Snort mailing list archives

Snort Overloading BASE?


From: James Chase <chase1124 () gmail com>
Date: Wed, 20 Jan 2010 15:24:31 -0500

I'm running snort-2.8.5-1 on CentOS 5.4 and collecting snort alerts to a
database with barnyard2. The problem is snort seems to be generating so many
alerts that whenever I load the BASE page it takes 5 or 10 minutes to
display! I believe it is just processing the new alerts but it really makes
the system unusable.

Is there anything that can be done to clear out the DB of old alerts
automatically or anyone else that has experienced this problem?

-- 
"Beware of all enterprises that require new clothes."
 --  Henry David Thoreau
------------------------------------------------------------------------------
Throughout its 18-year history, RSA Conference consistently attracts the
world's best and brightest in the field, creating opportunities for Conference
attendees to learn about information security's most important issues through
interactions with peers, luminaries and emerging and established companies.
http://p.sf.net/sfu/rsaconf-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: