[Prelude Hybrid IDS] #259: option to force prelude-lml to start at the end a log regardless on metadata
"Prelude Hybrid IDS" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#259: option to force prelude-lml to start at the end a log regardless on metadata ---------------------------------+------------------------------------------ Reporter: [email protected] | Owner: yoann Type: enhancement | Status: new Priority: normal | Milestone: Component: prelude-lml | Version: 0.9 Severity: normal | Keywords: ---------------------------------+------------------------------------------ a option to always start at the end of a log file regardless of metadata would be a nice feature to have. currently if for any reason an instance of prelude-lml is down on any host in my environment during a production day my operations staff will not restart the process until end of day due to the fact that when the process starts it jumps to 100% utilization of a cpu until it catches up. In this case it is often more important to get the monitoring back up and running then to find out what transpired while the prelude-lml process was down. in the case of some of the applications we are using it to monitor some of these log files grow to up to 90GB's over the course of an 8 hour day, so even a short outage could cause a to take several minutes to catchup so I can understand their reluctance. -- Ticket URL: <https://trac.prelude-ids.org/ticket/259> Prelude Hybrid IDS <http://www.prelude-ids.org> The Prelude Hybrid Intrusion Detection System suite _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel