Snort mailing list archives

SQL ALert Logging


From: "Wilcoxen, Scott" <SWilcoxen () macf com>
Date: Thu, 1 May 2003 11:12:45 -0400

I was wondering if it is possible to setup multiple ruletypes and have
them log to different databases.  I was going to take all my
"non-critical" alerts and put them into a separate database.  I was
under the impression I could do this with alert groups in Acid, but when
I setup an Alert Group in acid and add alerts to it, future alerts don't
end up in the group.  I'd rather keep them in the database as I can view
them remotely though Acid, of course with two databases I'd have to
setup to Acid directories on my web server...Anyone have any input on
this?

 

 

 

Scott S Wilcoxen

Macfadden & Associates, Inc.

Email: Swilcoxen at macf dot com

www.macf.com

 


Current thread: