RE: snort database administration
"Schmehl, Paul L" <[email protected]> Thu, 17 Jul 2003 09:05:37 -0500
| Newsgroups | gmane.comp.security.ids.snort.snarf |
|---|---|
| Message-ID | <871080DEC5874D41B4E3AFC5C400611E03F60583@UTDEVS02.campus.ad.utdallas.edu> |
In conjunction with a couple of other people, I have written a perl script that allows you to archive the snort database, and then another guy added the capability to choose deletion as opposed to archiving. I can send you the script and the conf file, if you'd like to try it out. It helps if you know perl, because this script has not been widely tested. If you run into problems, you'd have to be able to figure out why. Having said that, I'm using it in a production environment to keep the snort database to a seven day window while archiving everything older. Paul Schmehl ([email protected]) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/~pauls/ > -----Original Message----- > From: malcolm [mailto:[email protected]]=20 > Sent: Thursday, July 17, 2003 4:19 AM > To: [email protected] > Subject: [Snortsnarf] snort database administration >=20 >=20 > Is there an sql script or perl script to tidy up the snort=20 > database? My problem is is that we have about 200,000 new=20 > event records per day. These events fill up other tables such=20 > as iphdr, acid_event etc. I would like to delete all records=20 > from all tables which are older than 2 days. >=20 > Thank you >=20 >=20 > Malcolm Badley >=20 >=20 > _______________________________________________ > SnortSnarf-users mailing list [email protected] > http://www.silicondefense.com/mailman/listinfo/snortsnarf-users >=20