Snort mailing list archives
Re: Archive Database in ACID
From: "Lawrence Reed" <Lawrence.Reed () noaa gov>
Date: Thu, 23 Jan 2003 15:20:59 +0000
I saw this problem also, go to "application cache and status" from the main page. Then click "rebuild alert cache". This worked for me.
Counselman, Chris Contractor/Sverdrup wrote:
I am running RedHat 8.0, snort 1.9.0, and ACID .9.6b22 logging to a mysql database. I have two acid directories, one to connect to the alert database and one to connect to the archive database. I am trying to move current alerts to the archive database. I setup everything and can move or copy alerts to the archive database once and then view those alerts. When I try to move or copy alerts again it says successful move to the archive but when I go to the archive instance of ACID, the main screen actually updates the TCP/ICMP/UDP graphs to reflect the extra data but I can not see the data anywhere else. It does not say new alerts added and the new alerts does not show up anywhere but the graph. Thanks, Chris
-- Larry Reed Lawrence.Reed () noaa gov NOAA IT Security Office PGP Public Key: http://search.keyserver.net:11371/pks/lookup?op=get&search=0x7A998772 ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Archive Database in ACID Counselman, Chris Contractor/Sverdrup (Jan 23)
- Re: Archive Database in ACID Lawrence Reed (Jan 23)
- Re: Archive Database in ACID Herve Debar (Jan 24)