By using this site, you agree to our updated Privacy Policy and our Terms of Use. Manage your Cookies Settings.
437,777 Members | 1,755 Online
Bytes IT Community
+ Ask a Question
Need help? Post your question and get tips & solutions from a community of 437,777 IT Pros & Developers. It's quick & easy.

snort, acid and postgres

P: n/a
Ok, so here is my problem. I am running snort with ACID as the query
interface and FreeBSD with Postgresql 7.2 as the back end database
system. The problem I am encountering is that it takes forever for acid
to query the database and delete alerts. Also, there is no way to have
more than one person query the database without having it crawl. Is
there anyone out there that has experience tweaking postgres so that it
performs faster in this setup? The database is out of the box with no
tweaks to it.

thanks,

Jeremy

---------------------------(end of broadcast)---------------------------
TIP 5: Have you checked our extensive FAQ?

http://www.postgresql.org/docs/faqs/FAQ.html

Nov 12 '05 #1
Share this Question
Share on Google+
1 Reply


P: n/a
There are some web pages that provide specific hints for tuning the
snort + ACID combination, e.g:

http://www.andrew.cmu.edu/~rdanyliw/...aq.html#faq_c9

Having said that, it is worth collecting the information Dann suggested,
as folk on this list can probably give you database tuning tips that the
standard FAQs may not contain.

regards

Mark
Jeremy Hefner wrote:
Ok, so here is my problem. I am running snort with ACID as the query
interface and FreeBSD with Postgresql 7.2 as the back end database
system. The problem I am encountering is that it takes forever for acid
to query the database and delete alerts. Also, there is no way to have
more than one person query the database without having it crawl. Is
there anyone out there that has experience tweaking postgres so that it
performs faster in this setup? The database is out of the box with no
tweaks to it.

---------------------------(end of broadcast)---------------------------
TIP 8: explain analyze is your friend

Nov 12 '05 #2

This discussion thread is closed

Replies have been disabled for this discussion.