relatório semanal u&m - investlinux –...

26
Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço em Disco OK Dmesg OK Logs OK Dat Anti-Vírus OK Top - Memória / Processos / Carga OK Processos OK Portas Tcp Udp Abertas OK MRTG - Tráfego OK MRTG - Processador OK Ipaudit Diário OK Ipaudit Semanal OK Squid Reports - TopSites OK Squid Reports - TopUsers OK Nagios - Disponibilidade HTTP 99,48% Nagios - Disponibilidade SMTP 98,62%

Upload: others

Post on 04-Jul-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Relatório Semanal U&M - InvestLinux – 01/11/2011

Uptime / Last OK

Espaço em Disco OK

Dmesg OK

Logs OK

Dat Anti-Vírus OK

Top - Memória / Processos / Carga OK

Processos OK

Portas Tcp Udp Abertas OK

MRTG - Tráfego OK

MRTG - Processador OK

Ipaudit Diário OK

Ipaudit Semanal OK

Squid Reports - TopSites OK

Squid Reports - TopUsers OK

Nagios - Disponibilidade HTTP 99,48%

Nagios - Disponibilidade SMTP 98,62%

Page 2: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Uptime / LastUptime - Tempo Online do ServidorLast - Conexões remotas

[root@uem-gw]# uptime 14:10:56 up 1 day, 5:05, 2 users, load average: 0.45, 0.38, 0.36

[root@uem-gw]# last | sort -k 3 | more

uem ftpd21356 200.208.86.178 Tue Nov 1 10:52 - 10:52 (00:00) uem ftpd21361 200.208.86.178 Tue Nov 1 10:52 - 11:02 (00:10) il-adm pts/0 200.243.67.66 Tue Nov 1 14:10 still logged in wtmp begins Tue Nov 1 10:52:15 2011

Espaço em Disco[root@uem-gw]# df -hSist. Arq. Tam Usad Disp Uso% Montado em/dev/sda3 38G 23G 14G 63% / varrun 1014M 248K 1014M 1% /var/run varlock 1014M 0 1014M 0% /var/lock udev 1014M 52K 1014M 1% /dev devshm 1014M 0 1014M 0% /dev/shm /dev/sdb1 50G 17G 31G 35% /backup /dev/sda1 471M 140M 308M 32% /boot //192.168.0.105/Pessoal 20G 6,0G 15G 30% /ftp/Pessoal //192.168.0.105/Public 200G 114G 87G 57% /ftp/Public //192.168.0.105/Restrito 200G 114G 87G 57% /home/Restrito //192.168.0.100/CorporeRM 47G 17G 31G 36% /home/ponto //192.168.0.105/BKP-linux 15G 8,1G 6,9G 55% /backup-remoto

Page 3: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Dmesg

Dmesg – Alertas de Console (Eventuais Erros de Disco, Rede, Hardware em geral)- Sem informações relevantes -

Logs

Verificação superficial de logs do sistema: ( syslog(tmsys) / secure(tms) / squid(tmsq) )

Dat Anti-Vírus

[root@uem-gw]# freshclamClamAV update process started at Tue Nov 1 14:13:55 2011 main.cld is up to date (version: 54, sigs: 1044387, f-level: 60, builder: sven) daily.cld is up to date (version: 13876, sigs: 19346, f-level: 60, builder: jesler) bytecode.cld is up to date (version: 152, sigs: 38, f-level: 60, builder: edwin)

Semana Anterior:ClamAV update process started at Tue Oct 25 14:24:22 2011 main.cld is up to date (version: 54, sigs: 1044387, f-level: 60, builder: sven) daily.cld is up to date (version: 13848, sigs: 15926, f-level: 60, builder: ccordes) bytecode.cld is up to date (version: 152, sigs: 38, f-level: 60, builder: edwin)

Top - Memória / Processos / Carga- Sem informações relevantes -

Processos- Sem informações relevantes -

Portas Tcp Udp Abertas

[root@uem-gw]# netstat -ap | grep LISTEN | grep -v STREAMtcp 0 0 localhost:60000 *:* LISTEN 6624/postgrey.pid - tcp 0 0 192.168.0.1:5666 *:* LISTEN 6991/nrpe tcp 0 0 *:rsync *:* LISTEN 7191/rsync tcp 0 0 localhost:mysql *:* LISTEN 6549/mysqld tcp 0 0 *:webmin *:* LISTEN 8145/perl tcp 0 0 *:81 *:* LISTEN 7375/apache2 tcp 0 0 *:ftp *:* LISTEN 2632/proftpd: (acce tcp 0 0 10.0.0.29:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.27:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.25:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.23:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.21:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.19:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.17:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.15:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.13:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.11:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.9:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.7:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.3:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.5:domain *:* LISTEN 6072/named tcp 0 0 10.0.0.1:domain *:* LISTEN 6072/named tcp 0 0 192.168.1.1:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.12:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.50:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.11:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.10:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.9:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.8:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.7:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.6:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.4:domain *:* LISTEN 6072/named tcp 0 0 200.243.57.3:domain *:* LISTEN 6072/named tcp 0 0 correio.uem.com.:domain *:* LISTEN 6072/named tcp 0 0 uemnotes.uem.com:domain *:* LISTEN 6072/named tcp 0 0 192.168.0.1:domain *:* LISTEN 6072/named tcp 0 0 localhost:domain *:* LISTEN 6072/named tcp 0 0 *:ssh *:* LISTEN 6446/sshd tcp 0 0 *:3128 *:* LISTEN 16733/(squid)

Page 4: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

tcp 0 0 *:smtp *:* LISTEN 7172/master tcp 0 0 localhost:953 *:* LISTEN 6072/named tcp 0 0 *:1723 *:* LISTEN 7178/pptpd tcp6 0 0 [::]:rsync [::]:* LISTEN 7191/rsync tcp6 0 0 [::]:domain [::]:* LISTEN 6072/named tcp6 0 0 [::]:ssh [::]:* LISTEN 6446/sshd tcp6 0 0 [::]:3000 [::]:* LISTEN 7039/ntop tcp6 0 0 ip6-localhost:953 [::]:* LISTEN 6072/named Obs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.

root@uem-gw:~# netstat -nap | grep LISTEN | grep -v STREAMtcp 0 0 127.0.0.1:60000 0.0.0.0:* LISTEN 6624/postgrey.pid - tcp 0 0 192.168.0.1:5666 0.0.0.0:* LISTEN 6991/nrpe tcp 0 0 0.0.0.0:873 0.0.0.0:* LISTEN 7191/rsync tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN 6549/mysqld tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 8145/perl tcp 0 0 0.0.0.0:81 0.0.0.0:* LISTEN 7375/apache2 tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 2632/proftpd: (acce tcp 0 0 10.0.0.29:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.27:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.25:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.23:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.21:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.19:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.17:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.15:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.13:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.11:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.9:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.7:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.3:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.5:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 10.0.0.1:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 192.168.1.1:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.12:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.50:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.11:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.10:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.9:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.8:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.7:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.6:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.4:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.3:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.2:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 200.243.57.5:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 192.168.0.1:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN 6072/named tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 6446/sshd tcp 0 0 0.0.0.0:3128 0.0.0.0:* LISTEN 16733/(squid) tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 7172/master tcp 0 0 127.0.0.1:953 0.0.0.0:* LISTEN 6072/named tcp 0 0 0.0.0.0:1723 0.0.0.0:* LISTEN 7178/pptpd tcp6 0 0 :::873 :::* LISTEN 7191/rsync tcp6 0 0 :::53 :::* LISTEN 6072/named tcp6 0 0 :::22 :::* LISTEN 6446/sshd tcp6 0 0 :::3000 :::* LISTEN 7039/ntop tcp6 0 0 ::1:953 :::* LISTEN 6072/namedObs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.

Page 5: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

MRTG - Tráfego*

Internet – eth1

Roteador Embratel

VPN Embratel – eth2

VPN Yamana – tun1

Page 6: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

VPN Juruti

VPN Rio Capim – tun4

VPN Zâmbia – tun6

Page 7: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Roteador Jangada189.52.77.26

Roteador Marabá - 189.16.176.6

Page 8: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

UeM ADM – CPU Utilization

UeM ADM – Load

UeM GW – CPU Utilization

UeM GW – Load

*Os gráficos foram comparados com os da semana anterior. Em caso de alteração significativa, é feita a análise de possível problema e relatado como observação abaixo do mesmo.

Os Gráficos não comentados foram considerados normais. Caso queira análise de algum específico, basta fazer o pedido.

Page 9: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Ipaudit Diário

- Sem informações relevantes -

Ipaudit Semanal (Top 10)

IP Host Name Incoming(bytes)

Outgoing(bytes)

Total(bytes)

200.243.057.005 uemnotes.uem.com.br 6,812,763,022 7,616,366,124 14,429,129,146

192.168.000.001 - 2,958,421,162 9,370,544,260 12,328,965,422

192.168.000.103 uemnotes.uem.com.br 4,299,070,503 693,692,049 4,992,762,552

200.243.057.002 correio.uem.com.br 4,324,464,032 417,528,825 4,741,992,857

200.243.057.011 - 1,362,639,772 1,203,340,663 2,565,980,435

192.168.010.024 uemop416.uem.com.br 345,487,279 653,307,567 998,794,846

200.243.057.008 - 788,334,762 148,172,536 936,507,298

192.168.000.105 uemfs.uem.com.br 71,709,563 639,732,458 711,442,021

192.168.000.107 uemantspam.uem.com.br 467,450,669 199,523,415 666,974,084

192.168.000.023 - 582,226,468 18,591,458 600,817,926

Squid Reports Semanal – 23/10/2011 a 30/10/2011

Squid Reports – TopSites

NUM ACCESSED SITE CONNECT BYTES TIME

1 s.glbimg.com 271.29K 877.13M 228.16M

2 osce80-en.url.trendmicro.com 110.20K 73.80M 57.24M

3 au.download.windowsupdate.com 60.18K 4.26G 279.18M

4 mail.yimg.com 50.39K 140.39M 16.26M

5 www.google-analytics.com 41.39K 30.61M 11.87M

6 download.windowsupdate.com 37.77K 1.33G 132.17M

7 www.google.com.br 35.26K 297.45M 148.64M

8 clients1.google.com.br 29.57K 36.02M 11.60M

9 ads.img.globo.com 28.84K 157.58M 144.19M

10 s0.2mdn.net 27.71K 101.54M 19.47M

11 p2.trrsf.com.br 27.21K 47.66M 12.44M

12 safebrowsing-cache.google.com 20.40K 193.93M 73.42M

13 pagead2.googlesyndication.com 19.97K 114.32M 26.71M

14 exame.abril.com.br 19.05K 98.28M 10.79M

15 s1.trrsf.com.br 19.05K 26.02M 6.27M

16 p1.trrsf.com.br 18.74K 64.75M 8.89M

17 imagens.climatempo.com.br 18.70K 21.85M 1.91M

18 www.bb.com.br 16.23K 45.59M 4.85M

19 crl.microsoft.com 15.79K 6.76M 1.93M

20 error:unsupported-request-method 15.20K 24.69M 239.19K

Page 10: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Squid Reports – TopUsers

Squid Reports – Tentativas de acesso a Sites Indevidos

LOCAL ACESSADO IPwww.sexlog.com.br 192.168.9.181www.swingclubbh.kit.net 192.168.6.227www.videosdesexovip.com 192.168.12.197

Obs1: Não foi acrescentada nenhuma expressão ao arquivo /etc/squid/site_proibido.txt a fim de impedir o acesso de sites relacionados.

Page 11: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Trend Micro - InterScan Messaging Security Suite

DADOS DO SISTEMA

NOME VERSÃO CORRENTE DISPONÍVEL VERSÃO ANTERIORScan engine 9.500.1005 9.500.1005 9.200.1012Virus pattern 8.539.00 8.539.00 8.519.00Spyware/grayware pattern 0.871.00 0.871.00 0.871.00IntelliTrap pattern 0.161.00 0.161.00 0.161.00IntelliTrap exceptions 0.707.00 0.707.00 0.705.00Anti-spam engine 6.8.1017 6.8.1017 6.8.1017Spam pattern 18486.003 18486.003 18472.001IMSS Version 7.0-Build_Linux_3216 N/A

ESTATÍSTICAS

PERÍODO: ÚLTIMOS 7 DIAS

RESUMO

Scanning Conditions Total %Malicious code 4 0.01%Spyware/grayware 0 0%Spam 18395 27.92%Phish 5 0.01%Attachment 0 0%Size 62 0.09%Content 844 1.28%Others 0 0%Scanning exceptions 9 0.01%

GRÁFICOS – PERÍODO 23/10/2011 A 29/10/2011Spam by Action

Spam ActionsDetections Message % Size (MB)

Total spam message count 45600 100.00 247.050

Quarantined 17309 37.96 247.050

Deleted 0 0.00 0.000

Tagged 17309 37.96 247.050

Other 0 0.00 0.000

Rejected by NRS 28291 62.04 N/A

Rejected by IP Profiler 0 0.00 N/A

Page 12: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Top 10 Spam RecipientsRecipient Total Message Count Total Spam Msgs Spam Msgs % Spam Size (MB) Spam Size %

[email protected] 654 358 54.74 7.966 [email protected] 954 260 27.25 5.305 [email protected] 343 247 72.01 3.381 [email protected] 365 245 67.12 3.782 [email protected] 401 244 60.85 3.326 [email protected] 571 230 40.28 4.742 [email protected] 472 229 48.52 3.816 [email protected] 268 222 82.84 3.928 [email protected] 336 214 63.69 3.293 29.08

[email protected] 751 212 28.23 2.907 30.63

Virus and Malicious Code Summary

Detections Message %

Total detections 3 100.00

Messages deleted 3 100.00

Messages quarantined 0 0.00

Attachments cleaned 0 0.00

Messages with attachments deleted 0 0.00

Messages blocked by IP Profiler 0 0.00

Top 10 Virus and Malicious Code Detections1WORM_MYDOOM.GEN 32N/A 03N/A 04N/A 05N/A 06N/A 07N/A 08N/A 09N/A 0

10N/A 0

Top 10 Virus RecipientsRecipient Total Message Count Total Virus Msgs Virus Msgs % Virus Size (MB) Virus Size %

[email protected] 375 3 0.80 0.119 0.252N/A 0 0 0.00 0.000 0.003N/A 0 0 0.00 0.000 0.004N/A 0 0 0.00 0.000 0.005N/A 0 0 0.00 0.000 0.006N/A 0 0 0.00 0.000 0.007N/A 0 0 0.00 0.000 0.008N/A 0 0 0.00 0.000 0.009N/A 0 0 0.00 0.000 0.00

10N/A 0 0 0.00 0.000 0.00

Page 13: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

CACTI – Gráficos

Período de 25/10/2011 a 01/11/2011

UEMFS

Page 14: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço
Page 15: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

UEMICA

Page 16: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

UEMNOTES

Page 17: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

UEMPRD

Page 18: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço
Page 19: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

UEMRMSA

Page 20: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço
Page 21: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Nagios

Disponibilidade – últimos 7 dias

Host Service % Time OK% Time Warning

% Time Unknown

% Time Critical

% Time Undetermined

internet_embratel Rede_Ping99.383% (99.383%)

0.339% (0.339%)

0.000% (0.000%)

0.278% (0.278%)

0.000%

uem1_Rede_Ping99.562% (99.562%)

0.207% (0.207%)

0.000% (0.000%)

0.231% (0.231%)

0.000%

link-jangada Rede_Ping66.099% (66.099%)

0.051% (0.051%)

0.000% (0.000%)

33.851% (33.851%)

0.000%

link-juruti Rede_Ping95.097% (95.097%)

0.397% (0.397%)

0.000% (0.000%)

4.506% (4.506%)

0.000%

uem1_Rede_Ping80.890% (80.890%)

0.205% (0.205%)

0.000% (0.000%)

18.906% (18.906%)

0.000%

link-riocapim Rede_Ping96.397% (96.397%)

0.899% (0.899%)

0.000% (0.000%)

2.704% (2.704%)

0.000%

uem1_Rede_Ping97.992% (97.992%)

0.742% (0.742%)

0.000% (0.000%)

1.266% (1.266%)

0.000%

link-yamana Rede_Ping95.728% (95.728%)

0.919% (0.919%)

0.000% (0.000%)

3.353% (3.353%)

0.000%

uem1_Rede_Ping97.941% (97.941%)

0.696% (0.696%)

0.000% (0.000%)

1.363% (1.363%)

0.000%

link-zambia Rede_Ping84.812% (84.812%)

0.967% (0.967%)

0.000% (0.000%)

14.221% (14.221%)

0.000%

uem1_Rede_Ping97.883% (97.883%)

0.739% (0.739%)

0.000% (0.000%)

1.377% (1.377%)

0.000%

nagios_remoto Rede_Http99.851% (99.851%)

0.000% (0.000%)

0.000% (0.000%)

0.149% (0.149%)

0.000%

uem1_Rede_Http99.875% (99.875%)

0.000% (0.000%)

0.000% (0.000%)

0.125% (0.125%)

0.000%

router_cisco Rede_Ping99.968% (99.968%)

0.000% (0.000%)

0.000% (0.000%)

0.032% (0.032%)

0.000%

Rede_Telnet99.968% (99.968%)

0.000% (0.000%)

0.000% (0.000%)

0.032% (0.032%)

0.000%

uem1_Rede_Ping99.968% (99.968%)

0.000% (0.000%)

0.000% (0.000%)

0.032% (0.032%)

0.000%

storage-119 Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

storage-120 Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-B Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-C Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-D Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-E Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

switch-3com-F Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-adm Local_Carga100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Processos100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:82100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-gw Local_Carga100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Page 22: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Local_Disk_backup100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_bkpremoto

96.965% (96.965%)

0.000% (0.000%)

0.000% (0.000%)

3.035% (3.035%)

0.000%

Local_Disk_ftp_pessoal

96.965% (96.965%)

0.000% (0.000%)

0.000% (0.000%)

3.035% (3.035%)

0.000%

Local_Disk_ftp_public

96.965% (96.965%)

0.000% (0.000%)

0.000% (0.000%)

3.035% (3.035%)

0.000%

Local_Disk_home_ponto

99.952% (99.952%)

0.000% (0.000%)

0.000% (0.000%)

0.048% (0.048%)

0.000%

Local_Disk_home_restrito

96.965% (96.965%)

0.000% (0.000%)

0.000% (0.000%)

3.035% (3.035%)

0.000%

Local_Processos100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Dns100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ftp100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:8199.949% (99.949%)

0.000% (0.000%)

0.000% (0.000%)

0.051% (0.051%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Squid:312899.803% (99.803%)

0.000% (0.000%)

0.000% (0.000%)

0.197% (0.197%)

0.000%

uem1_Local_Disk_ftp_public

99.900% (99.900%)

0.000% (0.000%)

0.000% (0.000%)

0.100% (0.100%)

0.000%

uem1_Local_Disk_home_ponto

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemantspam-imss Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_TrendImss100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_TrendPolices100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemap-aplicacao Rede_Ping99.957% (99.957%)

0.000% (0.000%)

0.000% (0.000%)

0.043% (0.043%)

0.000%

uembdcRede_Active Directory

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Active Directory

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uembes-blackberry Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_LotusDomino100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemdev Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP99.008% (99.008%)

0.000% (0.000%)

0.000% (0.000%)

0.992% (0.992%)

0.000%

uemfs-fileserver Rede_Http96.944% (96.944%)

0.000% (0.000%)

0.000% (0.000%)

3.056% (3.056%)

0.000%

Rede_NetBios99.920% (99.920%)

0.000% (0.000%)

0.000% (0.000%)

0.080% (0.080%)

0.000%

Rede_Ping99.922% (99.922%)

0.000% (0.000%)

0.000% (0.000%)

0.078% (0.078%)

0.000%

uem1_Rede_NetBios100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemica-metaframe Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Metaframe100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Page 23: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Metaframe

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemmine-database Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Sql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Sql99.957% (99.957%)

0.000% (0.000%)

0.000% (0.000%)

0.043% (0.043%)

0.000%

uemnotes-correio Rede_Https99.852% (99.852%)

0.000% (0.000%)

0.000% (0.000%)

0.148% (0.148%)

0.000%

Rede_Ldap99.852% (99.852%)

0.000% (0.000%)

0.000% (0.000%)

0.148% (0.148%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Smtp99.852% (99.852%)

0.000% (0.000%)

0.000% (0.000%)

0.148% (0.148%)

0.000%

uem1_Rede_Https99.852% (99.852%)

0.000% (0.000%)

0.000% (0.000%)

0.148% (0.148%)

0.000%

uem1_Rede_Smtp99.852% (99.852%)

0.000% (0.000%)

0.000% (0.000%)

0.148% (0.148%)

0.000%

uemprd Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemrmsa-database Rede_Oracle99.931% (99.931%)

0.000% (0.000%)

0.000% (0.000%)

0.069% (0.069%)

0.000%

Rede_Ping99.931% (99.931%)

0.000% (0.000%)

0.000% (0.000%)

0.069% (0.069%)

0.000%

uem1_Rede_Oracle100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemvm-vmware Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

vm-isodoc Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Postgresql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Postgresql

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Average98.832% (98.832%)

0.068% (0.068%)

0.000% (0.000%)

1.100% (1.100%)

0.000%

NTOP

Page 24: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço
Page 25: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

Trend Micro - Office Scan

Update Status for Networked Computers

* itens marcados com a cor amarela possuem a mesma versão da semana anterior

Top 10 Security Risk Statistics for Networked Computers

Virus/Malware Statistics:

Virus/Malware

Name Infections

HTML_IFRAME.AUO 13927

Mal_Otorun1 4142

PE_MABEZAT.B-O 3835

TSC_GENCLEAN 2610

PAK_Generic.001 1691

Mal_Sality 1614

PE_SALITY.EN-1 1585

WORM_OTOIT.SMT 1257

TROJ_Generic.DIT 1098

EXPL_CPLNK.SM 1086

Infected Computers

Name Detections Log

HP-DISPATCH1 1828 View

UEMPABX 1262 View

UEMMBB317 936 View

UEMOP503 902 View

UEMFS 831 View

UEMOP706 763 View

UEMOP807 574 View

Page 26: Relatório Semanal U&M - InvestLinux – 01/11/2011portal.uem.com.br/relatorio/2011/relatorio-uem... · Relatório Semanal U&M - InvestLinux – 01/11/2011 Uptime / Last OK Espaço

HP21900126961 490 View

UEMMBB312 465 View

UEMOP509 439 View

Infection Source

Name Detections

HP-DISPATCH2\ADMINISTRATOR 1049

HP33671896628\EDWIN SIKAKENA 331

HP33671896628\OLIVER CHILESHE 77

HP33671896628\GILLY NYIRENDA 70

192.168.9.242\ADMINISTRADOR 70

HP33671896628\LOMBE CHOMBA 64

U-92CFD590AD0D4\MAINTENANCE 45

192.168.4.12\KEILLA REGINA 35

192.168.9.38\ADMINISTRADOR 34

\\192.168.0.133\GUEST 22

Spyware/Grayware Statistics:

Spyware/Grayware

Name Infections

CRCK_KEYGEN 1348

HKTL_ULTRASURF 1190

SPYW_ARDAKEY 285

GRAY_Gen 177

GRAY_GEN.0Z1013S 71

ADW_SAVENOW.BO 29

HKTL_USURF 25

CRCK_JBEAN 23

GRAY_Sml 22

ADW_YABECTOR.SM 18

Infected Computers

Name Detections Log

UEMOP964 2304 View

UEMPABX 286 View

UEMFS 217 View

UEMICA 71 View

UEMNOTES 20 View

UEMMBB01ET 16 View

UEMMBB163 13 View

UEMOP960 8 View

UEMMBB36 8 View

UEMOP957 7 View