store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 25, 2013 8:27 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 
Author Message
 Post subject: High CPU usage ossec-syscheckd
Unread postPosted: Thu Aug 02, 2012 12:02 pm 
Offline
Forum User
Forum User

Joined: Wed Jul 20, 2011 4:17 am
Posts: 16
Location: Eastbourne
Hello All

Our dedicated server looks to be getting overloaded by ossec-syscheckd. Any ideas of a solution?
Code:
Cpu(s): 25.1%us,  1.4%sy,  0.0%ni, 73.4%id,  0.1%wa,  0.0%hi,  0.0%si,  0.0%st
Mem:   4117376k total,  3907256k used,   210120k free,   185028k buffers
Swap:  2040244k total,    98824k used,  1941420k free,  2787248k cached

  PID USER      PR  NI  VIRT  RES  SHR S %CPU %MEM    TIME+  COMMAND
25279 root      20   0  8488 7360  604 R 100.0  0.2 335:51.63 ossec-syscheckd
 6109 root      39  19     0    0    0 S  2.4  0.0   4010:01 kipmi0
26717 apache    20   0  139m  74m 5100 S  0.7  1.9   0:00.10 httpd
25264 ossec     20   0  3512 2272  620 S  0.6  0.1  22:23.67 ossec-analysisd


Kind regards

Graham

_________________
Professional Insurance Agents ltd.


Top
 Profile  
 
 Post subject: Re: High CPU usage ossec-syscheckd
Unread postPosted: Thu Aug 02, 2012 1:03 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
It could be many things, so we've put together FAQ to help you with this:

https://www.atomicorp.com/wiki/index.ph ... lot_of_CPU

Please let us know how we can assist you.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: High CPU usage ossec-syscheckd
Unread postPosted: Fri Aug 03, 2012 7:09 am 
Offline
Forum User
Forum User

Joined: Wed Jul 20, 2011 4:17 am
Posts: 16
Location: Eastbourne
Many Thanks

I have added the line below running tests now looks promising.

Code:
<ignore>/var/log</ignore>


How frequently does the setting file get over written?

Kind regards,

Graham

_________________
Professional Insurance Agents ltd.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group