[Prelude Hybrid IDS] #259: option to force prelude-lml to start at the end a log regardless on metadata

"Prelude Hybrid IDS" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#259: option to force prelude-lml to start at the end a log regardless on
metadata
---------------------------------+------------------------------------------
 Reporter:  [email protected]  |       Owner:  yoann
     Type:  enhancement          |      Status:  new  
 Priority:  normal               |   Milestone:       
Component:  prelude-lml          |     Version:  0.9  
 Severity:  normal               |    Keywords:       
---------------------------------+------------------------------------------
 a option to always start at the end of a log file regardless of metadata
 would be a nice feature to have. currently if for any reason an instance
 of prelude-lml is down on any host in my environment during a production
 day my operations staff will not restart the process until end of day due
 to the fact that when the process starts it jumps to 100% utilization of a
 cpu until it catches up. In this case it is often more important to get
 the monitoring back up and running then to find out what transpired while
 the prelude-lml process was down. in the case of some of the applications
 we are using it to monitor some of these log files grow to up to 90GB's
 over the course of an 8 hour day, so even a short outage could cause a to
 take several minutes to catchup so I can understand their reluctance.

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/259>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.