Snort mailing list archives
Event Cache
From: "Paul McMonagle" <paul () dbu edu>
Date: Tue, 09 Nov 2004 09:04:59 -0600
Greetings, I am currently running snort on a Suse 9.0 box. I am logging to a mysql database. I use acid to parse the logs and generate events. Lately however, I've run into somewhat of a snag. My event cache is becoming too large. When I attempt to delete the generated alerts (most false positives.) The "clear event cache" button only gives me a time out request. Is there a way to clear the event log without using the web interface? Thanks for your help in advance. I'm new to the whole snort business. Paul McMonagle Network Security Dallas Baptist University ext: 8823 Pager: 1907438 Psalms 84:11 For the LORD God is a sun and shield; The LORD gives grace and glory; No good thing does He withhold from those who walk uprightly. ------------------------------------------------------- This SF.Net email is sponsored by: Sybase ASE Linux Express Edition - download now for FREE LinuxWorld Reader's Choice Award Winner for best database on Linux. http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Event Cache Paul McMonagle (Nov 09)