Snort mailing list archives
Re: Snort Logs
From: "Marc Quibell" <mquibell () fbfs com>
Date: Thu, 18 Sep 2003 08:46:50 -0500
Log rotate? Post rotate? I've made it a habit to restart my Snort EVERY night, and along with that I delete the alert file, which is then recreated when Snort starts. Good ol cron job every night in the wee hours: kill `cat /var/run/snort_eth1.pid` rm -f /var/log/snort/alert /usr/local/bin/snort -o -D -q -i eth1 -c /usr/local/etc/snort-2.0.7/snort.conf
Hello, I'm running snort 2.0 on Linux 9.0. Does anyone know how to rotate=20 /var/log/snort/alert when it reaches certain size?
------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort Logs Keaton, Lindamaria (Sep 17)
- Re: Snort Logs Demetri Mouratis (Sep 17)
- <Possible follow-ups>
- RE: Snort Logs Keaton, Lindamaria (Sep 17)
- Re: Snort Logs Michael Sconzo (Sep 17)
- RE: Snort Logs Demetri Mouratis (Sep 17)
- RE: Snort Logs Grejda, Eric (Sep 18)
- Re: Snort Logs Marc Quibell (Sep 18)
- RE: Snort Logs Esler, Joel Contractor (Sep 18)
- Re: Snort Logs John Creegan (Sep 18)