DB Maintenance

"Schubert, Aaron" <[email protected]> Tue, 9 Nov 2010 13:24:23 -0600
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <950F909D7BFFA041A0714E004BE2E96528C0DF7228@EXCHVS5A.mx.state.mo.us>
Thanks Steve and Frederic for your previous response.  Especially Steve, your document was the exact documentation I used to get my Prelude SIEM implementation up and running.

I have used the preludedb-admin commands with success on the heartbeats, but when I try to clean up alerts I get the following error.

preludedb-admin delete alert "type=mysql name=prelude user=prelude pass=ismo301"  --criteria "alert.create_time < 2010-11-1"
delete event failed: The total number of locks exceeds the lock table size.
Error at transaction 1000. Use --offset 1000 to resume operation.
18446744071566262268 'delete' events processed in 42.289796 seconds (0.000000 seconds/events - 436198464373120896.000000 delete/sec average).
18446744071566262268 events processed in 42.289796 seconds (0.000000 seconds/events - 436198464373120896.000000 events/sec average).
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-user