npamnani
10/24/2019, 4:43 AMtimb
10/24/2019, 4:51 AM[ 984.078179] Call Trace:
[ 984.080639] __schedule+0x2bc/0x89b
[ 984.084134] schedule+0x36/0x7c
[ 984.087280] schedule_preempt_disabled+0xe/0x10
[ 984.091812] __mutex_lock.isra.5+0x20c/0x634
[ 984.096089] ? release_sock+0x8f/0x94
timb
10/24/2019, 4:52 AM[ 1106.935142] INFO: task systemd:1 blocked for more than 120 seconds.
npamnani
10/24/2019, 7:42 AMtimb
10/24/2019, 5:15 PM[
{"name":"audit_allow_config","value":"true"},
{"name":"audit_allow_fim_events","value":"false"},
{"name":"audit_allow_fork_process_events","value":"false"},
{"name":"audit_allow_process_events","value":"true"},
{"name":"audit_allow_selinux_events","value":"false"},
{"name":"audit_allow_sockets","value":"true"},
{"name":"audit_allow_unix","value":"false"},
{"name":"audit_allow_user_events","value":"true"},
{"name":"audit_debug","value":"false"},
{"name":"audit_fim_debug","value":"false"},
{"name":"audit_fim_show_accesses","value":"false"},
{"name":"audit_force_reconfigure","value":"false"},
{"name":"audit_force_unconfigure","value":"false"},
{"name":"audit_persist","value":"true"},
{"name":"audit_show_partial_fim_events","value":"false"},
{"name":"audit_show_untracked_res_warnings","value":"false"},
{"name":"disable_audit","value":"false"}
]
timb
10/24/2019, 5:16 PMtimb
10/24/2019, 5:16 PMtimb
10/24/2019, 5:17 PMtimb
10/24/2019, 5:18 PMtimb
10/24/2019, 5:27 PM$ sudo auditctl -s
enabled 1
failure 0
pid 26178
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
timb
10/24/2019, 5:47 PMtimb
10/24/2019, 5:48 PMnpamnani
10/24/2019, 6:09 PMtheopolis
timb
10/24/2019, 7:03 PMtimb
10/24/2019, 7:04 PMtimb
10/24/2019, 7:07 PM$ sudo auditctl -l;echo; sudo auditctl -s
-a always,exit -S connect
-a always,exit -S bind
-a always,exit -S execve
-a always,exit -S execveat
enabled 1
failure 0
pid 19405
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
osquery stopped:
$ sudo auditctl -l;echo; sudo auditctl -s
No rules
enabled 0
failure 1
pid 19405
rate_limit 0
backlog_limit 0
lost 0
backlog 0
loginuid_immutable 0 unlocked
timb
10/24/2019, 7:08 PM$ sudo auditctl -l;echo; sudo auditctl -s
-a always,exit -S connect
-a always,exit -S bind
-a always,exit -S execve
-a always,exit -S execveat
enabled 1
failure 0
pid 32732
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
timb
10/24/2019, 7:10 PMnpamnani
10/24/2019, 7:46 PMtimb
10/24/2019, 7:52 PMnpamnani
10/24/2019, 8:06 PMtimb
10/24/2019, 8:07 PMnpamnani
10/24/2019, 8:09 PMnpamnani
10/24/2019, 8:10 PMnpamnani
10/24/2019, 8:10 PMnpamnani
10/24/2019, 8:11 PMnpamnani
10/24/2019, 8:11 PMnpamnani
10/24/2019, 8:11 PMnpamnani
10/24/2019, 8:12 PMnpamnani
10/24/2019, 8:12 PMnpamnani
10/24/2019, 8:13 PMnpamnani
10/24/2019, 8:13 PMnpamnani
10/24/2019, 8:14 PMnpamnani
10/24/2019, 8:15 PMnpamnani
10/24/2019, 8:15 PMnpamnani
10/24/2019, 8:15 PMnpamnani
10/24/2019, 8:20 PMnpamnani
10/24/2019, 8:21 PMnpamnani
10/24/2019, 8:21 PMtimb
10/24/2019, 8:21 PMnpamnani
10/24/2019, 8:22 PMtimb
10/24/2019, 8:22 PMnpamnani
10/24/2019, 8:22 PMnpamnani
10/24/2019, 8:23 PMnpamnani
10/24/2019, 8:23 PMnpamnani
10/24/2019, 8:24 PMtimb
10/24/2019, 8:25 PMnpamnani
10/24/2019, 8:25 PMnpamnani
10/24/2019, 8:26 PMnpamnani
10/24/2019, 8:26 PMnpamnani
10/24/2019, 8:27 PMtimb
10/24/2019, 8:28 PMtheopolis
Ivanlei
10/25/2019, 4:46 PMnpamnani
10/27/2019, 7:30 AMnpamnani
10/27/2019, 7:34 AM