33
Relatório Semanal U&M - InvestLinux – 07/12/2016 Servidores Linux Uptime / Last Uptime (Tempo Online do Servidor) Last (Conexões remotas) [root@uem-gw]# uptime  13:29:39 up 371 days, 23:47,  1 user,  load average: 0.30, 0.98, 1.29 [root@uem-adm]# uptime  13:30:06 up 158 days,  1:32,  1 user,  load average: 0.00, 0.05, 0.07 [root@uem-gw]# last | sort -k 3 | more il-adm   pts/0        177.104.87.9     Wed Dec  7 13:29   still logged in   il-adm   pts/1        177.104.87.9     Wed Dec  7 13:29   still logged in   uem      ftpd11746    177-85-2-68-dyna Thu Dec  1 13:36 - 13:36  (00:00)    uem      ftpd11766    177-85-2-68-dyna Thu Dec  1 13:36 - 13:37  (00:00)    uem      ftpd13867    177-85-2-68-dyna Thu Dec  1 14:13 - 14:13  (00:00)    uem      ftpd13868    177-85-2-68-dyna Thu Dec  1 14:13 - 14:15  (00:02)    upload   ftpd29584    185.86.150.37    Thu Dec  1 22:13 - 22:13  (00:00)    vpnuem   ppp0         191.249.13.39    Mon Dec  5 20:39 - 21:21  (00:42)    root     pts/0        192.168.11.210   Tue Dec  6 12:09 - 12:13  (00:04)    root     pts/0        192.168.11.210   Tue Dec  6 17:43 - 17:45  (00:01)    uem      ftpd7980     192.168.11.239   Fri Dec  2 10:33 - 10:33  (00:00)    uem      ftpd7985     192.168.11.239   Fri Dec  2 10:33 - 10:43  (00:10)    uem      ftpd8228     192.168.11.239   Fri Dec  2 10:39 - 10:39  (00:00)    uem      ftpd8640     192.168.11.239   Fri Dec  2 10:50 - 10:50  (00:00)    uem      ftpd8743     192.168.11.239   Fri Dec  2 10:52 - 10:53  (00:00)    uem      ftpd14425    192.168.11.239   Fri Dec  2 11:49 - 11:49  (00:00)    uem      ftpd14459    192.168.11.239   Fri Dec  2 11:50 - 12:00  (00:10)    uem      ftpd14710    192.168.11.239   Fri Dec  2 11:56 - 11:56  (00:00)    root     pts/0        192.168.11.245   Wed Dec  7 07:42 - 07:51  (00:08)    root     pts/0        192.168.11.245   Wed Dec  7 07:54 - 08:03  (00:08)    vpnuem   ppp0         192.168.1.69     Fri Dec  2 17:36 - 17:38  (00:01)    il-adm   pts/0        mail.investlinux Mon Dec  5 09:44 - 09:55  (00:10)    il-adm   pts/0        mail.investlinux Thu Dec  1 14:11 - 16:18  (02:07)    wtmp begins Thu Dec  1 13:36:42 2016 root     pts/0        uemmbb254.uem.co Fri Dec  2 16:43 - 16:56  (00:12) root@uem-adm:~# last | sort -k 3 | more il-adm   pts/0        192.168.0.1      Thu Dec  1 14:30 - 16:18  (01:47)    il-adm   pts/0        192.168.0.1      Wed Dec  7 13:30   still logged in   root     pts/0        192.168.1.47     Mon Dec  5 14:57 - 14:59  (00:01)    andreia  ftpd9810     ::ffff:177.104.8 Thu Dec  1 07:04 - 07:32  (00:28)    andreia  ftpd14355    ::ffff:177.104.8 Thu Dec  1 07:33 - 07:57  (00:23)    andreia  ftpd18732    ::ffff:177.104.8 Thu Dec  1 08:01 - 08:17  (00:15)    andreia  ftpd31334    ::ffff:177.104.8 Thu Dec  1 09:14 - 09:24  (00:10)    andreia  ftpd1648     ::ffff:177.104.8 Thu Dec  1 09:30 - 09:47  (00:16)    andreia  ftpd16950    ::ffff:187.109.1 Fri Dec  2 07:58 - 09:03  (01:05)    andreia  ftpd19399    ::ffff:187.109.1 Fri Dec  2 20:43 - 21:03  (00:19)    andreia  ftpd812      ::ffff:187.109.1 Fri Dec  2 22:09 - 22:44  (00:34)    andreia  ftpd7024     ::ffff:187.109.1 Fri Dec  2 22:48 - 22:53  (00:04)    andreia  ftpd4355     ::ffff:187.109.1 Thu Dec  1 09:46 - 09:59  (00:12)    andreia  ftpd13761    ::ffff:187.109.1 Thu Dec  1 20:13 - 20:23  (00:10)    wtmp begins Thu Dec  1 07:04:38 2016 root     pts/0        uemti03.uem.com. Fri Dec  2 14:53 - 14:58  (00:05)

ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Relatório Semanal U&M ­ InvestLinux – 07/12/2016

Servidores LinuxUptime / Last

Uptime (Tempo Online do Servidor) Last (Conexões remotas)

[root@uem­gw]# uptime 13:29:39 up 371 days, 23:47,  1 user,  load average: 0.30, 0.98, 1.29

[root@uem­adm]# uptime 13:30:06 up 158 days,  1:32,  1 user,  load average: 0.00, 0.05, 0.07

[root@uem­gw]# last | sort ­k 3 | moreil­adm   pts/0        177.104.87.9     Wed Dec  7 13:29   still logged in   il­adm   pts/1        177.104.87.9     Wed Dec  7 13:29   still logged in   uem      ftpd11746    177­85­2­68­dyna Thu Dec  1 13:36 ­ 13:36  (00:00)    uem      ftpd11766    177­85­2­68­dyna Thu Dec  1 13:36 ­ 13:37  (00:00)    uem      ftpd13867    177­85­2­68­dyna Thu Dec  1 14:13 ­ 14:13  (00:00)    uem      ftpd13868    177­85­2­68­dyna Thu Dec  1 14:13 ­ 14:15  (00:02)    upload   ftpd29584    185.86.150.37    Thu Dec  1 22:13 ­ 22:13  (00:00)    vpnuem   ppp0         191.249.13.39    Mon Dec  5 20:39 ­ 21:21  (00:42)    root     pts/0        192.168.11.210   Tue Dec  6 12:09 ­ 12:13  (00:04)    root     pts/0        192.168.11.210   Tue Dec  6 17:43 ­ 17:45  (00:01)    uem      ftpd7980     192.168.11.239   Fri Dec  2 10:33 ­ 10:33  (00:00)    uem      ftpd7985     192.168.11.239   Fri Dec  2 10:33 ­ 10:43  (00:10)    uem      ftpd8228     192.168.11.239   Fri Dec  2 10:39 ­ 10:39  (00:00)    uem      ftpd8640     192.168.11.239   Fri Dec  2 10:50 ­ 10:50  (00:00)    uem      ftpd8743     192.168.11.239   Fri Dec  2 10:52 ­ 10:53  (00:00)    uem      ftpd14425    192.168.11.239   Fri Dec  2 11:49 ­ 11:49  (00:00)    uem      ftpd14459    192.168.11.239   Fri Dec  2 11:50 ­ 12:00  (00:10)    uem      ftpd14710    192.168.11.239   Fri Dec  2 11:56 ­ 11:56  (00:00)    root     pts/0        192.168.11.245   Wed Dec  7 07:42 ­ 07:51  (00:08)    root     pts/0        192.168.11.245   Wed Dec  7 07:54 ­ 08:03  (00:08)    vpnuem   ppp0         192.168.1.69     Fri Dec  2 17:36 ­ 17:38  (00:01)    il­adm   pts/0        mail.investlinux Mon Dec  5 09:44 ­ 09:55  (00:10)    il­adm   pts/0        mail.investlinux Thu Dec  1 14:11 ­ 16:18  (02:07)    wtmp begins Thu Dec  1 13:36:42 2016root     pts/0        uemmbb254.uem.co Fri Dec  2 16:43 ­ 16:56  (00:12)

root@uem­adm:~# last | sort ­k 3 | more il­adm   pts/0        192.168.0.1      Thu Dec  1 14:30 ­ 16:18  (01:47)    il­adm   pts/0        192.168.0.1      Wed Dec  7 13:30   still logged in   root     pts/0        192.168.1.47     Mon Dec  5 14:57 ­ 14:59  (00:01)    andreia  ftpd9810     ::ffff:177.104.8 Thu Dec  1 07:04 ­ 07:32  (00:28)    andreia  ftpd14355    ::ffff:177.104.8 Thu Dec  1 07:33 ­ 07:57  (00:23)    andreia  ftpd18732    ::ffff:177.104.8 Thu Dec  1 08:01 ­ 08:17  (00:15)    andreia  ftpd31334    ::ffff:177.104.8 Thu Dec  1 09:14 ­ 09:24  (00:10)    andreia  ftpd1648     ::ffff:177.104.8 Thu Dec  1 09:30 ­ 09:47  (00:16)    andreia  ftpd16950    ::ffff:187.109.1 Fri Dec  2 07:58 ­ 09:03  (01:05)    andreia  ftpd19399    ::ffff:187.109.1 Fri Dec  2 20:43 ­ 21:03  (00:19)    andreia  ftpd812      ::ffff:187.109.1 Fri Dec  2 22:09 ­ 22:44  (00:34)    andreia  ftpd7024     ::ffff:187.109.1 Fri Dec  2 22:48 ­ 22:53  (00:04)    andreia  ftpd4355     ::ffff:187.109.1 Thu Dec  1 09:46 ­ 09:59  (00:12)    andreia  ftpd13761    ::ffff:187.109.1 Thu Dec  1 20:13 ­ 20:23  (00:10)    wtmp begins Thu Dec  1 07:04:38 2016root     pts/0        uemti03.uem.com. Fri Dec  2 14:53 ­ 14:58  (00:05)

Page 2: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Espaço em disco

[root@uem­gw]# df ­hSist. Arq.            Tam   Usad Disp  Uso% Montado em/dev/sda3              38G   26G  9,9G  73% /varrun                1,5G  292K  1,5G   1% /var/runvarlock               1,5G     0  1,5G   0% /var/lockudev                  1,5G   52K  1,5G   1% /devdevshm                1,5G     0  1,5G   0% /dev/shm/dev/sdb1              50G   40G  7,5G  85% /backup/dev/sda1             471M  140M  308M  32% /boot//192.168.0.106/Pessoal                       30G   27G  3,4G  89% /ftp/Pessoal//192.168.0.100/CorporeRM                       47G   21G   27G  44% /home/ponto//192.168.0.106/Linux_BKP                      110G   92G   19G  83% /backup­remoto//192.168.0.106/TGP   682G  602G   80G  89% /ftp/TGP

[root@uem­adm:]# df ­hSist. Arq.            Tam   Usad Disp  Uso% Montado em/dev/sda3              96G   80G   12G  88% /varrun                2,0G   14M  2,0G   1% /var/runvarlock               2,0G     0  2,0G   0% /var/lockudev                  2,0G   52K  2,0G   1% /devdevshm                2,0G     0  2,0G   0% /dev/shm/dev/sda1             471M  150M  297M  34% /boot//192.168.0.106/Linux_BKP                      110G   92G   19G  83% /backup­remoto

DmesgDmesg – Alertas de Console (Eventuais Erros de Disco, Rede, Hardware em geral)­ Sem informações relevantes ­

LogsVerificação superficial de logs do sistema:

  ( syslog(tmsys) / secure(tms) / squid(tmsq – uem­gw) )

Obs: Foi feito o bloqueio de acesso SSH em uem­gw, devido a constatação de váriastentativas.

Top ­ Memória / Processos / Carga­ Sem informações relevantes ­

Portas Tcp Udp Abertas[root@uem­gw]# netstat ­ap | grep LISTEN | grep ­v STREAMtcp        0      0 localhost:60000         *:*                     LISTEN      8464/postgrey.pid ­tcp        0      0 192.168.0.1:5666        *:*                     LISTEN      13202/nrpe      tcp        0      0 *:10050                 *:*                     LISTEN      10214/zabbix_agentdtcp        0      0 *:rsync                 *:*                     LISTEN      9053/rsync      tcp        0      0 localhost:zebra         *:*                     LISTEN      9034/zebra      tcp        0      0 localhost:mysql         *:*                     LISTEN      8396/mysqld     tcp        0      0 localhost:bgpd          *:*                     LISTEN      9038/bgpd       tcp        0      0 *:webmin                *:*                     LISTEN      10245/perl      tcp        0      0 *:81                    *:*                     LISTEN      2146/apache2    tcp        0      0 *:bgp                   *:*                     LISTEN      9038/bgpd       tcp        0      0 *:ftp                   *:*                     LISTEN      30530/proftpd: (acctcp        0      0 192.168.12.10:domain    *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.29:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.27:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.25:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.23:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.21:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.19:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.17:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.15:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.13:domain        *:*                     LISTEN      7939/named      

Page 3: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

tcp        0      0 10.0.0.11:domain        *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.9:domain         *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.7:domain         *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.3:domain         *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.5:domain         *:*                     LISTEN      7939/named      tcp        0      0 10.0.0.1:domain         *:*                     LISTEN      7939/named      tcp        0      0 201­048­214­114.:domain *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.14:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.29:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.28:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.12:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.50:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.11:domain    *:*                     LISTEN      7939/named      tcp        0      0 177.38.168.10:domain    *:*                     LISTEN      7939/named      tcp        0      0 n009.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 n008.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 n007.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 n006.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 rev2.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 n002.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 rev1.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 uemnotes.uem.com:domain *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.28:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.29:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.12:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.50:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.11:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.10:domain    *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.9:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.8:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.7:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.6:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.4:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.3:domain     *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.2:domain     *:*                     LISTEN      7939/named      tcp        0      0 n001.uem.com.br:domain  *:*                     LISTEN      7939/named      tcp        0      0 200.243.57.5:domain     *:*                     LISTEN      7939/named      tcp        0      0 192.168.2.1:domain      *:*                     LISTEN      7939/named      tcp        0      0 192.168.0.2:domain      *:*                     LISTEN      7939/named      tcp        0      0 192.168.0.1:domain      *:*                     LISTEN      7939/named      tcp        0      0 localhost:domain        *:*                     LISTEN      7939/named      tcp        0      0 *:ssh                   *:*                     LISTEN      8264/sshd       tcp        0      0 *:3128                  *:*                     LISTEN      15214/(squid)   tcp        0      0 *:smtp                  *:*                     LISTEN      23766/smtpd     tcp        0      0 localhost:953           *:*                     LISTEN      7939/named      tcp        0      0 *:1723                  *:*                     LISTEN      9020/pptpd      tcp6       0      0 [::]:rsync              [::]:*                  LISTEN      9053/rsync      tcp6       0      0 [::]:bgp                [::]:*                  LISTEN      9038/bgpd       tcp6       0      0 [::]:domain             [::]:*                  LISTEN      7939/named      tcp6       0      0 [::]:ssh                [::]:*                  LISTEN      8264/sshd       tcp6       0      0 ip6­localhost:953       [::]:*                  LISTEN      7939/named  Obs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.

root@uem­gw:~# netstat ­nap | grep LISTEN | grep ­v STREAMtcp        0      0 127.0.0.1:60000         0.0.0.0:*               LISTEN      8464/postgrey.pid ­tcp        0      0 192.168.0.1:5666        0.0.0.0:*               LISTEN      13202/nrpe      tcp        0      0 0.0.0.0:10050           0.0.0.0:*               LISTEN      10214/zabbix_agentdtcp        0      0 0.0.0.0:873             0.0.0.0:*               LISTEN      9053/rsync      tcp        0      0 127.0.0.1:2601          0.0.0.0:*               LISTEN      9034/zebra      tcp        0      0 127.0.0.1:3306          0.0.0.0:*               LISTEN      8396/mysqld     tcp        0      0 127.0.0.1:2605          0.0.0.0:*               LISTEN      9038/bgpd       tcp        0      0 0.0.0.0:10000           0.0.0.0:*               LISTEN      10245/perl      tcp        0      0 0.0.0.0:81              0.0.0.0:*               LISTEN      2146/apache2    tcp        0      0 0.0.0.0:179             0.0.0.0:*               LISTEN      9038/bgpd       tcp        0      0 0.0.0.0:21              0.0.0.0:*               LISTEN      30530/proftpd: (acctcp        0      0 192.168.12.10:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.29:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.27:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.25:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.23:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.21:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.19:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.17:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.15:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.13:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.11:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.9:53             0.0.0.0:*               LISTEN      7939/named      

Page 4: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

tcp        0      0 10.0.0.7:53             0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.3:53             0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.5:53             0.0.0.0:*               LISTEN      7939/named      tcp        0      0 10.0.0.1:53             0.0.0.0:*               LISTEN      7939/named      tcp        0      0 201.48.214.114:53       0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.14:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.29:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.28:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.12:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.50:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.11:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.10:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.9:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.8:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.7:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.6:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.4:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.3:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.2:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.5:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.28:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.29:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.12:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.50:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.11:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.10:53        0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.9:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.8:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.7:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.6:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.4:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.3:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.2:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 177.38.168.1:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 200.243.57.5:53         0.0.0.0:*               LISTEN      7939/named      tcp        0      0 192.168.2.1:53          0.0.0.0:*               LISTEN      7939/named      tcp        0      0 192.168.0.2:53          0.0.0.0:*               LISTEN      7939/named      tcp        0      0 192.168.0.1:53          0.0.0.0:*               LISTEN      7939/named      tcp        0      0 127.0.0.1:53            0.0.0.0:*               LISTEN      7939/named      tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      8264/sshd       tcp        0      0 0.0.0.0:3128            0.0.0.0:*               LISTEN      15214/(squid)   tcp        0      0 0.0.0.0:25              0.0.0.0:*               LISTEN      24156/smtpd     tcp        0      0 127.0.0.1:953           0.0.0.0:*               LISTEN      7939/named      tcp        0      0 0.0.0.0:1723            0.0.0.0:*               LISTEN      9020/pptpd      tcp6       0      0 :::873                  :::*                    LISTEN      9053/rsync      tcp6       0      0 :::179                  :::*                    LISTEN      9038/bgpd       tcp6       0      0 :::53                   :::*                    LISTEN      7939/named      tcp6       0      0 :::22                   :::*                    LISTEN      8264/sshd       tcp6       0      0 ::1:953                 :::*                    LISTEN      7939/named      Obs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.

[root@uem­adm]# netstat ­ap | grep LISTEN | grep ­v STREAMtcp        0      0 *:10050                 *:*                     LISTEN      5764/zabbix_agentdtcp        0      0 uem­adm:5666            *:*                     LISTEN      5486/nrpe       tcp        0      0 *:10051                 *:*                     LISTEN      20320/zabbix_servertcp        0      0 *:rsync                 *:*                     LISTEN      5565/rsync      tcp        0      0 *:gds_db                *:*                     LISTEN      15880/fbserver  tcp        0      0 localhost:mysql         *:*                     LISTEN      5373/mysqld     tcp        0      0 *:netbios­ssn           *:*                     LISTEN      5582/smbd       tcp        0      0 *:webmin                *:*                     LISTEN      6234/perl       tcp        0      0 portal.uem.com.br:www   *:*                     LISTEN      5723/apache2    tcp        0      0 *:82                    *:*                     LISTEN      5723/apache2    tcp        0      0 *:ssh                   *:*                     LISTEN      7409/sshd       tcp        0      0 localhost:postgresql    *:*                     LISTEN      5450/postgres   tcp        0      0 *:smtp                  *:*                     LISTEN      13691/smtpd     tcp        0      0 *:microsoft­ds          *:*                     LISTEN      5582/smbd       tcp6       0      0 [::]:rsync              [::]:*                  LISTEN      5565/rsync      tcp6       0      0 [::]:ftp                [::]:*                  LISTEN      7943/proftpd: (accetcp6       0      0 [::]:ssh                [::]:*                  LISTEN      7409/sshdObs: Comando mostra na quarta coluna, preferencialmente, o nome do serviço após o caracter “:”.

root@uem­adm:~# netstat ­nap | grep LISTEN | grep ­v STREAM tcp        0      0 0.0.0.0:10050           0.0.0.0:*               LISTEN      5764/zabbix_agentdtcp        0      0 192.168.0.109:5666      0.0.0.0:*               LISTEN      5486/nrpe       tcp        0      0 0.0.0.0:10051           0.0.0.0:*               LISTEN      20320/zabbix_servertcp        0      0 0.0.0.0:873             0.0.0.0:*               LISTEN      5565/rsync      

Page 5: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

tcp        0      0 0.0.0.0:3050            0.0.0.0:*               LISTEN      15880/fbserver  tcp        0      0 127.0.0.1:3306          0.0.0.0:*               LISTEN      5373/mysqld     tcp        0      0 0.0.0.0:139             0.0.0.0:*               LISTEN      5582/smbd       tcp        0      0 0.0.0.0:10000           0.0.0.0:*               LISTEN      6234/perl       tcp        0      0 192.168.0.124:80        0.0.0.0:*               LISTEN      5723/apache2    tcp        0      0 0.0.0.0:82              0.0.0.0:*               LISTEN      5723/apache2    tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      7409/sshd       tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      5450/postgres   tcp        0      0 0.0.0.0:25              0.0.0.0:*               LISTEN      14855/smtpd     tcp        0      0 0.0.0.0:445             0.0.0.0:*               LISTEN      5582/smbd       tcp6       0      0 :::873                  :::*                    LISTEN      5565/rsync      tcp6       0      0 :::21                   :::*                    LISTEN      7943/proftpd: (accetcp6       0      0 :::22                   :::*                    LISTEN      7409/sshd Obs: Comando mostra na quarta coluna a porta do serviço após o caracter “:”.

Page 6: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Squid Reports Semanal – 27/11/2016 a 04/12/2016

Squid Reports – TopSites 

Squid Reports – TopUsers

Page 7: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Squid Reports – Tentativas de acesso a Sites Indevidos

LOCAL ACESSADO  IPwww.flagrasdesexo.blog.br 192.168.18.28

Obs: Não foi acrescentada nenhuma expressão ao arquivo /etc/squid/site_proibido.txt a fim de impedir o acesso desites relacionados.

Page 8: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

OFFICE 365

E­mails – Uso

Caixa de Correio

Page 9: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Armazenamento

Cota

Page 10: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp
Page 11: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Caixa de correio ativas e inativas

Número de caixas de correio ativas e inativas ao longo do tempo. Uma caixa decorreio é considerada inativa se um usuário não fizer logon por mais de 30 dias.

Inativo há 30 ­ 60 dias

Inativo há 61 ­ 90 dias

Inativo há mais de 90 dias

Page 12: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Uso da caixa de correio

Mostra o número total de caixas de correio, caixas de correio que excederam suascotas de armazenamento e caixas de correio que estão usando menos de 25% de seulimite de armazenamento. 

Sistema operacional usado

Mostra o número de sistemas operacionais diferentes nos quais seus usuáriosentraram com suas contas do Office 365 nos últimos 30 dias.

Page 13: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Licenciamento vs Uso Ativo

Visualize   o   uso   ativo   (nos   últimos   30   dias)   de   seus   serviços   do   O365   emcomparação com os serviços realmente licenciados para o seu uso. Use esses dadospara verificar se você está obtendo o máximo do seu investimento em nuvem.

Page 14: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Proteção (dados dos últimos 14 dias)

Principais destinatários de e­mail

Principais remetentes de e­mail

Page 15: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Principais destinatários de spams

Principais destinatários de Malware

Page 16: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Detecções de Spam

Page 17: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Principal malware de e­mail

Page 18: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Emails recebidos e enviados

Page 19: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Anti virus – Bitdefender 

Page 20: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp
Page 21: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

ZABBIX

Triggers mais ativas da semana – TOP 10Hosts que mais geraram alerta no Zabbixx

Fonte:http://192.168.0.109:82/zabbix/report5.php?sid=87d41391d956aaea&form_refresh=1&period=week

Page 22: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Gráficos

Período de 23/11/2016 a 07/12/2016

SERVIDORES LINUX

UEM_ADM ­ CPU Utilization

UEM_ADM ­ Memory Usage

Page 23: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

UEM_ADM ­ Disk Space Usage

UEM_GW ­ CPU Utilization

Page 24: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

UEM_GW ­ Memory Usage

UEM_GW ­ Disk Space Usage

Page 25: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

SERVIDORES WINDOWS

UEMFS – CPU LOAD

UEMFS – Disk Usage

Page 26: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp
Page 27: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp
Page 28: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

UEMICA – CPU Load

UEMICA – Disk space usage

Page 29: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

UEMRMSA – CPU Load

UEMRMSA – Disk Space Usage

Page 30: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp
Page 31: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Relatório de Disponibilidade (SLA) – 23/11/2016 a 07/12/2016

Será exibida a observação e detalhes do problema quando estes atingirem 2%

UEMICA – okUEMRMAP – okUEMRMSA – okUEMFS – okUEMMINE – ok

Fonte: http://   192.168.0.109   :82/zabbix/report2.php

Page 32: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

Nagios

Disponibilidade – últimos 7 dias

Host Service % Time OK% Time Warning

% Time Unknown

% Time Critical

% Time Undetermined

nagios_remoto Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Http100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-adm Local_Carga100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Processos100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:82100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem-gw Local_Carga99.950% (99.950%)

0.050% (0.050%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_Root100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_backup100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_bkpremoto

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_ftp_pessoal

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Disk_home_ponto

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Processos100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Local_Users100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Dns100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ftp100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Http:81100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Squid:3128100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Local_Disk_home_ponto

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemantispam-linux Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SSH100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemap-aplicacao Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemdev Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemfs-fileserver Rede_NetBios100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Page 33: ório Semanal U&M InvestLinux – 07/12/2016portal.uem.com.br/relatorio/relatorio-uem-investlinux... · 2016-12-07 · Espaço em disco [root@uemgw]# df h Sist. Arq. Tam Usad Disp

uem1_Rede_NetBios

100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemica-metaframe Rede_Http99.957% (99.957%)

0.000% (0.000%)

0.000% (0.000%)

0.043% (0.043%)

0.000%

Rede_Metaframe99.228% (99.228%)

0.000% (0.000%)

0.000% (0.000%)

0.772% (0.772%)

0.000%

Rede_Ping99.957% (99.957%)

0.000% (0.000%)

0.000% (0.000%)

0.043% (0.043%)

0.000%

Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Metaframe

99.306% (99.306%)

0.000% (0.000%)

0.000% (0.000%)

0.694% (0.694%)

0.000%

uem1_Rede_TS100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemmine-database Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_Sql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Sql100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemprd Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_SAP100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemrmsa-database Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uemvm-vmware4 Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

vpn-server-mk-lan Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

vpn-server-mk-wan Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

uem1_Rede_Ping100.000% (100.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000% (0.000%)

0.000%

Average99.968% (99.968%)

0.001% (0.001%)

0.000% (0.000%)

0.031% (0.031%)

0.000%