1855696 Members
6112 Online
104103 Solutions
New Discussion

HIDS "idscor" process

 
SOLVED
Go to solution
Andrew Pollard
Super Advisor

HIDS "idscor" process

Hi,

I am currently testing HIDS on our Production systems and there is a process called "idscor" that is at the very top of my "glance" process list.
Can someone tell me what "idscor" is and how I can lower it in the process list. Would "renice" be OK?
Thanks
Andrew Pollard
3 REPLIES 3
Uday_S_Ankolekar
Honored Contributor
Solution

Re: HIDS "idscor" process

Andrew Pollard
Super Advisor

Re: HIDS "idscor" process

Hi Uday,

Thanks for the info. I followed one suggestion in that document, and changed the value of "IDDS_MODE" to 3. The "idscor" process is still at the top of the process table, I guess I will need to upgrade to v3 when it is ready.
I am also getting the error:
KernelDSP: idskerndsp: Droping audit records due to heavy load.
Do you know if this is because of v2.2 and will go away after upgrading to v3?
Thanks
Andrew Pollard
Pierre Pasturel
Respected Contributor

Re: HIDS "idscor" process

Andrew -

The high CPU usage of idscor was addressed by HIDS v3.0, which was available last December. We have recently posted V3.1 on software.hp.com that fixes some V3.0 defects. You should see significant CPU usage improvement with V3.1.

The Race Condition template is still CPU intensive, so do not schedule this template initially. The Buffer Overflow template is no longer CPU intensive as it was in V2.2.

You can still get the "dropping audit records" message under heavy loads but it is less likely to happen with V3.1.

I encourage you to read the Admin Guide (AG) that describes the new syntax for specifying template properties and describes new filtering template properties (See appendix A). Also refer to the troubleshooting section in Appendix G and the Release Notes (RN) for V3.1. The RN and AG are both available on docs.hp.com.

Pierre