Host Intrusion Detection System Administrator's Guide Release 3.1

Troubleshooting
Summary
Appendix G
244
Summary
This appendix describes various steps you can take in resolving problems on the agent
and administrative systems. The topics are:
Agent and System Manager cannot communicate with each other” on page 246
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds is
present” on page 247
Agent does not start on system boot” on page 247
Agent halts abnormally, leaving ids_* files and message queues” on page 248
Agent host appears to hang and/or you see message “disk full”” on page 248
Agent needs further troubleshooting” on page 248
Agent does not start after installation” on page 249
Agents appear to be stuck in polling status” on page 249
Alert date/time sort seems inconsistent” on page 249
Alerts are not being displayed in the alert browser” on page 249
“Duplicate alerts appear in System Manager” on page 250
“Buffer overflow triggers false positives” on page 250
“Idsadmin needs installed agent certificates” on page 250
“Idsadmin notifies of bad certificate when pinging a remote agent” on page 250
“IDS_checkInstall fails with a kmtune error” on page 251
“IDS_genAdminKeys or IDS_genAgentCerts does not complete successfully” on
page 251
“IDS_genAdminKeys or idsgui quits early” on page 251
“Large files in /var/opt/ids” on page 252
“Log files are filling up” on page 252
“No Agent Available” on page 252
“Normal operation of an application generates heavy volume of alerts” on page 253
“Reflection X rlogin produces multiple login and logout alerts” on page 253
“Schedule Manager timetable screen appears to hang” on page 254
“SSH does not perform a clean exit after idsgent is started” on page 254
“System Manager appears to hang” on page 254
“System Manager does not let you save files to specific directories” on page 254
“System Manager does not start after idsgui is started” on page 254
“System Manager starts with no borders or title bar in X client programs on
Windows” on page 255