in reply to Re: Re: Snort
in thread Snort output; report changes only?

What don't you like about grep's solutions? His two points are completely valid. Is there something else that you are looking for?

metadoktor

"The doktor is in."

Replies are listed 'Best First'.
Re: Re: Re: Re: Snort
by satanklawz (Beadle) on Jan 15, 2002 at 11:47 UTC
    Well, my only concern is this. Let's say the snort log file gets to be 25 megs in size, it dups it. Thus, 50 meg's of HD space. That's my only concern. I do agree that that method works, I'm just wondering if there is another one that doesnt tie up as many system resources and the such.