Snort mailing list archives

RE: Flushing the data from the MySQL database


From: "Josh Berry" <josh.berry () netschematics com>
Date: Tue, 14 Oct 2003 10:47:48 -0500 (CDT)

This is already built into ACID.  Just build a second (archive DB) and
then configure the primary ACID/DB in acid_conf.php.  Set the archive DB
parameters (much the same as the regular).  Whenever you run a query you
will see a drop down at the bottom that allows you to Move or Copy the
results of the query (or items you select) to the Archive DB.

Dear all,

Sorry to barge in on this particular conversation but I would also be
very interested in the script for clearing down the Mysql DB into
archive.

The data I am accumulating does tend to get rather large and automating the
archive process would be a god send.

With thanks

Michael

################################################################

Michael Parkinson BSc(Hons)
Technical Director
Intellnet Limited
5 Priors
London Road
Bishops Stortford
Hertfordshire
CM23 5ED
UK

Telephone     :       01279 602800
DDI           :       01279 602805
Fax           :       01279 602815
Mobile                :       07770 380511
Email         :       michael () intellnet net uk
                      michael () parkinson co uk
Web           :       http://www.ishop.co.uk
                      http://www.intellnet.net.uk

################################################################

-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net]On Behalf Of Schmehl,
Paul L
Sent: Tuesday, October 14, 2003 3:46 PM
To: Kaplan, Andrew H.; snort-users () lists sourceforge net
Subject: RE: [Snort-users] Flushing the data from the MySQL database


-----Original Message-----
From: Kaplan, Andrew H. [mailto:AHKAPLAN () PARTNERS ORG]
Sent: Tuesday, October 14, 2003 8:54 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Flushing the data from the MySQL database


I was running Snort on a trial basis, and I am now ready to
have it run in full operational mode. There is a considerable
amount of data in the datbase, and I would like to remove it,
and start fresh. The database I am using is MySQL 4.0.14.
What is the easiest way to do this.

The easiest way I know of is to use the script that I and two other
people have developed.  It allows you to delete or archive db records in
mysql for any period of time that you choose.  I use it to keep 7 days
worth of data in the active db and archive everything else.

If you're interested in it, send me email.

Eric, maybe we should make this available on the site?  If so, how would
I go about doing that?

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/


-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=ort-users



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



Thanks,
Josh Berry, CTO
LinkNet-Solutions
469-831-8543
josh.berry () linknet-solutions com




Thanks,
Josh Berry, CTO
LinkNet-Solutions
469-831-8543
josh.berry () linknet-solutions com



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: