Snort mailing list archives

Archive Data Format


From: "Maynard, Jeff S." <Jeff.Maynard () banctec com>
Date: Fri, 7 Mar 2003 13:57:11 -0600

I am starting to archive some of the alert data that is in my MYSQL database
and it appears that the data is being archived in raw format in the data
table rather than in event format in the acid_event table.  A couple of
questions:
 
1) Is this normal?
2) If so, how can I either convert the data to the acid_event table or read
the data so that it makes sense to me?
3) If not, what am I doing wrong?
 
I would like to go back to review the data against some of the active data
to see if problems are still present after I have taken corrective action on
them.
 

Jeff Maynard
BancTec LAN/WAN Services
(972) 450-7999
(214) 968-1164 
 

 


Current thread: