HP-UX Host Intrusion Detection System Version 4.1 Administrator's Guide

G Troubleshooting
This appendix describes various steps you can take in resolving problems on the agent
and administrative systems. This appendix addresses the following topics:
Agent and System Manager cannot communicate with each other (page 268)
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds is
present” (page 269)
Agent does not start on system boot” (page 269)
Agent halts abnormally, leaving ids_* files and message queues” (page 270)
Agent host appears to hang and/or you see message disk full” (page 270)
Agent needs further troubleshooting” (page 271)
Agent does not start after installation” (page 271)
Agents appear to be stuck in polling status” (page 271)
Aggregated alerts targets or details field are truncated and the same aggregated
alert has several entries logged in the IDS_ALERTFILE” (page 271)
Alert date/time sort seems inconsistent” (page 272)
Alerts are not being displayed in the alert browser (page 272)
“Buffer overflow triggers false positives” (page 273)
“Duplicate alerts appear in System Manager (page 273)
“Getting several aggregated alerts for the same process” (page 273)
“GUI runs out of memory after receiving around 19,000 alerts” (page 273)
“The idsadmin Command needs installed agent certificates” (page 273)
“The idsadmin Command notifies of bad certificate when pinging a remote agent”
(page 274)
“IDS_checkInstall fails with a kmtune error (page 274)
“IDS_genAdminKeys or IDS_genAgentCerts does not complete successfully”
(page 275)
“IDS_genAdminKeys or idsgui quits early” (page 275)
“Large files in /var/opt/ids” (page 275)
“Log files are filling up” (page 275)
“No Agent Available” (page 275)
“Normal operation of an application generates heavy volume of alerts” (page 276)
“Reflection X rlogin produces multiple login and logout alerts” (page 277)
“Schedule Manager timetable screen appears to hang” (page 277)
“SSH does not perform a clean exit after idsagent is started” (page 277)
“System Manager appears to hang” (page 277)
“System Manager does not let you save files to specific directories” (page 278)
“System Manager does not start after idsgui is started” (page 278)
“System Manager starts with no borders or title bar in X client programs on
Windows” (page 278)
267