Snort mailing list archives
RE: Snort Logs
From: "Grejda, Eric" <EGrejda () county allegheny pa us>
Date: Thu, 18 Sep 2003 08:52:02 -0400
When the Snort process is sent the HUP signal, it'll close the file descriptor for that log file and reopen it, essentially opening a new file. You won't have to reboot the system; you won't even have to restart Snort because that's what the `kill -HUP` command does. As for compressing the file, if you have the directive 'compress' in your /etc/logrotate.conf file the log file will be compressed as it's rotated out. -- Eric Grejda -----Original Message----- From: Keaton, Lindamaria [mailto:LKeaton () unionsafe com] Sent: Wednesday, September 17, 2003 2:37 PM To: Demetri Mouratis Cc: snort-users () lists sourceforge net Subject: RE: [Snort-users] Snort Logs How will a new file generate? How I see this, it will kill snort but not restart it. Will I then have to reboot the system, in order for a new alert file to generate. Is that correct, or am I completely wrong? This is what I'm trying to accomplish. I want the alert file to either compress and move to a different directory, but then start a new alert file without kill snort. Is there a way to do this? ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort Logs Keaton, Lindamaria (Sep 17)
- Re: Snort Logs Demetri Mouratis (Sep 17)
- <Possible follow-ups>
- RE: Snort Logs Keaton, Lindamaria (Sep 17)
- Re: Snort Logs Michael Sconzo (Sep 17)
- RE: Snort Logs Demetri Mouratis (Sep 17)
- RE: Snort Logs Grejda, Eric (Sep 18)
- Re: Snort Logs Marc Quibell (Sep 18)
- RE: Snort Logs Esler, Joel Contractor (Sep 18)
- Re: Snort Logs John Creegan (Sep 18)