Platform-Specific Dashboard Details; Unix And Linux Systems; Windows Systems - Enterasys Intrusion Prevention System Reporting Manual

Analysis and reporting guide
Hide thumbs Also See for Intrusion Prevention System:
Table of Contents

Advertisement

Platform-Specific Dashboard Details

Platform-Specific Dashboard Details
This section provides details about how the various Enterasys IPS statistics available in the
Dashboard are gathered. In addition, differences between supported operating systems in how
this data is collected are detailed.

Unix and Linux Systems

Unix and Linux Enterasys IPS systems use dragonctl, system calls and platform-specific shell
scripts to provide system status information to Dashboard. The dragonctl process reports system
statistics, while the host sensor process reports sensor statistics.
System Status
The dragonctl process generates heartbeat events that contain system status. Dashboard uses these
heartbeat events to provide the following information:
System CPU used (percentage)
Total disk space available on the Dragon partition
Total disk space used on the Dragon partition
Total memory available on the system, in megabytes (MB)
Total memory used on the system, in megabytes (MB)
System uptime
Event rate from the system
Host Sensor Status
On Unix platforms, the Host Sensor is responsible for generating heartbeat events that contain
Host Sensor status information. Dashboard uses these heartbeat events to report the following
information:
Host Sensor uptime
Host Sensor event rate
Host Sensor CPU usage
Host Sensor memory used
Total system memory

Windows Systems

On Windows systems, the Host Sensor process generates heartbeat events that provide both
system and Host Sensor status information to the System Dashboard.
2-20 Enterasys IPS Analysis and Reporting Guide
Note: Unix CPU Used values are averaged from snapshot measurements and may differ from the
output of running the top command.
Note: On Windows systems, if the Host Sensor (DragonSquire Services) is not running, both
System Status and Host Sensor Status will be unavailable in the System Dashboard. This is
because the Host Sensor generates both sets of data for Windows systems.
System Dashboard

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Intrusion Prevention System and is the answer not in the manual?

Questions and answers

Table of Contents