HP-UX Host Intrusion Detection System Version 4.4 Administrator Guide (5900-1634, April 2011)

G Troubleshooting
This appendix describes various steps you can take in resolving problems on the agent and
administrative systems. This appendix addresses the following topics:
Agent and System Manager cannot communicate with each other” (page 209)
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds is present
(page 210)
Agent does not start on system boot (page 210)
Agent halts abnormally, leaving ids_* files and message queues (page 211)
Agent host appears to hang and/or you see message disk full (page 211)
Agent needs further troubleshooting (page 211)
Agent does not start after installation” (page 212)
Agents appear to be stuck in polling status (page 212)
Agent displays error if hostname to IP mapping is not registered in name service (page 212)
Aggregated alerts targets or details field are truncated and the same aggregated alert has
several entries logged in the IDS_ALERTFILE (page 212)
Alert date/time sort seems inconsistent (page 213)
Alerts are not being displayed in the alert browser” (page 213)
“Buffer overflow triggers false positives (page 213)
“Duplicate alerts appear in System Manager” (page 213)
“Getting several aggregated alerts for the same process (page 214)
“GUI runs out of memory after receiving around 19,000 alerts (page 214)
The idsadmin Command needs installed agent certificates (page 214)
The idsadmin Command notifies of bad certificate when pinging a remote agent” (page 214)
IDS_checkInstall fails with a kmtune error (page 215)
IDS_genAdminKeys or IDS_genAgentCerts does not complete successfully” (page 215)
IDS_genAdminKeys or idsgui quits early (page 215)
“Large files in /var/opt/ids (page 215)
“Log files are filling up (page 216)
“No Agent Available (page 216)
“Normal operation of an application generates heavy volume of alerts (page 216)
“Reflection X rlogin produces multiple login and logout alerts (page 216)
“Schedule Manager timetable screen appears to hang (page 217)
“SSH does not perform a clean exit after idsagent is started” (page 217)
“System Manager appears to hang (page 217)
“System Manager does not let you save files to specific directories (page 217)
“System Manager does not start after idsgui is started” (page 217)
“System Manager starts with no borders or title bar in X client programs on Windows
(page 218)
“System Manager times out on agent functions such as Activate and Status Poll” (page 218)
“UNKNOWN program and arguments in certain alert messages (page 218)
208 Troubleshooting