HP-UX Host Intrusion Detection System Version 4.7 Administrator Guide HP-UX 11i v3 (766144-001, March 2014)

G Troubleshooting
This appendix describes various steps you can take in resolving problems on the agent and
administrative systems. This appendix addresses the following topics:
Agent and System Manager cannot communicate with each other (page 204)
Agent complains that idds has not been enabled, yet lsdev shows /dev/idds is present”
(page 205)
Agent does not start on system boot” (page 205)
Agent halts abnormally, leaving ids_* files and message queues (page 206)
Agent host appears to hang and/or you see message disk full (page 206)
Agent needs further troubleshooting (page 206)
Agent does not start after installation (page 207)
Agents appear to be stuck in polling status (page 207)
Agent displays error if hostname to IP mapping is not registered in name service (page 207)
Aggregated alerts targets or details field are truncated and the same aggregated alert has
several entries logged in the IDS_ALERTFILE (page 207)
Alert date/time sort seems inconsistent” (page 208)
Alerts are not being displayed in the alert browser (page 208)
“Buffer overflow triggers false positives (page 208)
“Duplicate alerts appear in System Manager” (page 208)
“Getting several aggregated alerts for the same process (page 209)
“GUI runs out of memory after receiving around 19,000 alerts (page 209)
“The idsadmin Command needs installed agent certificates (page 209)
“The idsadmin Command notifies of bad certificate when pinging a remote agent” (page 209)
IDS_checkInstall fails with a kmtune error” (page 210)
IDS_genAdminKeys or IDS_genAgentCerts does not complete successfully” (page 210)
IDS_genAdminKeys or idsgui quits early (page 210)
“Large files in /var/opt/ids (page 210)
“Log files are filling up” (page 211)
“No Agent Available (page 211)
“Normal operation of an application generates heavy volume of alerts (page 211)
“Reflection X rlogin produces multiple login and logout alerts (page 211)
“Schedule Manager timetable screen appears to hang (page 212)
“SSH does not perform a clean exit after idsagent is started” (page 212)
“System Manager appears to hang” (page 212)
“System Manager does not let you save files to specific directories (page 212)
“System Manager does not start after idsgui is started” (page 212)
“System Manager starts with no borders or title bar in X client programs on Windows
(page 213)
“System Manager times out on agent functions such as Activate and Status Poll” (page 213)
“UNKNOWN program and arguments in certain alert messages (page 213)
203