<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS Database files too big in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502020#M98022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whilst my sybase database seems to be getting pruned automatically by SecMon 2.1 my idsmc.log is still growing - it'a almost 12GB now. Did you get a resolution to your problem? Why isn't CW2K managing the size of this file?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jun 2005 09:33:35 GMT</pubDate>
    <dc:creator>d-g-c</dc:creator>
    <dc:date>2005-06-23T09:33:35Z</dc:date>
    <item>
      <title>IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502017#M98019</link>
      <description>&lt;P&gt;I'm receiving this alert from the management centre for IDS sensors :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Name:         IDS database files &lt;/P&gt;&lt;P&gt; Size Limit:   8 GB &lt;/P&gt;&lt;P&gt; Current Usage:128.87% (10.31 GB) &lt;/P&gt;&lt;P&gt; Note:         Current usage is more than the recommended limit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I prune the size of these files automatically within cisco works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502017#M98019</guid>
      <dc:creator>d-g-c</dc:creator>
      <dc:date>2019-03-10T09:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502018#M98020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depends on which version of the IDS MC you're using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Security Monitor 2.0, the database pruning is handled automatically by a database pruning daemon. By default, it will prune the database when it hits 2,000,000 events. This default value can be changed by logging into SecMon and going to Admin -&amp;gt; Data Management -&amp;gt; Database -&amp;gt; Pruning Configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when the database is pruned, by default it will create an archive of the pruned data in a flat file that is stored in ~\CSCOpx\MDC\secmon\AlertPruneData. This is a directory you will want to watch, because it can grow rapidly. If the archive is no longer needed, it is save to delete these files to reclaim disk space. Another recommended option is to change the pruning directory to a network share so that you don&amp;#146;t have to worry about maintaining that directory. To change the directory, go to Admin -&amp;gt; System Configuration -&amp;gt; Prune Archive Location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, if you want to change the thresholds at which you are warned, go to Admin -&amp;gt; Data Management -&amp;gt; Files. For each file you can change the value in the Limit column by just clicking on the current value. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For IDS MC 1.2 see this doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mon_sec/secmon12/ug/ch07.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mon_sec/secmon12/ug/ch07.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2005 16:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502018#M98020</guid>
      <dc:creator>Jeffrey Bollinger</dc:creator>
      <dc:date>2005-05-26T16:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502019#M98021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am having the same issue.  The idsmc.log is almost 8GB itself.  When I try to change the size, it says I do not have the proper space available even thoug I have 5GB of free space.  Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2005 12:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502019#M98021</guid>
      <dc:creator>nickbruno</dc:creator>
      <dc:date>2005-05-27T12:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502020#M98022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whilst my sybase database seems to be getting pruned automatically by SecMon 2.1 my idsmc.log is still growing - it'a almost 12GB now. Did you get a resolution to your problem? Why isn't CW2K managing the size of this file?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2005 09:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502020#M98022</guid>
      <dc:creator>d-g-c</dc:creator>
      <dc:date>2005-06-23T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502021#M98023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi had the same problem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i simply stopped all services by the application, and then removed the idsmdc.log file, that seems not to be the database.&lt;/P&gt;&lt;P&gt;note that you have another file idsmdc.db.&lt;/P&gt;&lt;P&gt;i didn't lost any alert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jul 2005 15:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502021#M98023</guid>
      <dc:creator>cburgarella</dc:creator>
      <dc:date>2005-07-25T15:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Database files too big</title>
      <link>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502022#M98024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi! We also encountered pruned data that is increasing so fast as well as the idsmdc.db. &lt;/P&gt;&lt;P&gt;1. Is it safe to delete old files at /opt/CSCOpx/MDC/secmon/AlertPruneData?  What would be the importance of these files that we should consider for future use?&lt;/P&gt;&lt;P&gt;2. I understand that information in these pruned data no longer exist at idsmdc.db: Events are pruned from the database when the event tables exceed a specified size. The oldest event records are deleted from an event table first. How come the idsmdc.db is still increasing so fast? What does idsdmc.db comprised of?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2005 02:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-database-files-too-big/m-p/502022#M98024</guid>
      <dc:creator>koiflowerhorn</dc:creator>
      <dc:date>2005-08-04T02:19:40Z</dc:date>
    </item>
  </channel>
</rss>

