HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
G Troubleshooting
This appendix describes various steps you can take in resolving problems on the agent and
administrative systems. This appendix addresses the following topics:
Agent and System Manager cannot communicate with each other (page 214)
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds is present”
(page 214)
Agent does not start on system boot” (page 214)
Agent halts abnormally, leaving ids_* files and message queues” (page 216)
Agent host appears to hang and/or you see message disk full (page 216)
Agent needs further troubleshooting” (page 216)
Agent does not start after installation” (page 216)
Agents appear to be stuck in polling status” (page 217)
Agent displays error if hostname to IP mapping is not registered in name service” (page 217)
Aggregated alerts targets or details field are truncated and the same aggregated alert has
several entries logged in the IDS_ALERTFILE (page 217)
Alert date/time sort seems inconsistent” (page 218)
Alerts are not being displayed in the alert browser (page 218)
“Buffer overflow triggers false positives” (page 218)
“Duplicate alerts appear in System Manager (page 218)
“Getting several aggregated alerts for the same process” (page 218)
“GUI runs out of memory after receiving around 19,000 alerts” (page 219)
“The idsadmin Command needs installed agent certificates” (page 219)
“The idsadmin Command notifies of bad certificate when pinging a remote agent” (page 219)
IDS_checkInstall fails with a kmtune error (page 220)
IDS_genAdminKeys or IDS_genAgentCerts does not complete successfully” (page 220)
IDS_genAdminKeys or idsgui quits early” (page 220)
“Large files in /var/opt/ids (page 220)
“Log files are filling up” (page 221)
“No Agent Available” (page 221)
“Normal operation of an application generates heavy volume of alerts” (page 221)
“Reflection X rlogin produces multiple login and logout alerts” (page 222)
“Schedule Manager timetable screen appears to hang” (page 222)
“SSH does not perform a clean exit after idsagent is started” (page 222)
“System Manager appears to hang” (page 222)
“System Manager does not let you save files to specific directories” (page 222)
“System Manager does not start after idsgui is started” (page 222)
“System Manager starts with no borders or title bar in X client programs on Windows”
(page 223)
“System Manager times out on agent functions such as Activate and Status Poll” (page 223)
“UNKNOWN program and arguments in certain alert messages” (page 223)
“Using HP-UX HIDS with IPFilter and SecureShell” (page 223)
“Unable to Generate Administrator Keys and Agent Certificates on PA–RISC 1.1 Systems”
(page 225)
Troubleshooting
This section describes a variety of potential problems and their solutions. To stay current with
product updates and patches, be sure to monitor the HP security software news and events web
site at www.hp.com/security.
Troubleshooting 213