Re: [sentinix-list] Clearing snort database

"M. Morgan" <[email protected]>
Newsgroups gmane.linux.sentinix
Message-ID <28976343.1071779041750.JavaMail.root@wamui05.slb.atl.earthlink.net>
 If I may add something to this, I have a test sensor sitting on our busiest LAN segment. It generates 100,000 +/- events per day with a defualt ruleset. Easily 90% of this is legitimate automated traffic between our servers, this is the point where I identify our legitimate traffic and false positives and remove those rules or modifiy them to get only the traffic I want. I intend to deploy a minimum of three snort nodes and will be quickly buried If I dont trim the ruleset before I deploy them. If Im not mistaken the snort rule itself can be modified and new rules written to meet your specific needs.

 I do have an additional question regarding the handling of log files though. Is there an automated method for setting the lifespan of log files? Say to delete them after so many days? If not I was going to try and write script that would compress and move old logs and ultimately delete them after 3 months. 

 Additionally, Michel I use IE 6x to access snort center and havent found any trouble yet, do you know what the specific problem may be so I can try and reproduce it and mayhaps try and fix it?

Thanks,
Michael Morgan

-----Original Message-----
From: Michel Blomgren <[email protected]>
Sent: Dec 18, 2003 1:05 PM
To: The SENTINIX Mailing List <[email protected]>
Subject: Re: [sentinix-list] Clearing snort database

On Thursday 18 December 2003 17:42, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote:
> Hi.
> My database has so many alerts that it has become impossible for me to go
> through everything. How can i clear the database and then begin to limit

The easiest way to do it is to enter ACID (from SnortCenter, "alert console") 
and choose to see all alerts (not only TCP, UDP, etc. but everything) then on 
the bottom, choose "delete" "entire queue" (or something).  If it's really 
many alerts (several hundered MB worth, or even GB) it may take a few minutes 
(depending on your hardware).

> the amount of data being collected? I figure i should be able to deactivate
> some of the rules but is there anything else that i can do to keep the
> entries in my database manageable?

Keep the alerts to nill (or bare minimum), if you don't you'll have a hard 
time discovering real attacks.  A few alerts (<5) a week, if possible, is a 
good goal, as long as you still track what you want to track, i.e. if you get 
Blaster-D activity (CyberKit icmp stuff) on your net, you might want to keep 
those alerts in there anyway (or why not filter out those bad ICMP packets in 
the firewall?).

Take a look at your most common alerts, get their sid (the [snort] link in the 
ACID alert listing) and disable them by removing them from following a policy 
in the SnortCenter rules listing (you can not disable them if they follow a 
policy, you must remove them from following a policy first).

Also:  SnortCenter should _only_ be used in Mozilla, Netscape 6.x or Mozilla 
Firebird, MSIE works but not perfectly.

	Michel

>
> Regards
>
>
>
>
> ====================================
> Marlon Richards
> Communications Engineer
> West Indies Alumina Company
> Kirkvine Works
> Jamaica
> Tel#:    876-961-7434
> Fax#:   876-961-7464
> Email:  marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected]
>
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix

_______________________________________________
SENTINIX mailing list
[email protected]
http://elevenprospect.com/mailman/listinfo/sentinix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.