Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

snort correlation stops working with huge numbers of snort logs #8

Open
vzarubin opened this issue Oct 6, 2015 · 0 comments
Open
Assignees

Comments

@vzarubin
Copy link
Collaborator

vzarubin commented Oct 6, 2015

When srvlog tries to correlate ossec message on the snort log it tries to find all relevant logs by snort alert identifier for the closest time window. When it has a lot of ossec messages during the small period of time it tries to copy the same snort messages from unprocessed_snort_logs to snort_logs messages several times. It is proposed to omit correlation between ossec and snort_logs messages, instead of it just consolidate snort alerts with payloads in the snort_logs table directly. When it is required to show snort_logs associated with ossec alert, just open the screen with snort logs with the corresponding filters: snort identifier, time from, time to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants