Honeypots mailing list archives
Re: X command and Lost client data
From: Edward Balas <ebalas () iu edu>
Date: Thu, 25 Mar 2004 08:37:28 -0500 (EST)
On Thu, 25 Mar 2004 tebodell () mchsi com wrote:
Back again folks :-/, So far i've tried to streamline setting up a sebek server and several sebek clients and i've run into the same thing everytime. The install process is pretty much flawless but when i start the client with accurate configuration and the server listening with sbk_upload (database schema and user is setup correctly). In the web interface the only record that ever occurs is the X Command and the pid corresponds to the X server of the sebek client. When the server is listening i also get a lot of Warning 5 RX Lost 4 with the numbers close to each other. Why do i only get the X server command and why is it losing so much data between the clients and server (there are no other hosts on this segment).
Can you provide a bit of background on the server you are using, including OS version and type of nic that you are collecting on. What is the CPUload on the box when you are doing this? Is the Sebek Client on a vmware host or physical host? What version of the sebek server are you using? Edward
Current thread:
- X command and Lost client data tebodell (Mar 25)
- Re: X command and Lost client data Edward Balas (Mar 25)
- <Possible follow-ups>
- Re: X command and Lost client data Andy Woods (Mar 25)
