Re: [sentinix-list] Clearing snort database

Michel Blomgren <[email protected]>
Newsgroups gmane.linux.sentinix
Message-ID <[email protected]>
Also, depending on what one wants to do, Snort can be either a network 
auditing tool (an enchanced sniffer) or an IDS.  Regular sniffer have very 
limited filtering features, while Snort has great filtering features and an 
already dense db of traffic rules.  It's great for seeing what kind of 
traffic there's on the net, especially when it's so easy to get reference to 
CVE, bugtraq or nessus.   The other use of Snort, as a NIDS, one should 
basically invert the sniffer filter, very few alerts should be generated in 
order to catch that which is uncommon.

	Michel

On Thursday 18 December 2003 20:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote:
> Thanks for the help.
>
>
>
>
>
> ====================================
> Marlon Richards
> Communications Engineer
> West Indies Alumina Company
> Kirkvine Works
> Jamaica
> Tel#:    876-961-7434
> Fax#:   876-961-7464
> Email:  marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected]
>
>
>
>
>              Michel Blomgren
>              <[email protected]
>              org>                                                       To
>              Sent by:                  The SENTINIX Mailing List
>              sentinix-bounces@         <[email protected]>
>              elevenprospect.co                                          cc
>              m
>                                                                    Subject
>                                        Re: [sentinix-list] Clearing snort
>              12/18/2003 01:05          database
>              PM
>
>
>              Please respond to
>                The SENTINIX
>                Mailing List
>              <[email protected]
>                rospect.com>
>
> On Thursday 18 December 2003 17:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote:
> > Hi.
> > My database has so many alerts that it has become impossible for me to go
> > through everything. How can i clear the database and then begin to limit
>
> The easiest way to do it is to enter ACID (from SnortCenter, "alert
> console")
> and choose to see all alerts (not only TCP, UDP, etc. but everything) then
> on
> the bottom, choose "delete" "entire queue" (or something).  If it's really
> many alerts (several hundered MB worth, or even GB) it may take a few
> minutes
> (depending on your hardware).
>
> > the amount of data being collected? I figure i should be able to
>
> deactivate
>
> > some of the rules but is there anything else that i can do to keep the
> > entries in my database manageable?
>
> Keep the alerts to nill (or bare minimum), if you don't you'll have a hard
> time discovering real attacks.  A few alerts (<5) a week, if possible, is a
>
> good goal, as long as you still track what you want to track, i.e. if you
> get
> Blaster-D activity (CyberKit icmp stuff) on your net, you might want to
> keep
> those alerts in there anyway (or why not filter out those bad ICMP packets
> in
> the firewall?).
>
> Take a look at your most common alerts, get their sid (the [snort] link in
> the
> ACID alert listing) and disable them by removing them from following a
> policy
> in the SnortCenter rules listing (you can not disable them if they follow a
>
> policy, you must remove them from following a policy first).
>
> Also:  SnortCenter should _only_ be used in Mozilla, Netscape 6.x or
> Mozilla
> Firebird, MSIE works but not perfectly.
>
>              Michel
>
> > Regards
> >
> >
> >
> >
> > ====================================
> > Marlon Richards
> > Communications Engineer
> > West Indies Alumina Company
> > Kirkvine Works
> > Jamaica
> > Tel#:    876-961-7434
> > Fax#:   876-961-7464
> > Email:  marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected]
> >
> > _______________________________________________
> > SENTINIX mailing list
> > [email protected]
> > http://elevenprospect.com/mailman/listinfo/sentinix
>
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix
>
>
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.