Snort mailing list archives

Backup questions


From: "Subba Rao" <sailorn () attglobal net>
Date: Wed, 13 Nov 2002 20:1:10 -0500

The few installations of snort I did in production environment had only the log file ("alerts") which Snort was writing 
too.  This file was massaged and created neat/meaningful web pages and alerts were sent out to the admins.  At the end 
of the day I did backup the "alerts" file to the backup (Tivoli) server and then copied /dev/null over "alerts" for the 
next day.

Now I plan to use the Snort + Acid combination.  In this setup, Acid seems to use MySql (or other preffered SQL 
server).  At the end of the day, I would like to backup these alerts/warnings for a few months.  In this case, what do 
I backup? There is no "alerts" file.  If it is the database, then what are the database files that I need to backup?
Once backup is done, how do I clean up the DB for the next day alerts/warnings?

Thank you in advance for any help.

Subba Rao
sailorn () attglobal net
2002-11-13




-------------------------------------------------------
This sf.net email is sponsored by: Are you worried about 
your web server security? Click here for a FREE Thawte 
Apache SSL Guide and answer your Apache SSL security 
needs: http://www.gothawte.com/rd523.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: