Snort mailing list archives

RE: BASE/AAnval MySQL dbase management


From: "Irons, Clarence" <Clarence.Irons () hq doe gov>
Date: Thu, 20 Apr 2006 10:41:15 -0400

Aanval to be very helpful in managing our information.

 -----Original Message-----
From:   snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net]  On Behalf Of 
John Hally
Sent:   Thursday, April 20, 2006 9:59 AM
To:     snort-users () lists sourceforge net
Subject:        [Snort-users] BASE/AAnval MySQL dbase management

Hello All,

I'm curious as to how people are managing the mysql backend data that snort
reports.  I've been mulling over adding syslog entries to the mix, but with
the amount of denies I see at the borders/firewalls, the database is going
to get unwieldy pretty fast.  Not being a DBA but knowing enough to get
things up and running, is there any 'canned' scripts out there to help me
out? I'm thinking along the lines of possibly archiving daily/weekly, having
the dbase drop entries older than X, or something to that effect.  

Thoughts/suggestions?

Thanks!



-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid0709&bid&3057&dat1642
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: