You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If there are residual logs in /var/log/syslog, they will all be processed by DataServer.py when initialized. I would prefer if it only processed real time events.
Two options:
Truncate /var/log/syslog when DataServer.py is initialized.
Start reading from end of /var/log/syslog.
Thoughts/Ideas?
The text was updated successfully, but these errors were encountered:
I like the first, truncate the syslog when run DataServer.py once time.
And I also do that.
The syslog.py can run all the time, even restart DataServer.py several times.
And if never truncate the syslog,it will be bigger and bigger.
The log files should not be modified in my opinion. Better work on the application so it reads only the new data and not from start to finish how it is done. Another interesting option I make here is to transfer the log that arrives in syslog to a specific file. This makes things easier because it does not mix attack logs with system logs, access, etc ... It is possible by editing the configuration file of your log system and put something like this:
if $fromhost-ip startswith '192.168.0.2' then /var/log/snort.log
If there are residual logs in /var/log/syslog, they will all be processed by DataServer.py when initialized. I would prefer if it only processed real time events.
Two options:
Thoughts/Ideas?
The text was updated successfully, but these errors were encountered: