HP Host Intrusion Detection System (HIDS) manual Enabling Large Numbers of Agents

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 43
Image 43

Configuration

Enabling Large Numbers of Agents

Enabling Large Numbers of Agents

If you have more than about 20 agent systems, you may have to modify a kernel parameter and/or a network parameter. The procedures are described below in the sections:

“Enabling Over 23 Agents (Thread Limits)” on page 31

“Enabling Over 20 Inbound Requests” on page 32

Enabling Over 23 Agents (Thread Limits)

NOTE

NOTE

Step 1.

Step 2.

Step 3.

Step 4.

Step 5.

Step 6.

Step 7.

Step 8.

You need to ensure that the administration system provides enough threads per process to handle the maximum number of agent systems you will monitor at one time. This value is specified by the tunable kernel parameter max_thread_proc. You can compute its minimum value from the formula:

max_thread_proc = 2 * num_agents + 18

where num_agents is the number of agent systems to be monitored.

By default, max_thread_proc is set to its minimum value, 64, which allows for 23 agents. The maximum value of max_thread_proc is governed by the configurable kernel parameter nkthread, which you may need to increase if you have a larger number of agents.

max_thread_proc became a dynamic tunable in HP-UX 11i version 1.6. In prior systems, a change to it will require a reboot.

To change the value of max_thread_proc

In HP-UX 11i version 2, the modification of kernel tunables and kernel configuration was moved from SAM to the kcweb system configuration interface. Please see Managing Systems and Workgroups: A Guide for HP-UX System Administrators for details.

Run sam, the HP-UX System Administration Manager (SAM)

Select Kernel Configuration

Select Configurable Parameters

Highlight max_thread_proc

Select Actions > Modify Configurable Parameter

Enter your new value in the Formula/Value box

Choose OK. Your new value shows in the Pending column.

Select File > Exit.

Chapter 2

31

Page 43
Image 43
HP Host Intrusion Detection System (HIDS) manual Enabling Large Numbers of Agents, Enabling Over 23 Agents Thread Limits