Re: [sentinix-list] Clearing snort database
"M. Morgan" <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <28976343.1071779041750.JavaMail.root@wamui05.slb.atl.earthlink.net> |
If I may add something to this, I have a test sensor sitting on our busiest LAN segment. It generates 100,000 +/- events per day with a defualt ruleset. Easily 90% of this is legitimate automated traffic between our servers, this is the point where I identify our legitimate traffic and false positives and remove those rules or modifiy them to get only the traffic I want. I intend to deploy a minimum of three snort nodes and will be quickly buried If I dont trim the ruleset before I deploy them. If Im not mistaken the snort rule itself can be modified and new rules written to meet your specific needs. I do have an additional question regarding the handling of log files though. Is there an automated method for setting the lifespan of log files? Say to delete them after so many days? If not I was going to try and write script that would compress and move old logs and ultimately delete them after 3 months. Additionally, Michel I use IE 6x to access snort center and havent found any trouble yet, do you know what the specific problem may be so I can try and reproduce it and mayhaps try and fix it? Thanks, Michael Morgan -----Original Message----- From: Michel Blomgren <[email protected]> Sent: Dec 18, 2003 1:05 PM To: The SENTINIX Mailing List <[email protected]> Subject: Re: [sentinix-list] Clearing snort database On Thursday 18 December 2003 17:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote: > Hi. > My database has so many alerts that it has become impossible for me to go > through everything. How can i clear the database and then begin to limit The easiest way to do it is to enter ACID (from SnortCenter, "alert console") and choose to see all alerts (not only TCP, UDP, etc. but everything) then on the bottom, choose "delete" "entire queue" (or something). If it's really many alerts (several hundered MB worth, or even GB) it may take a few minutes (depending on your hardware). > the amount of data being collected? I figure i should be able to deactivate > some of the rules but is there anything else that i can do to keep the > entries in my database manageable? Keep the alerts to nill (or bare minimum), if you don't you'll have a hard time discovering real attacks. A few alerts (<5) a week, if possible, is a good goal, as long as you still track what you want to track, i.e. if you get Blaster-D activity (CyberKit icmp stuff) on your net, you might want to keep those alerts in there anyway (or why not filter out those bad ICMP packets in the firewall?). Take a look at your most common alerts, get their sid (the [snort] link in the ACID alert listing) and disable them by removing them from following a policy in the SnortCenter rules listing (you can not disable them if they follow a policy, you must remove them from following a policy first). Also: SnortCenter should _only_ be used in Mozilla, Netscape 6.x or Mozilla Firebird, MSIE works but not perfectly. Michel > > Regards > > > > > ==================================== > Marlon Richards > Communications Engineer > West Indies Alumina Company > Kirkvine Works > Jamaica > Tel#: 876-961-7434 > Fax#: 876-961-7464 > Email: marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected] > > _______________________________________________ > SENTINIX mailing list > [email protected] > http://elevenprospect.com/mailman/listinfo/sentinix _______________________________________________ SENTINIX mailing list [email protected] http://elevenprospect.com/mailman/listinfo/sentinix