Login
Log in using an SSO provider:
Fedora Account System
Red Hat Associate
Red Hat Customer
Login using a Red Hat Bugzilla account
Forgot Password
Create an Account
Red Hat Bugzilla – Attachment 1472651 Details for
Bug 1611542
bz for manual recovery of thinpool metadata
Home
New
Search
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh92 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
[?]
This site requires JavaScript to be enabled to function correctly, please enable it.
OS messages (/var/log/messages)
messages (text/plain), 74.19 KB, created by
asshriva
on 2018-08-02 10:54:14 UTC
(
hide
)
Description:
OS messages (/var/log/messages)
Filename:
MIME Type:
Creator:
asshriva
Created:
2018-08-02 10:54:14 UTC
Size:
74.19 KB
patch
obsolete
>Aug 2 10:12:01 gbrpsr000006230 rsyslogd: [origin software="rsyslogd" swVersion="8.24.0" x-pid="838" x-info="http://www.rsyslog.com"] rsyslogd was HUPed >Aug 2 10:12:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:12:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:12:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:12:51 >Aug 2 10:12:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:13:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:13:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:14:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:14:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:15:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:15:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:16:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:16:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:17:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:17:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:17:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:17:51 >Aug 2 10:17:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:18:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:18:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:19:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:19:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:20:01 gbrpsr000006230 systemd: Started Session 11 of user root. >Aug 2 10:20:01 gbrpsr000006230 systemd: Starting Session 11 of user root. >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533201601.148:210): pid=8571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533201601.149:211): pid=8571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533201601.152:212): pid=8571 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=11 res=1 >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533201601.176:213): pid=8571 uid=0 auid=0 ses=11 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533201601.236:214): pid=8571 uid=0 auid=0 ses=11 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533201601.262:215): pid=8571 uid=0 auid=0 ses=11 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:05 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533201601.265:216): pid=8571 uid=0 auid=0 ses=11 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:20:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:20:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:21:05 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533201664.380:217): pid=8645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=8645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:21:05 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533201664.380:218): pid=8645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=8645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:21:05 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533201664.384:219): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=8645 suid=74 rport=53820 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=? res=success' >Aug 2 10:21:05 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533201664.384:220): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=8645 suid=74 rport=53820 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=? res=success' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533201665.649:221): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=ssh res=failed' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533201665.654:222): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=ssh res=failed' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533201665.658:223): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=ssh res=failed' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533201665.663:224): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8645 suid=74 rport=53820 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=? res=success' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=USER_ERR msg=audit(1533201665.665:225): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/sbin/sshd" hostname=gbrpsr000002186.intranet.barcapint.com addr=10.34.88.49 terminal=ssh res=failed' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533201665.666:226): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=8644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533201665.666:227): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=8644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:21:15 gbrpsr000006230 audit_log: type=USER_LOGIN msg=audit(1533201665.666:228): pid=8644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login acct="root" exe="/usr/sbin/sshd" hostname=? addr=10.34.88.49 terminal=ssh res=failed' >Aug 2 10:21:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:21:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:22:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:22:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:22:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:22:51 >Aug 2 10:22:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:23:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:23:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:24:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:24:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:25:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:25:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:26:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:26:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:27:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:27:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:27:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:27:51 >Aug 2 10:27:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:28:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:28:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:29:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:29:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:30:01 gbrpsr000006230 systemd: Started Session 13 of user root. >Aug 2 10:30:01 gbrpsr000006230 systemd: Starting Session 13 of user root. >Aug 2 10:30:01 gbrpsr000006230 systemd: Started Session 12 of user root. >Aug 2 10:30:01 gbrpsr000006230 systemd: Starting Session 12 of user root. >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533202201.293:229): pid=9307 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533202201.293:230): pid=9308 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533202201.295:231): pid=9308 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533202201.295:232): pid=9307 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533202201.297:234): pid=9308 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=13 res=1 >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533202201.297:233): pid=9307 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=12 res=1 >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533202201.321:235): pid=9308 uid=0 auid=0 ses=13 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533202201.321:236): pid=9307 uid=0 auid=0 ses=12 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533202201.392:237): pid=9307 uid=0 auid=0 ses=12 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533202201.392:238): pid=9308 uid=0 auid=0 ses=13 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533202201.419:239): pid=9307 uid=0 auid=0 ses=12 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:06 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533202201.421:240): pid=9307 uid=0 auid=0 ses=12 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:30:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:30:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:31:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:31:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:32:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:32:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:32:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:32:51 >Aug 2 10:32:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:33:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:33:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:34:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:34:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:35:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:35:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:36:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:36:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:37:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:37:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:37:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:37:51 >Aug 2 10:37:54 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:38:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:38:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:39:05 gbrpsr000006230 systemd: Created slice User Slice of sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Starting User Slice of sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd-logind: New session 14 of user sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Started Session 14 of user sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Starting Session 14 of user sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Created slice User Slice of sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Starting User Slice of sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd-logind: New session 14 of user sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Started Session 14 of user sa_makir1. >Aug 2 10:39:05 gbrpsr000006230 systemd: Starting Session 14 of user sa_makir1. >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202736.854:241): pid=9964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=9964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202736.855:242): pid=9964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=9964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533202736.898:243): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes256-ctr ksize=256 mac=hmac-sha2-256 pfs=curve25519-sha256@libssh.org spid=9964 suid=74 rport=56665 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.188.54.46 terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533202736.899:244): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes256-ctr ksize=256 mac=hmac-sha2-256 pfs=curve25519-sha256@libssh.org spid=9964 suid=74 rport=56665 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.188.54.46 terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.462:245): avc: denied { write } for pid=9974 comm="mkdir" name="home" dev="dm-1" ino=131074 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.462:245): avc: denied { add_name } for pid=9974 comm="mkdir" name="sa_makir1" scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.462:245): avc: denied { create } for pid=9974 comm="mkdir" name="sa_makir1" scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=SYSCALL msg=audit(1533202745.462:245): arch=c000003e syscall=83 success=yes exit=0 a0=7ffc8903ef95 a1=1ff a2=1ff a3=7ffc8903d1e0 items=0 ppid=9973 pid=9974 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="mkdir" exe="/usr/bin/mkdir" subj=system_u:system_r:vasd_t:s0 key=(null) >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=PROCTITLE msg=audit(1533202745.462:245): proctitle=6D6B646972002D70002F686F6D652F73615F6D616B697231 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.464:246): avc: denied { setattr } for pid=9975 comm="chmod" name="sa_makir1" dev="dm-1" ino=137396 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=SYSCALL msg=audit(1533202745.464:246): arch=c000003e syscall=268 success=yes exit=0 a0=ffffffffffffff9c a1=23f2120 a2=1c0 a3=7fff381a59e0 items=0 ppid=9973 pid=9975 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="chmod" exe="/usr/bin/chmod" subj=system_u:system_r:vasd_t:s0 key=(null) >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=PROCTITLE msg=audit(1533202745.464:246): proctitle=63686D6F6400373030002F686F6D652F73615F6D616B697231 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.491:247): avc: denied { create } for pid=9978 comm="cpio" name=".bash_logout" scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.491:247): avc: denied { write open } for pid=9978 comm="cpio" path="/home/sa_makir1/.bash_logout" dev="dm-1" ino=144403 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=SYSCALL msg=audit(1533202745.491:247): arch=c000003e syscall=2 success=yes exit=4 a0=1104510 a1=41 a2=180 a3=7ffefe954b60 items=0 ppid=9973 pid=9978 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="cpio" exe="/usr/bin/cpio" subj=system_u:system_r:vasd_t:s0 key=(null) >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=PROCTITLE msg=audit(1533202745.491:247): proctitle=6370696F002D6470002F686F6D652F73615F6D616B697231 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.493:248): avc: denied { setattr } for pid=9978 comm="cpio" name=".bash_logout" dev="dm-1" ino=144403 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=SYSCALL msg=audit(1533202745.493:248): arch=c000003e syscall=93 success=yes exit=0 a0=4 a1=0 a2=0 a3=7ffefe954b20 items=0 ppid=9973 pid=9978 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="cpio" exe="/usr/bin/cpio" subj=system_u:system_r:vasd_t:s0 key=(null) >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=PROCTITLE msg=audit(1533202745.493:248): proctitle=6370696F002D6470002F686F6D652F73615F6D616B697231 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533202745.624:249): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:authentication grantors=pam_vas3 acct="sa_makir1" exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533202745.627:250): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_vas3 acct="sa_makir1" exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202745.627:251): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9964 suid=74 rport=56665 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.188.54.46 terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533202745.629:252): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="sa_makir1" exe="/usr/sbin/sshd" hostname=? addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533202745.678:253): pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_vas3 acct="sa_makir1" exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533202745.679:254): pid=9963 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old-auid=4294967295 auid=3077657 tty=(none) old-ses=4294967295 ses=14 res=1 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_ROLE_CHANGE msg=audit(1533202745.873:255): pid=9963 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.910:256): avc: denied { write } for pid=1405 comm=".vasd" name="sa_makir1" dev="dm-1" ino=137396 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.910:256): avc: denied { add_name } for pid=1405 comm=".vasd" name=".vas_logon_server" scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=dir >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.910:256): avc: denied { create } for pid=1405 comm=".vasd" name=".vas_logon_server" scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=AVC msg=audit(1533202745.910:256): avc: denied { write open } for pid=1405 comm=".vasd" path="/home/sa_makir1/.vas_logon_server" dev="dm-1" ino=144411 scontext=system_u:system_r:vasd_t:s0 tcontext=system_u:object_r:root_t:s0 tclass=file >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=SYSCALL msg=audit(1533202745.910:256): arch=c000003e syscall=2 success=yes exit=12 a0=1082640 a1=241 a2=1b6 a3=24 items=0 ppid=1395 pid=1405 auid=4294967295 uid=0 gid=0 euid=3077657 suid=0 fsuid=3077657 egid=260 sgid=0 fsgid=260 tty=(none) ses=4294967295 comm=".vasd" exe="/opt/quest/sbin/.vasd" subj=system_u:system_r:vasd_t:s0 key=(null) >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=PROCTITLE msg=audit(1533202745.910:256): proctitle=2F6F70742F71756573742F7362696E2F2E76617364002D70002F7661722F6F70742F71756573742F7661732F766173642F2E766173642E706964002D77 >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533202745.912:257): pid=9963 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_selinux,pam_loginuid,pam_selinux,pam_namespace,pam_keyinit,pam_keyinit,pam_limits,pam_systemd,pam_vas3,pam_vas3,pam_unix,pam_lastlog acct="sa_makir1" exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202745.913:258): pid=9995 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=9995 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202745.913:259): pid=9995 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=9995 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533202745.916:260): pid=9995 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_vas3 acct="sa_makir1" exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_LOGIN msg=audit(1533202746.001:261): pid=9963 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=3077657 exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533202746.001:262): pid=9963 uid=0 auid=3077657 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=3077657 exe="/usr/sbin/sshd" hostname=22.188.54.46 addr=22.188.54.46 terminal=ssh res=success' >Aug 2 10:39:06 gbrpsr000006230 rsyslogd: imjournal: journal reloaded... [v8.24.0 try http://www.rsyslog.com/e/0 ] >Aug 2 10:39:06 gbrpsr000006230 rsyslogd: action 'action 0' suspended, next retry is Thu Aug 2 10:39:36 2018 [v8.24.0 try http://www.rsyslog.com/e/2007 ] >Aug 2 10:39:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:39:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:40:01 gbrpsr000006230 systemd: Started Session 15 of user root. >Aug 2 10:40:01 gbrpsr000006230 systemd: Starting Session 15 of user root. >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533202801.449:263): pid=10052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533202801.450:264): pid=10052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533202801.451:265): pid=10052 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=15 res=1 >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533202801.468:266): pid=10052 uid=0 auid=0 ses=15 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533202801.514:267): pid=10052 uid=0 auid=0 ses=15 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533202801.536:268): pid=10052 uid=0 auid=0 ses=15 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:06 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533202801.537:269): pid=10052 uid=0 auid=0 ses=15 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:40:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:40:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:41:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:41:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202941.893:270): pid=10211 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=10211 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202941.894:271): pid=10211 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=10211 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533202941.899:272): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=10211 suid=74 rport=38695 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533202941.899:273): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=10211 suid=74 rport=38695 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533202942.319:274): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=ssh res=failed' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533202942.324:275): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=ssh res=failed' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533202942.328:276): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=ssh res=failed' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202942.333:277): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10211 suid=74 rport=38695 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=USER_ERR msg=audit(1533202942.337:278): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/sbin/sshd" hostname=gbrccr00078n09.intranet.barcapint.com addr=22.113.196.147 terminal=ssh res=failed' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202942.338:279): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=10210 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533202942.338:280): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=10210 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:42:26 gbrpsr000006230 audit_log: type=USER_LOGIN msg=audit(1533202942.338:281): pid=10210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.113.196.147 terminal=ssh res=failed' >Aug 2 10:42:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:42:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:42:52 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:42:52 >Aug 2 10:42:54 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:43:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:43:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:44:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:44:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:45:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:45:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:46:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:46:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:47:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:47:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:47:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:47:51 >Aug 2 10:47:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:48:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:48:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:48:58 gbrpsr000006230 systemd-logind: Removed session 1. >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533203338.323:282): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533203338.370:283): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_selinux,pam_loginuid,pam_selinux,pam_namespace,pam_keyinit,pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_lastlog acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533203338.399:284): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533203338.400:285): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=2561 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533203338.400:286): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=2561 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 10:49:07 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533203338.400:287): pid=2561 uid=0 auid=0 ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2561 suid=0 rport=54940 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 10:49:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:49:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:50:01 gbrpsr000006230 systemd: Started Session 16 of user root. >Aug 2 10:50:01 gbrpsr000006230 systemd: Starting Session 16 of user root. >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533203401.564:288): pid=10772 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533203401.565:289): pid=10772 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533203401.566:290): pid=10772 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=16 res=1 >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533203401.584:291): pid=10772 uid=0 auid=0 ses=16 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533203401.635:292): pid=10772 uid=0 auid=0 ses=16 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533203401.661:293): pid=10772 uid=0 auid=0 ses=16 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:07 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533203401.662:294): pid=10772 uid=0 auid=0 ses=16 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:50:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:50:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:51:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:51:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:52:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:52:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:52:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:52:51 >Aug 2 10:52:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:53:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:53:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:54:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:54:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:55:29 gbrpsr000006230 dbus-daemon: dbus[823]: [system] Activating via systemd: service name='org.freedesktop.hostname1' unit='dbus-org.freedesktop.hostname1.service' >Aug 2 10:55:29 gbrpsr000006230 dbus[823]: [system] Activating via systemd: service name='org.freedesktop.hostname1' unit='dbus-org.freedesktop.hostname1.service' >Aug 2 10:55:29 gbrpsr000006230 systemd: Starting Hostname Service... >Aug 2 10:55:29 gbrpsr000006230 dbus[823]: [system] Successfully activated service 'org.freedesktop.hostname1' >Aug 2 10:55:29 gbrpsr000006230 dbus-daemon: dbus[823]: [system] Successfully activated service 'org.freedesktop.hostname1' >Aug 2 10:55:29 gbrpsr000006230 systemd: Started Hostname Service. >Aug 2 10:55:33 gbrpsr000006230 systemd: Configuration file /etc/systemd/system/pblocald.service is marked world-inaccessible. This has no effect as configuration data is accessible via APIs without restrictions. Proceeding anyway. >Aug 2 10:55:33 gbrpsr000006230 systemd: Configuration file /usr/lib/systemd/system/vasd.service is marked executable. Please remove executable permission bits. Proceeding anyway. >Aug 2 10:55:37 gbrpsr000006230 audit_log: type=SERVICE_START msg=audit(1533203729.458:295): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' >Aug 2 10:55:45 gbrpsr000006230 systemd: Removed slice User Slice of root. >Aug 2 10:55:45 gbrpsr000006230 systemd: Stopping User Slice of root. >Aug 2 10:55:47 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533203745.262:296): pid=9308 uid=0 auid=0 ses=13 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:55:47 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533203745.266:297): pid=9308 uid=0 auid=0 ses=13 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 10:55:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:55:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:56:07 gbrpsr000006230 audit_log: type=SERVICE_STOP msg=audit(1533203759.506:298): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' >Aug 2 10:56:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:56:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:57:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:57:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:57:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_10:57:51 >Aug 2 10:57:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 10:58:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:58:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 10:59:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 10:59:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:00:01 gbrpsr000006230 systemd: Created slice User Slice of root. >Aug 2 11:00:01 gbrpsr000006230 systemd: Starting User Slice of root. >Aug 2 11:00:01 gbrpsr000006230 systemd: Started Session 17 of user root. >Aug 2 11:00:01 gbrpsr000006230 systemd: Starting Session 17 of user root. >Aug 2 11:00:01 gbrpsr000006230 systemd: Removed slice User Slice of root. >Aug 2 11:00:01 gbrpsr000006230 systemd: Stopping User Slice of root. >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533204001.301:299): pid=12306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533204001.302:300): pid=12306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533204001.303:301): pid=12306 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=17 res=1 >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533204001.333:302): pid=12306 uid=0 auid=0 ses=17 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533204001.396:303): pid=12306 uid=0 auid=0 ses=17 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533204001.432:304): pid=12306 uid=0 auid=0 ses=17 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:07 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533204001.434:305): pid=12306 uid=0 auid=0 ses=17 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:00:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:00:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:01:01 gbrpsr000006230 systemd: Created slice User Slice of root. >Aug 2 11:01:01 gbrpsr000006230 systemd: Starting User Slice of root. >Aug 2 11:01:01 gbrpsr000006230 systemd: Started Session 18 of user root. >Aug 2 11:01:01 gbrpsr000006230 systemd: Starting Session 18 of user root. >Aug 2 11:01:01 gbrpsr000006230 systemd: Removed slice User Slice of root. >Aug 2 11:01:01 gbrpsr000006230 systemd: Stopping User Slice of root. >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533204061.455:306): pid=12377 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533204061.456:307): pid=12377 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533204061.458:308): pid=12377 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=18 res=1 >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533204061.482:309): pid=12377 uid=0 auid=0 ses=18 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533204061.485:310): pid=12377 uid=0 auid=0 ses=18 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533204061.604:311): pid=12377 uid=0 auid=0 ses=18 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:07 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533204061.607:312): pid=12377 uid=0 auid=0 ses=18 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:01:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:01:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:02:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:02:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:02:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_11:02:51 >Aug 2 11:02:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533204224.489:313): pid=12618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=12618 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533204224.489:314): pid=12618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=12618 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533204224.506:315): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=12618 suid=74 rport=51386 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=35.53.49.145 terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533204224.507:316): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=12618 suid=74 rport=51386 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=35.53.49.145 terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533204224.759:317): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=35.53.49.145 terminal=ssh res=failed' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533204224.761:318): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12618 suid=74 rport=51386 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=35.53.49.145 terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=USER_ERR msg=audit(1533204224.762:319): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:bad_ident grantors=? acct="?" exe="/usr/sbin/sshd" hostname=gbrpsr000000276.intranet.barcapint.com addr=35.53.49.145 terminal=ssh res=failed' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533204224.763:320): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=12616 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533204224.763:321): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=12616 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:03:48 gbrpsr000006230 audit_log: type=USER_LOGIN msg=audit(1533204224.763:322): pid=12616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login acct="root" exe="/usr/sbin/sshd" hostname=? addr=35.53.49.145 terminal=ssh res=failed' >Aug 2 11:03:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:03:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:04:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:04:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:05:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:05:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:06:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:06:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:07:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:07:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:07:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_11:07:51 >Aug 2 11:07:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 11:08:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:08:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:09:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:09:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:10:01 gbrpsr000006230 systemd: Created slice User Slice of root. >Aug 2 11:10:01 gbrpsr000006230 systemd: Starting User Slice of root. >Aug 2 11:10:01 gbrpsr000006230 systemd: Started Session 19 of user root. >Aug 2 11:10:01 gbrpsr000006230 systemd: Starting Session 19 of user root. >Aug 2 11:10:01 gbrpsr000006230 systemd: Removed slice User Slice of root. >Aug 2 11:10:01 gbrpsr000006230 systemd: Stopping User Slice of root. >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533204601.632:323): pid=13049 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_access,pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533204601.632:324): pid=13049 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533204601.634:325): pid=13049 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=19 res=1 >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533204601.668:326): pid=13049 uid=0 auid=0 ses=19 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533204601.720:327): pid=13049 uid=0 auid=0 ses=19 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=CRED_DISP msg=audit(1533204601.752:328): pid=13049 uid=0 auid=0 ses=19 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:08 gbrpsr000006230 audit_log: type=USER_END msg=audit(1533204601.755:329): pid=13049 uid=0 auid=0 ses=19 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_loginuid,pam_keyinit,pam_limits,pam_systemd,pam_unix acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >Aug 2 11:10:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:10:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:11:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:11:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:12:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:12:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:12:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_11:12:51 >Aug 2 11:12:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 11:13:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:13:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:14:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:14:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:15:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:15:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:16:48 gbrpsr000006230 systemd: Created slice User Slice of root. >Aug 2 11:16:48 gbrpsr000006230 systemd: Starting User Slice of root. >Aug 2 11:16:48 gbrpsr000006230 systemd-logind: New session 20 of user root. >Aug 2 11:16:48 gbrpsr000006230 systemd: Started Session 20 of user root. >Aug 2 11:16:48 gbrpsr000006230 systemd: Starting Session 20 of user root. >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533205007.820:330): pid=13520 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=13520 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533205007.820:331): pid=13520 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=13520 suid=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533205007.823:332): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=13520 suid=74 rport=44688 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_SESSION msg=audit(1533205007.823:333): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 mac=hmac-sha1 pfs=diffie-hellman-group-exchange-sha256 spid=13520 suid=74 rport=44688 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533205008.233:334): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=ssh res=failed' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533205008.260:335): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=ssh res=failed' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533205008.280:336): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=44688 acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533205008.280:337): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=SHA256:3e:1d:09:ae:a8:d3:21:58:1c:fb:0d:a8:9e:5f:7e:7b:8c:01:92:ed:cb:2a:c9:0a:26:f9:5d:bc:a1:b5:18:0e rport=44688 acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_ACCT msg=audit(1533205008.291:338): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_faillock,pam_unix,pam_localuser acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533205008.291:339): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=13520 suid=74 rport=44688 laddr=10.45.34.78 lport=22 exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=? res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_AUTH msg=audit(1533205008.293:340): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRED_ACQ msg=audit(1533205008.294:341): pid=13519 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=LOGIN msg=audit(1533205008.295:342): pid=13519 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old-auid=4294967295 auid=0 tty=(none) old-ses=4294967295 ses=20 res=1 >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_ROLE_CHANGE msg=audit(1533205008.514:343): pid=13519 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533205008.548:344): pid=13519 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open grantors=pam_selinux,pam_loginuid,pam_selinux,pam_namespace,pam_keyinit,pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_lastlog acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533205008.609:345): pid=13522 uid=0 auid=0 ses=20 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:e8:f5:03:db:1e:d5:a6:5f:80:d7:ff:57:41:69:90:d2:84:65:45:3a:dc:64:fc:4d:71:0b:8c:44:ce:ec:dd:c7 direction=? spid=13522 suid=0 exe="/usr/sbin/sshd" hostname=gbrpsr000006230.intranet.barcapint.com addr=? terminal=pts/0 res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRYPTO_KEY_USER msg=audit(1533205008.609:346): pid=13522 uid=0 auid=0 ses=20 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=SHA256:46:b3:1a:6a:c6:e6:c5:1e:c9:48:e4:c7:c5:a3:91:d4:5a:28:e9:06:94:a5:16:7f:78:e0:b7:23:ff:cb:16:c6 direction=? spid=13522 suid=0 exe="/usr/sbin/sshd" hostname=gbrpsr000006230.intranet.barcapint.com addr=? terminal=pts/0 res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_LOGIN msg=audit(1533205008.615:347): pid=13522 uid=0 auid=0 ses=20 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=/dev/pts/0 res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=USER_START msg=audit(1533205008.616:348): pid=13522 uid=0 auid=0 ses=20 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=/dev/pts/0 res=success' >Aug 2 11:16:48 gbrpsr000006230 audit_log: type=CRED_REFR msg=audit(1533205008.623:349): pid=13522 uid=0 auid=0 ses=20 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/sbin/sshd" hostname=gbrdsr000000233.intranet.barcapint.com addr=22.115.19.192 terminal=ssh res=success' >Aug 2 11:16:50 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:16:50 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:17:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:17:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369. >Aug 2 11:17:51 gbrpsr000006230 logger: SplunkHealth_2018-08-02_11:17:51 >Aug 2 11:17:53 gbrpsr000006230 nimbus: Argument "10.45.34.78" isn't numeric in numeric gt (>) at /opt/nimbus/probes/barclayscapital/bc_health/bc_health.pl line 616. >Aug 2 11:18:49 gbrpsr000006230 nimbus: Use of uninitialized value $pdsTableC in string ne at ./bc_processes.pl line 261. >Aug 2 11:18:49 gbrpsr000006230 nimbus: Reference found where even-sized list expected at ./bc_processes.pl line 369.
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 1611542
: 1472651 |
1472652
|
1472653