Re: [sentinix-list] Clearing snort database
Michel Blomgren <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <[email protected]> |
Also, depending on what one wants to do, Snort can be either a network auditing tool (an enchanced sniffer) or an IDS. Regular sniffer have very limited filtering features, while Snort has great filtering features and an already dense db of traffic rules. It's great for seeing what kind of traffic there's on the net, especially when it's so easy to get reference to CVE, bugtraq or nessus. The other use of Snort, as a NIDS, one should basically invert the sniffer filter, very few alerts should be generated in order to catch that which is uncommon. Michel On Thursday 18 December 2003 20:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote: > Thanks for the help. > > > > > > ==================================== > Marlon Richards > Communications Engineer > West Indies Alumina Company > Kirkvine Works > Jamaica > Tel#: 876-961-7434 > Fax#: 876-961-7464 > Email: marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected] > > > > > Michel Blomgren > <[email protected] > org> To > Sent by: The SENTINIX Mailing List > sentinix-bounces@ <[email protected]> > elevenprospect.co cc > m > Subject > Re: [sentinix-list] Clearing snort > 12/18/2003 01:05 database > PM > > > Please respond to > The SENTINIX > Mailing List > <[email protected] > rospect.com> > > On Thursday 18 December 2003 17:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote: > > Hi. > > My database has so many alerts that it has become impossible for me to go > > through everything. How can i clear the database and then begin to limit > > The easiest way to do it is to enter ACID (from SnortCenter, "alert > console") > and choose to see all alerts (not only TCP, UDP, etc. but everything) then > on > the bottom, choose "delete" "entire queue" (or something). If it's really > many alerts (several hundered MB worth, or even GB) it may take a few > minutes > (depending on your hardware). > > > the amount of data being collected? I figure i should be able to > > deactivate > > > some of the rules but is there anything else that i can do to keep the > > entries in my database manageable? > > Keep the alerts to nill (or bare minimum), if you don't you'll have a hard > time discovering real attacks. A few alerts (<5) a week, if possible, is a > > good goal, as long as you still track what you want to track, i.e. if you > get > Blaster-D activity (CyberKit icmp stuff) on your net, you might want to > keep > those alerts in there anyway (or why not filter out those bad ICMP packets > in > the firewall?). > > Take a look at your most common alerts, get their sid (the [snort] link in > the > ACID alert listing) and disable them by removing them from following a > policy > in the SnortCenter rules listing (you can not disable them if they follow a > > policy, you must remove them from following a policy first). > > Also: SnortCenter should _only_ be used in Mozilla, Netscape 6.x or > Mozilla > Firebird, MSIE works but not perfectly. > > Michel > > > Regards > > > > > > > > > > ==================================== > > Marlon Richards > > Communications Engineer > > West Indies Alumina Company > > Kirkvine Works > > Jamaica > > Tel#: 876-961-7434 > > Fax#: 876-961-7464 > > Email: marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected] > > > > _______________________________________________ > > SENTINIX mailing list > > [email protected] > > http://elevenprospect.com/mailman/listinfo/sentinix > > _______________________________________________ > SENTINIX mailing list > [email protected] > http://elevenprospect.com/mailman/listinfo/sentinix > > > _______________________________________________ > SENTINIX mailing list > [email protected] > http://elevenprospect.com/mailman/listinfo/sentinix