Relatório Semanal U&M InvestLinux –...
Transcript of Relatório Semanal U&M InvestLinux –...
Relatório Semanal U&M InvestLinux – 26/04/2016
Servidores LinuxUptime / Last
Uptime (Tempo Online do Servidor) Last (Conexões remotas)
[root@uemgw]# uptime 06:56:36 up 146 days, 18:14, 4 users, load average: 0.21, 0.24, 0.27
[root@uemadm]# uptime 06:56:31 up 339 days, 12:16, 2 users, load average: 0.31, 0.22, 0.21
[root@uemgw]# last | sort k 3 | morevpnuem ppp0 177.174.106.130 Sat Apr 16 12:55 12:56 (00:01) vpnuem ppp2 177.174.14.123 Sun Apr 10 12:49 13:04 (00:14) vpnuem ppp0 177.67.100.42 Fri Apr 1 13:27 17:51 (04:24) vpnuem ppp0 177.67.100.42 Fri Apr 1 17:53 09:12 (15:19) vpnuem ppp0 177.67.100.42 Fri Apr 8 14:03 01:01 (10:57) vpnuem ppp1 177.67.100.42 Fri Apr 8 19:05 01:00 (05:54) vpnuem ppp0 177.67.100.42 Mon Apr 11 07:26 03:25 (1+19:59) vpnuem ppp0 177.67.100.42 Mon Apr 18 08:54 09:54 (00:59) vpnuem ppp0 177.67.100.42 Mon Apr 18 09:55 19:55 (09:59) vpnuem ppp0 177.67.100.42 Mon Apr 18 20:00 21:46 (01:45) vpnuem ppp1 177.67.100.42 Mon Apr 18 20:40 21:43 (01:02) vpnuem ppp0 177.67.100.42 Mon Apr 18 21:49 22:31 (00:41) vpnuem ppp0 177.67.100.42 Mon Apr 18 22:32 22:33 (00:01) vpnuem ppp0 177.67.100.42 Mon Apr 18 22:38 08:08 (09:29) vpnuem ppp0 177.67.100.42 Mon Apr 25 07:58 09:36 (01:38) vpnuem ppp0 177.67.100.42 Mon Apr 25 09:37 10:29 (00:52) vpnuem ppp0 177.67.100.42 Mon Apr 25 10:35 14:57 (04:22) vpnuem ppp1 177.67.100.42 Mon Apr 25 11:29 still logged in vpnuem ppp0 177.67.100.42 Mon Apr 25 14:59 still logged in vpnuem ppp0 177.67.100.42 Sat Apr 2 09:13 21:12 (11:58) vpnuem ppp0 177.67.100.42 Sat Apr 2 21:18 10:23 (13:05) vpnuem ppp0 177.67.100.42 Sat Apr 9 01:01 01:03 (00:02) vpnuem ppp0 177.67.100.42 Sat Apr 9 01:04 07:25 (2+06:20) vpnuem ppp1 177.67.100.42 Sat Apr 9 21:36 07:25 (1+09:49) vpnuem ppp0 177.67.100.42 Sun Apr 3 10:26 20:27 (10:01) vpnuem ppp0 177.67.100.42 Sun Apr 3 20:29 11:20 (14:51) vpnuem ppp0 177.67.100.42 Thu Apr 14 10:59 16:50 (05:51) vpnuem ppp0 177.67.100.42 Thu Apr 14 16:52 14:33 (21:40) vpnuem ppp0 177.67.100.42 Tue Apr 19 08:08 13:37 (05:28) vpnuem ppp1 177.67.100.42 Tue Apr 19 11:25 13:34 (02:09) vpnuem ppp0 177.67.100.42 Tue Apr 19 15:49 16:44 (00:55) vpnuem ppp0 177.67.100.42 Tue Apr 5 08:53 13:02 (04:08) vpnuem ppp0 177.67.100.42 Tue Apr 5 13:03 15:09 (02:06) vpnuem ppp0 177.67.100.42 Tue Apr 5 15:11 15:14 (1+00:03) vpnuem ppp0 177.67.100.42 Wed Apr 13 10:39 12:50 (02:11) vpnuem ppp0 177.67.100.42 Wed Apr 13 12:51 14:46 (01:54) vpnuem ppp0 177.67.100.42 Wed Apr 20 09:14 11:02 (01:48) vpnuem ppp1 177.67.100.42 Wed Apr 6 08:17 15:20 (07:03) iladm pts/1 187.109.112.9 Fri Apr 15 09:39 10:37 (00:57) iladm pts/0 187.109.112.9 Mon Apr 4 17:27 21:28 (04:00) iladm pts/0 187.109.112.9 Thu Apr 7 12:13 12:19 (00:06) iladm pts/1 187.109.112.9 Tue Apr 12 06:35 23:03 (16:27) iladm pts/2 187.109.112.9 Tue Apr 12 06:36 23:03 (16:26) iladm pts/2 187.109.112.9 Tue Apr 26 06:54 still logged in iladm pts/3 187.109.112.9 Tue Apr 26 06:54 still logged in iladm pts/2 187.109.112.9 Wed Apr 6 08:54 09:42 (00:47) wtmp begins Fri Apr 1 13:27:34 2016root pts/0 uemmbb254.uem.co Fri Apr 15 15:12 15:53 (00:41) root pts/0 uemmbb254.uem.co Fri Apr 15 16:05 16:25 (00:20) root pts/1 uemmbb254.uem.co Mon Apr 18 16:52 17:25 (00:32)
root pts/2 uemmbb254.uem.co Mon Apr 25 13:54 14:40 (00:46)
[root@uemadm:]# last | sort k 3 | moreluis ftpd16605 1775912655.3g Tue Apr 5 22:46 23:00 (00:14) luis ftpd24192 1775912655.3g Tue Apr 5 23:32 23:53 (00:20) luis ftpd28367 1775912655.3g Tue Apr 5 23:59 00:15 (00:15) luis ftpd28710 1775969181.3g Fri Apr 15 07:53 08:22 (00:29) luis ftpd5238 1775969181.3g Fri Apr 15 08:48 08:59 (00:11) luis ftpd8495 1775969181.3g Fri Apr 15 09:07 09:24 (00:16) luis ftpd11891 1775969181.3g Fri Apr 15 09:28 09:39 (00:11) luis ftpd17129 1775969181.3g Fri Apr 15 09:59 10:13 (00:14) luis ftpd28383 19124722810.3 Fri Apr 15 11:02 11:12 (00:10) luis ftpd2075 19124722810.3 Fri Apr 15 11:39 11:53 (00:13) luis ftpd5138 19124722810.3 Fri Apr 15 11:58 12:08 (00:10) luis ftpd9988 19124722810.3 Fri Apr 15 12:27 12:39 (00:12) luis ftpd13153 19124722810.3 Fri Apr 15 12:46 12:53 (00:07) luis ftpd14354 19124722810.3 Fri Apr 15 12:54 13:05 (00:10) luis ftpd15010 19124722810.3 Fri Apr 15 12:58 13:08 (00:10) luis ftpd16804 19124722810.3 Fri Apr 15 13:09 13:20 (00:11) luis ftpd17732 19124722810.3 Fri Apr 15 13:14 13:28 (00:13) luis ftpd22215 19124722810.3 Fri Apr 15 13:41 13:51 (00:10) luis ftpd24807 19124722810.3 Fri Apr 15 13:55 14:06 (00:11) luis ftpd27111 19124722810.3 Fri Apr 15 14:09 14:21 (00:12) luis ftpd28622 19124722810.3 Fri Apr 15 14:17 14:25 (00:08) luis ftpd29920 19124722810.3 Fri Apr 15 14:26 14:26 (00:00) luis ftpd30320 19124722810.3 Fri Apr 15 14:28 14:38 (00:10) luis ftpd32217 19124722810.3 Fri Apr 15 14:40 14:50 (00:10) luis ftpd3283 19124722810.3 Fri Apr 15 15:01 15:11 (00:10) luis ftpd7673 19124722810.3 Fri Apr 15 15:26 15:38 (00:11) luis ftpd2058 19124722810.3 Fri Apr 15 18:08 18:19 (00:10) luis ftpd3748 19124722810.3 Fri Apr 15 18:20 18:32 (00:12) luis ftpd17645 19124722810.3 Fri Apr 15 19:49 19:58 (00:09) luis ftpd19089 19124722810.3 Fri Apr 15 19:58 20:09 (00:10) luis ftpd20609 19124722810.3 Fri Apr 15 20:08 20:17 (00:09) luis ftpd22092 19124722810.3 Fri Apr 15 20:18 20:30 (00:12) luis ftpd27973 19124722810.3 Fri Apr 15 20:53 20:57 (00:04) luis ftpd28646 19124722810.3 Fri Apr 15 20:57 21:08 (00:11) luis ftpd29354 19124722810.3 Fri Apr 15 21:02 21:12 (00:10) luis ftpd3190 19124722810.3 Fri Apr 15 21:43 21:47 (00:04) luis ftpd3953 19124722810.3 Fri Apr 15 21:48 21:58 (00:10) luis ftpd4736 19124722810.3 Fri Apr 15 21:52 22:03 (00:10) luis ftpd21334 19124723010.3 Fri Apr 15 23:41 23:54 (00:13) luis ftpd24393 19124723010.3 Fri Apr 15 23:57 00:08 (00:10) luis ftpd27523 19124723010.3 Sat Apr 16 08:29 08:40 (00:10) luis ftpd28140 19124723010.3 Sat Apr 16 08:33 08:43 (00:10) luis ftpd30233 19124723010.3 Sat Apr 16 08:46 08:56 (00:09) luis ftpd31798 19124723010.3 Sat Apr 16 08:57 09:07 (00:10) luis ftpd31890 1912472305.3g Fri Apr 15 00:03 00:15 (00:11) luis ftpd15819 1912472305.3g Thu Apr 14 22:21 22:33 (00:11) luis ftpd18303 1912472305.3g Thu Apr 14 22:38 22:48 (00:10) luis ftpd18917 1912472305.3g Thu Apr 14 22:41 22:52 (00:10) luis ftpd23243 1912472305.3g Thu Apr 14 23:10 23:21 (00:11) luis ftpd26259 1912472305.3g Thu Apr 14 23:27 23:32 (00:04) luis ftpd27055 1912472305.3g Thu Apr 14 23:32 23:42 (00:10) luis ftpd28044 1912472305.3g Thu Apr 14 23:38 23:47 (00:08) luis ftpd29377 1912472305.3g Thu Apr 14 23:47 23:57 (00:10) luis ftpd30162 1912472305.3g Thu Apr 14 23:52 23:55 (00:02) luis ftpd30780 1912472305.3g Thu Apr 14 23:56 00:03 (00:07) iladm pts/0 192.168.0.1 Tue Apr 12 06:36 23:03 (16:26) iladm pts/0 192.168.0.1 Tue Apr 26 06:55 still logged in andreia ftpd19201 ::ffff:187.109.1 Fri Apr 1 21:07 21:16 (00:09) andreia ftpd32368 ::ffff:187.109.1 Mon Apr 4 09:02 09:13 (00:10) andreia ftpd9928 ::ffff:187.109.1 Mon Apr 4 22:44 23:07 (00:23) andreia ftpd24885 ::ffff:187.109.1 Sun Apr 3 22:01 22:18 (00:16) andreia ftpd21886 ::ffff:187.109.1 Tue Apr 12 07:31 07:41 (00:10) luis ftpd3476 ::ffff:201.46.14 Fri Apr 1 09:39 10:10 (00:31) luis ftpd32111 ::ffff:201.46.14 Mon Apr 25 00:12 00:44 (00:31)
Espaço em disco
[root@uemgw]# df hSist. Arq. Tam Usad Disp Uso% Montado em/dev/sda3 38G 22G 15G 60% /varrun 1,5G 296K 1,5G 1% /var/runvarlock 1,5G 0 1,5G 0% /var/lockudev 1,5G 52K 1,5G 1% /devdevshm 1,5G 0 1,5G 0% /dev/shm/dev/sdb1 50G 39G 9,0G 81% /backup/dev/sda1 471M 140M 308M 32% /boot//192.168.0.106/Pessoal 30G 22G 8,6G 72% /ftp/Pessoal//192.168.0.100/CorporeRM 47G 23G 25G 48% /home/ponto//192.168.0.106/Linux_BKP 110G 86G 25G 78% /backupremoto//192.168.0.106/TGP 682G 478G 204G 71% /ftp/TGP
[root@uemadm:]# df hSist. Arq. Tam Usad Disp Uso% Montado em/dev/sda3 96G 78G 14G 86% /varrun 2,0G 3,9M 2,0G 1% /var/runvarlock 2,0G 0 2,0G 0% /var/lockudev 2,0G 52K 2,0G 1% /devdevshm 2,0G 0 2,0G 0% /dev/shm/dev/sda1 471M 150M 297M 34% /boot//192.168.0.106/Linux_BKP 110G 86G 25G 78% /backupremoto
Dmesg
Dmesg – Alertas de Console (Eventuais Erros de Disco, Rede, Hardware em geral) Sem informações relevantes
LogsVerificação superficial de logs do sistema:
( syslog(tmsys) / secure(tms) / squid(tmsq – uemgw) )
Top Memória / Processos / Carga Sem informações relevantes
Portas Tcp Udp Abertas[root@uemgw]# netstat ap | grep LISTEN | grep v STREAMtcp 0 0 localhost:60000 *:* LISTEN 8464/postgrey.pid tcp 0 0 *:10050 *:* LISTEN 10214/zabbix_agentdtcp 0 0 192.168.0.1:5666 *:* LISTEN 8858/nrpe tcp 0 0 *:rsync *:* LISTEN 9053/rsync tcp 0 0 localhost:zebra *:* LISTEN 9034/zebra tcp 0 0 localhost:mysql *:* LISTEN 8396/mysqld tcp 0 0 localhost:bgpd *:* LISTEN 9038/bgpd tcp 0 0 *:webmin *:* LISTEN 10245/perl tcp 0 0 *:81 *:* LISTEN 9261/apache2 tcp 0 0 *:bgp *:* LISTEN 9038/bgpd tcp 0 0 *:ftp *:* LISTEN 8884/proftpd: (accetcp 0 0 192.168.12.10:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.29:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.27:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.25:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.23:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.21:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.19:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.17:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.15:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.13:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.11:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.9:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.7:domain *:* LISTEN 7939/named
tcp 0 0 10.0.0.3:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.5:domain *:* LISTEN 7939/named tcp 0 0 10.0.0.1:domain *:* LISTEN 7939/named tcp 0 0 201048214114.:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.14:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.29:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.28:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.12:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.50:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.11:domain *:* LISTEN 7939/named tcp 0 0 177.38.168.10:domain *:* LISTEN 7939/named tcp 0 0 n009.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 n008.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 n007.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 n006.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 rev2.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 n002.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 rev1.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 uemnotes.uem.com:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.28:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.29:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.12:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.50:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.11:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.10:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.9:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.8:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.7:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.6:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.4:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.3:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.2:domain *:* LISTEN 7939/named tcp 0 0 n001.uem.com.br:domain *:* LISTEN 7939/named tcp 0 0 200.243.57.5:domain *:* LISTEN 7939/named tcp 0 0 192.168.2.1:domain *:* LISTEN 7939/named tcp 0 0 192.168.0.2:domain *:* LISTEN 7939/named tcp 0 0 192.168.0.1:domain *:* LISTEN 7939/named tcp 0 0 localhost:domain *:* LISTEN 7939/named tcp 0 0 *:ssh *:* LISTEN 8264/sshd tcp 0 0 *:3128 *:* LISTEN 8413/(squid) tcp 0 0 *:smtp *:* LISTEN 9013/master tcp 0 0 localhost:953 *:* LISTEN 7939/named tcp 0 0 *:1723 *:* LISTEN 9020/pptpd tcp6 0 0 [::]:rsync [::]:* LISTEN 9053/rsync tcp6 0 0 [::]:bgp [::]:* LISTEN 9038/bgpd tcp6 0 0 [::]:domain [::]:* LISTEN 7939/named tcp6 0 0 [::]:ssh [::]:* LISTEN 8264/sshd tcp6 0 0 ip6localhost:953 [::]:* LISTEN 7939/named Obs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.
root@uemgw:~# netstat nap | grep LISTEN | grep v STREAMtcp 0 0 127.0.0.1:60000 0.0.0.0:* LISTEN 8464/postgrey.pid tcp 0 0 0.0.0.0:10050 0.0.0.0:* LISTEN 10214/zabbix_agentdtcp 0 0 192.168.0.1:5666 0.0.0.0:* LISTEN 8858/nrpe tcp 0 0 0.0.0.0:873 0.0.0.0:* LISTEN 9053/rsync tcp 0 0 127.0.0.1:2601 0.0.0.0:* LISTEN 9034/zebra tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN 8396/mysqld tcp 0 0 127.0.0.1:2605 0.0.0.0:* LISTEN 9038/bgpd tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 10245/perl tcp 0 0 0.0.0.0:81 0.0.0.0:* LISTEN 9261/apache2 tcp 0 0 0.0.0.0:179 0.0.0.0:* LISTEN 9038/bgpd tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 8884/proftpd: (accetcp 0 0 192.168.12.10:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.29:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.27:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.25:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.23:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.21:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.19:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.17:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.15:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.13:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.11:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.9:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.7:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.3:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 10.0.0.5:53 0.0.0.0:* LISTEN 7939/named
tcp 0 0 10.0.0.1:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 201.48.214.114:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.14:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.29:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.28:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.12:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.50:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.11:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.10:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.9:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.8:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.7:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.6:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.4:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.3:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.2:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.5:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.28:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.29:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.12:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.50:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.11:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.10:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.9:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.8:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.7:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.6:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.4:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.3:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.2:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 177.38.168.1:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 200.243.57.5:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 192.168.2.1:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 192.168.0.2:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 192.168.0.1:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 7939/named tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 8264/sshd tcp 0 0 0.0.0.0:3128 0.0.0.0:* LISTEN 8413/(squid) tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 9013/master tcp 0 0 127.0.0.1:953 0.0.0.0:* LISTEN 7939/named tcp 0 0 0.0.0.0:1723 0.0.0.0:* LISTEN 9020/pptpd tcp6 0 0 :::873 :::* LISTEN 9053/rsync tcp6 0 0 :::179 :::* LISTEN 9038/bgpd tcp6 0 0 :::53 :::* LISTEN 7939/named tcp6 0 0 :::22 :::* LISTEN 8264/sshd tcp6 0 0 ::1:953 :::* LISTEN 7939/named Obs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.
[root@uemadm]# netstat ap | grep LISTEN | grep v STREAMtcp 0 0 *:10050 *:* LISTEN 7872/zabbix_agentdtcp 0 0 uemadm:5666 *:* LISTEN 5559/nrpe tcp 0 0 *:10051 *:* LISTEN 23793/zabbix_servertcp 0 0 *:rsync *:* LISTEN 5636/rsync tcp 0 0 *:gds_db *:* LISTEN 20823/fbserver tcp 0 0 localhost:mysql *:* LISTEN 5375/mysqld tcp 0 0 *:netbiosssn *:* LISTEN 5655/smbd tcp 0 0 *:webmin *:* LISTEN 20398/perl tcp 0 0 portal.uem.com.br:www *:* LISTEN 8588/apache2 tcp 0 0 *:82 *:* LISTEN 8588/apache2 tcp 0 0 *:ssh *:* LISTEN 5277/sshd tcp 0 0 localhost:postgresql *:* LISTEN 5524/postgres tcp 0 0 *:smtp *:* LISTEN 617/master tcp 0 0 *:microsoftds *:* LISTEN 5655/smbd tcp6 0 0 [::]:rsync [::]:* LISTEN 5636/rsync tcp6 0 0 [::]:ftp [::]:* LISTEN 8585/proftpd: (accetcp6 0 0 [::]:ssh [::]:* LISTEN 5277/sshd Obs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.
root@uemadm:~# netstat nap | grep LISTEN | grep v STREAM tcp 0 0 0.0.0.0:10050 0.0.0.0:* LISTEN 7872/zabbix_agentdtcp 0 0 192.168.0.109:5666 0.0.0.0:* LISTEN 5559/nrpe tcp 0 0 0.0.0.0:10051 0.0.0.0:* LISTEN 23793/zabbix_servertcp 0 0 0.0.0.0:873 0.0.0.0:* LISTEN 5636/rsync tcp 0 0 0.0.0.0:3050 0.0.0.0:* LISTEN 20823/fbserver tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN 5375/mysqld
tcp 0 0 0.0.0.0:139 0.0.0.0:* LISTEN 5655/smbd tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 20398/perl tcp 0 0 192.168.0.124:80 0.0.0.0:* LISTEN 8588/apache2 tcp 0 0 0.0.0.0:82 0.0.0.0:* LISTEN 8588/apache2 tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 5277/sshd tcp 0 0 127.0.0.1:5432 0.0.0.0:* LISTEN 5524/postgres tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 617/master tcp 0 0 0.0.0.0:445 0.0.0.0:* LISTEN 5655/smbd tcp6 0 0 :::873 :::* LISTEN 5636/rsync tcp6 0 0 :::21 :::* LISTEN 8585/proftpd: (accetcp6 0 0 :::22 :::* LISTEN 5277/sshdObs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.
Squid Reports Semanal – 17/04/2016 a 23/04/2016
Squid Reports – TopSites
Squid Reports – TopUsers
Squid Reports – Tentativas de acesso a Sites Indevidos
LOCAL ACESSADO IPwww.calcinhamolhada.net 192.168.14.135www.fadadosexo.com 192.168.14.135www.flagrasdenovinhas.com 192.168.14.135www.ninfetasgratis.net 192.168.14.135www.novinhaexcitada.com 192.168.14.135www.novinhaputa.com 192.168.14.135www.pornobr.club 192.168.14.135www.pornocaramujos.com 192.168.14.135www.pornocarioca.com 192.168.14.135www.pornocegonha.com 192.168.14.135www.pornoclip.com.br 192.168.14.135www.pornocodorna.com 192.168.14.135www.pornocoruja.com 192.168.14.135www.pornopato.net 192.168.14.135www.pornorazzo.com 192.168.14.135www.pornosafadas.net 192.168.14.135www.pornoteen.com.br 192.168.14.135www.tvonlinegratis.tv 192.168.14.58www.videoamadorbrasil.com 192.168.14.135www.videosdebucetas.com 192.168.14.135www.videosdesexohd.net 192.168.14.135www.videosporno11.com 192.168.14.135www.videospornop.com 192.168.14.135
Obs: Não foi acrescentada nenhuma expressão ao arquivo /etc/squid/site_proibido.txt a fim de impedir o acesso desites relacionados.Obs2: Muitas tentativas de acessos indevidos originadas do ip 192.168.14.135
OFFICE 365
Caixa de correio ativas e inativas
Número de caixas de correio ativas e inativas ao longo do tempo. Uma caixa decorreio é considerada inativa se um usuário não fizer logon por mais de 30 dias.
Inativo há 30 60 dias
Inativo há 61 90 dias
Inativo há mais de 90 dias
Data Nome para exibição Último logon bem-sucedido Dias inativos
17/03/2016 00:00
Adriano Lima#N#DEL:c36be30e-aa05-4410-bc13-e75070dc926d
342
17/03/2016 00:00
adsync2014-10-06T07:45:18
528
17/03/2016 00:00
Alexandre Meirelles#N#DEL:37627ad1-e515-4cd4-a97d-16b344e004f5
342
17/03/2016 00:00
Almoxarifado CN#N#DEL:ba7d35a9-9a7c-4e9f-a8ee-4d377bfce8c5
342
17/03/2016 00:00
Antonio Junior2015-12-15T11:22:04
93
17/03/2016 00:00
Carla Cristina#N#DEL:88a5db57-6a2b-4f03-9946-2ab1d737080d
342
17/03/2016 00:00
Cesar Andrey#N#DEL:3b452a15-12e0-41fa-851c-5cf857c72c83
342
17/03/2016 00:00
Dariely Costa#N#DEL:456d8e24-9d01-4eaa-bc9f-04651c4101ab
342
17/03/2016 00:00
Diogenes Freitas2015-10-23T07:25:23
146
17/03/2016 00:00
Edmilson Diniz2015-12-03T05:28:45
105
17/03/2016 00:00
Gilberto Santos#N#DEL:17214bca-e754-41b4-bb05-66e81459edca
342
17/03/2016 00:00
Gleidiciele Santos2015-08-12T07:16:16
218
17/03/2016 00:00
Gustavo Barros#N#DEL:51dda5d5-fff8-4a22-962a-ae74ae5c170f
342
17/03/2016 00:00
Jan Carlos2015-11-22T12:42:13
116
17/03/2016 00:00
Janderson Monteiro2015-11-21T03:13:11
117
17/03/2016 00:00
Linux 342
17/03/2016 00:00
Luiz Campos2014-10-26T11:30:27
508
17/03/2016 00:00
luiz geraldo2015-08-28T07:17:18
202
17/03/2016 00:00
Magno Alessandro#N#DEL:ca2c6e92-523b-4a60-b1a8-de6d37d23ede
342
17/03/2016 00:00
marcia fonseca#N#DEL:07ea39e3-5d5e-4ee2-9594-0605c950146c
126
17/03/2016 00:00
Marco Antonio2015-11-05T02:29:21
133
17/03/2016 00:00
Marta Andrade2015-10-27T11:25:20
142
17/03/2016 00:00
Mauricio Mattos2015-10-19T07:34:39
150
17/03/2016 00:00
Mauro Araujo#N#DEL:00e2a36a-5d1e-4e1d-90c8-ab798cc47e99
342
17/03/2016 00:00
Mauro Cesar#N#DEL:c5a78e8d-21c7-4caf-b17a-4c38cbbe1a96
342
17/03/2016 00:00
Murilo Lima#N#DEL:9f1a7612-2fcd-442c-ae14-4e420f0c96f2
342
17/03/2016 00:00
nfe.matriz 342
17/03/2016 00:00
nfe.varzeadolopes 342
17/03/2016 00:00
Oseis Soares#N#DEL:6cc0b195-039e-4423-bc61-16c1c41d9918
342
17/03/2016 00:00
Paulo Cunha2015-12-09T11:49:06
99
17/03/2016 00:00
Ricardo Alexandre#N#DEL:ff61afd3-afda-46ae-9cf9-bee0b8082a28
342
17/03/2016 00:00
Ronis Hebert#N#DEL:b6da183f-d919-4127-8dc8-8e9bb64f4810
342
17/03/2016 00:00
Sala Reunião 3 342
17/03/2016 00:00
Sala Reunião 4 342
17/03/2016 00:00
Sala Reunião 5 342
17/03/2016 00:00
Sala Reunião 6 342
17/03/2016 00:00
Sergio Lima2015-09-23T10:45:03
176
17/03/2016 00:00
Solano Silva2015-11-30T02:08:01
108
17/03/2016 00:00
Valdinei Braz#N#DEL:26e82497-4d00-4bc5-843f-f331ed16e9e1
342
17/03/2016 00:00
Victor Hugo#N#DEL:748a1af8-9dce-4866-ae76-ab072b99e1da
342
17/03/2016 00:00
Wagner Calister#N#DEL:92b943cd-55f1-497a-b467-aa4c69ffccda
342
Uso da caixa de correio
Mostra o número total de caixas de correio, caixas de correio que excederam suascotas de armazenamento e caixas de correio que estão usando menos de 25% de seulimite de armazenamento.
Sistema operacional usado
Mostra o número de sistemas operacionais diferentes nos quais seus usuáriosentraram com suas contas do Office 365 nos últimos 30 dias.
Licenciamento vs Uso Ativo
Visualize o uso ativo (nos últimos 30 dias) de seus serviços do O365 emcomparação com os serviços realmente licenciados para o seu uso. Use esses dadospara verificar se você está obtendo o máximo do seu investimento em nuvem.
Proteção (dados dos últimos 14 dias)
Principais destinatários de email
Principais remetentes de email
Principais destinatários de spams
Principais destinatários de Malware
Detecções de Spam
Principal malware de email
Emails recebidos e enviados
Detecções de malware
Anti virus – Bitdefender
ZABBIX
Triggers mais ativas da semana – TOP 10Hosts que mais geraram alerta no Zabbixx
Fonte:http://192.168.0.109:82/zabbix/report5.php?sid=87d41391d956aaea&form_refresh=1&period=week
Gráficos
Período de 12/04/2016 a 26/04/2016
SERVIDORES LINUX
UEM_ADM CPU Utilization
UEM_ADM Memory Usage
UEM_ADM Disk Space Usage
UEM_GW CPU Utilization
UEM_GW Memory Usage
UEM_GW Disk Space Usage
SERVIDORES WINDOWS
UEMFS – CPU LOAD
UEMFS – Disk Usage
UEMICA – CPU Load
UEMICA – Disk space usage
UEMRMSA – CPU Load
UEMRMSA – Disk Space Usage
Relatório de Disponibilidade (SLA) – 12/04/2016 a 26/04/2016
Será exibida a observação e detalhes do problema quando estes atingirem 2%
UEMICA – okUEMRMAP – okUEMRMSA – Espaço em disco menor que 10% no volume MUEMFS – okUEMMINE – Espaço em disco menor que 10% no volume M
UEMRMSA
UEMMINE
Fonte: http:// 192.168.0.109 :82/zabbix/report2.php
Nagios
Disponibilidade – últimos 7 dias
Host Service % Time OK % Time Warning
% Time Unknown
% Time Critical
% Time Undetermined
nagios_remoto Rede_Http 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_Http 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem-adm Local_Carga 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_Root 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Processos 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Users 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Http:82 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_SSH 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem-gw Local_Carga 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_Root 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_backup
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_bkpremoto
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_ftp_pessoal
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Disk_home_ponto
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Processos 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Local_Users 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Dns 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Ftp 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Http:81 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_SSH 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Squid:3128 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Local_Disk_home_ponto
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemantispam-linux Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_SSH 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemap-aplicacao Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemdev Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_SAP 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemfs-fileserver Rede_NetBios 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_NetBios
100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemica-metaframe Rede_Http 99.917% (99.917%)
0.000% (0.000%)
0.000% (0.000%)
0.083% (0.083%)
0.000%
Rede_Metaframe 99.950% (99.950%)
0.000% (0.000%)
0.000% (0.000%)
0.050% (0.050%)
0.000%
Rede_Ping 99.917% (99.917%)
0.000% (0.000%)
0.000% (0.000%)
0.083% (0.083%)
0.000%
Rede_TS 98.313% (98.313%)
0.000% (0.000%)
0.000% (0.000%)
1.687% (1.687%)
0.000%
uem1_Rede_Metaframe
99.952% (99.952%)
0.000% (0.000%)
0.000% (0.000%)
0.048% (0.048%)
0.000%
uem1_Rede_TS 98.284% (98.284%)
0.000% (0.000%)
0.000% (0.000%)
1.716% (1.716%)
0.000%
uemmine-database Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_Sql 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_Sql 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemprd Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Rede_SAP 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_SAP 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemrmsa-database Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uemvm-vmware4 Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
vpn-server-mk-lan Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
vpn-server-mk-wan Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
uem1_Rede_Ping 100.000% (100.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000% (0.000%)
0.000%
Average 99.927% (99.927%)
0.000% (0.000%)
0.000% (0.000%)
0.073% (0.073%)
0.000%