z/OS Communications Server: IP Messages Volume 4 (EZZ, SNM)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZZ8654I

z/OS Communications Server: IP Messages Volume 4 (EZZ, SNM)
SC27-3657-01

EZZ8654I
TRMD ATTACK Interface flood start:date time,ifcname=ifcname,dipaddr=dipaddr,correlator=correlator,discardcnt=discardcnt,discardp=discardp,
lastsip=lastsip,probeid=probeid,sensorhostname=sensorhostname

Explanation

An interface flood condition for the specified interface has been detected by Intrusion Detection Services (IDS).

In the message text:
date
The date when the interface flood started.
time
The time when the interface flood started.
ifcname
The name of the interface experiencing the interface flood condition.
dipaddr
An IP address assigned to the interface.
correlator
The Intrusion Detection Services (IDS) trace correlator.
discardcnt
The number of packets received on the interface that were discarded or not processed and triggered the interface flood detection.
discardp
The percentage of the total packets received on the interface that were discarded and triggered the interface flood detection.
lastsip
The source IP address, if available, from the packet being discarded when the flood condition was detected.
probeid
The unique identifier of the probe that indicated the interface flood start. See z/OS Communications Server: IP and SNA Codes for a description of the Intrusion Detection Services probe IDs.
sensorhostname
The fully qualified host name of the IDS sensor.

System action

Processing continues.

Operator response

None.

System programmer response

A possible interface flood condition exists for the specified interface. An IDS Trace of the next 100 discarded inbound packets on the interface will be written if tracing was requested by the IDS ATTACK FLOOD policy. Reviewing the IDS Trace data might help determine the cause of the interface flood. If the flood continues for more than five minutes, an EZZ8656I message with additional summary data will be written to syslogd every five minutes until the interface flood condition ends. Reviewing this data might also help to determine the cause of the flood.

Module

EZATRMD

Example

EZZ8654I TRMD ATTACK Interface flood start:07/16/2010 20:19:43.52,ifcname=OSA123,dipaddr=9.67.120.3,
correlator= 57,discardcnt=372,discardp=23,lastsip=9.67.120.73,probeid=04070010,
sensorhostname=MVS123.tcp.company.com

Procedure name

WriteLogEntries

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014