Snort mailing list archives

Re: Snort Logs


From: "Marc Quibell" <mquibell () fbfs com>
Date: Thu, 18 Sep 2003 08:46:50 -0500



Log rotate? Post rotate?

I've made it a habit to restart my Snort EVERY night, and along with that I
delete the alert file, which is then recreated when Snort starts. Good ol cron
job every night in the wee hours:

kill `cat /var/run/snort_eth1.pid`
rm -f /var/log/snort/alert
 /usr/local/bin/snort -o -D -q -i eth1 -c /usr/local/etc/snort-2.0.7/snort.conf

Hello,

I'm running snort 2.0 on Linux 9.0. Does anyone know how to rotate=20
/var/log/snort/alert when it reaches certain size?





-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: