Snort mailing list archives

Event Cache


From: "Paul McMonagle" <paul () dbu edu>
Date: Tue, 09 Nov 2004 09:04:59 -0600

Greetings,

I am currently running snort on a Suse 9.0 box. I am logging to a mysql
database. I use acid to parse the logs and generate events. Lately
however, I've run into somewhat of a snag. My event cache is becoming
too large. When I attempt to delete the generated alerts (most false
positives.) The "clear event cache" button only gives me a time out
request. Is there a way to clear the event log without using the web
interface?

Thanks for your help in advance. I'm new to the whole snort business. 

Paul McMonagle
Network Security
Dallas Baptist University
ext: 8823
Pager: 1907438

Psalms 84:11
For the LORD God is a sun and shield;
The LORD gives grace and glory;
No good thing does He withhold from 
those who walk uprightly.


-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: