ^/sbin/mount$ & ^/sbin/umount$ & ^/sbin/fs/.*/mount$ & ^/opt/cifsclient/bin/cifsmount$ & ^/sbin/fs/.*/umount$ & ^/opt/cifsclient/bin/cifsumount$ & ^/usr/bin/df$ & ^/usr/bin/bdf$ | ^/sbin/.*display$ some junk here at the end of the line"
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_ro_line_process: Property values syntax error line: "programs_1 | ^/usr/bin/nfsstat$ & ^/usr/sbin/syncer$ & ^/sbin/mount$ & ^/sbin/umount$ & ^/sbin/fs/.*/mount$ & ^/opt/cifsclient/bin/cifsmount$ & ^/sbin/fs/.*/umount$ & ^/opt/cifsclient/bin/cifsumount$ & ^/usr/bin/df$ & ^/usr/bin/bdf$ | ^/sbin/.*display$ some junk here at the end of the line"
Wed Jul 30 16:15:32 2008: libtee: pid=3343 thread_id=1: ERROR: tmpl_get_template_properties: Processing error in property line: "programs_1 | ^/usr/bin/nfsstat$ & ^/usr/sbin/syncer$ & ^/sbin/mount$ & ^/sbin/umount$ & ^/sbin/fs/.*/mount$ & ^/opt/cifsclient/bin/cifsmount$ & ^/sbin/fs/.*/umount$ & ^/opt/cifsclient/bin/cifsumount$ & ^/usr/bin/df$ & ^/usr/bin/bdf$ | ^/sbin/.*display$ some junk here at the end of the line"
ERROR: Unable to parse temp schedule file "/var/opt/ids/tmp/FileAndLoginMonitoringAlwaysOn.txt".
>

The GUI also needs to be enhanced to better deal with these error conditions and give more informative error info. We have noted this for a future release.

Pierre

TheJuiceman
Super Advisor

Re: HIDS: Problems with GUI

Since the GUI is now working, I've decided to just redo the schedule. Thanks everyone for the help.