- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- IDS-9000 Trim Alert Database
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-11-2005 11:48 AM
тАО10-11-2005 11:48 AM
IDS-9000 Trim Alert Database
OS: HP-UX 11.11
Application: HP IDS 9000 B.02.01.32 (J5083AA)
How and where do I trim the ids databases to eliminate alerts and errors that are greater than 3 months old? I have over 35,000 alerts that are displayed when I bring up the gui (/opt/ids/bin/idsgui). Dates shown go back years. I mark all alerts as тАЬreadтАЭ and delete those whose dates are greater than 3 months old. I then save the file and exit the gui. Later when I open the IDS gui, all 35,000+ alerts are again displayed as unread new alerts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-11-2005 12:57 PM
тАО10-11-2005 12:57 PM
Re: IDS-9000 Trim Alert Database
There's a process called 'log file rotation'. Check this document at url below about 'HP Intrusion Detection System/9000 Administrator's Guide: Software Release 2.0' :
http://docs.hp.com/en/J5083-90007/index.html
And also check the thread below :
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=725998
Hope this information can help you.
Cheers,
AW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-12-2005 05:06 AM
тАО10-12-2005 05:06 AM
Re: IDS-9000 Trim Alert Database
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2005 04:16 AM
тАО10-13-2005 04:16 AM
Re: IDS-9000 Trim Alert Database
When performing alert file rotation, you need to rotate the alert.log file on the agent (sensor) system (i.e., /var/opt/ids/alert.log), not the GUI's local alert file.
Regardless, during a resync, the GUI will resync all alerts with a timestamp newer than the most recent alert currently displayed by the GUI. So if you have left recent alerts in the GUI, as it appears that you have, you should only see more recent alerts during a resync. If you remove *all* alerts in the GUi and then perform a resync, you will get *all* alerts in the agent's alert.log file (i.e., all 35K). See p. 49 of the V3.1 Admin Guide available on docs.hp.com.
I noticed that you are running an old version of HIDS. I would encourage you to upgrade to the latest release (V3.1 available on software.hp.com) that has significant performance improvements.
I can't remember off hand if V2.1 had problems with a resync.
Pierre
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-14-2005 07:41 AM
тАО10-14-2005 07:41 AM