[sentinix-list] Clearing Snort Database (revisited)
"M. Morgan" <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <1460892.1072107060643.JavaMail.root@wamui08.slb.atl.earthlink.net> |
Hello all, I'm trying to clear *all* of the alerts in the database and start from scratch. If I use the method discussed last week on the list and go to snort_center/alerts/delete alerts/ selected, "all on screen or entire query" it will only delete the 50 alerts visable on the screen. There are currently 400,000+ in the database I need to clear. Is there a method in snort center to clear "all" of the alerts in one fell swoop? If not, can someone give me the path to the mysql database files so I can empty them by hand? I have been unsuccessfull in locating them thus far... Ive looked in: /var/lib/mysql# and found: [email protected]:/var/lib/mysql# ls -al total 20592 drwxr-x--- 8 mysql mysql 4096 Dec 19 16:51 . drwxr-xr-x 6 root root 4096 Dec 15 04:52 .. -rw-rw---- 1 mysql root 1007 Dec 19 16:51 Underdog.err -rw-rw---- 1 mysql mysql 3 Dec 19 16:51 Underdog.pid drwx------ 2 mysql mysql 4096 Dec 15 04:52 cacti -rw-rw---- 1 mysql mysql 25088 Nov 23 11:50 ib_arch_log_0000000000 -rw-rw---- 1 mysql mysql 5242880 Dec 19 16:51 ib_logfile0 -rw-rw---- 1 mysql mysql 5242880 Nov 23 11:50 ib_logfile1 -rw-rw---- 1 mysql mysql 10485760 Dec 15 15:49 ibdata1 drwx------ 2 mysql mysql 4096 Dec 15 04:52 mysql -rw-rw---- 1 mysql root 1205 Nov 23 11:52 sandbox.err drwx------ 2 mysql mysql 4096 Dec 15 04:52 snort drwx------ 2 mysql mysql 4096 Dec 15 04:52 snort_archive drwx------ 2 mysql mysql 4096 Dec 15 04:52 snortcenter drwx------ 2 mysql mysql 4096 Nov 23 11:50 test Many thanks. Michael