Alerts not stored in SecMon during database compaction period
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-27-2005 02:33 PM - edited 03-10-2019 01:15 AM
I used the idsDbCompact utility to compact the SecMon database which took a few hours. After the compaction, I cannot find in the database any alerts generated by the sensors during the compaction period. Is there a way to recover/retrieve those alerts?
Thanks.
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-27-2005 07:25 PM
During the compaction period, the database and other cisco works services are unavailable. Therefore, none of the events that were generated during this period were logged. Use the link below for more information.
Faris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2005 07:43 AM
Thanks Faris. I performed the DB compact as described in the doc. The SecMon is functioning properly after the compact.
I understand that the SecMon cannot poll alerts from the sensors during the compaction. I had expected it to resume alerts subscription to the sensors after compaction, and pull all the alerts from where it left off.
Is there a way to recover these alerts from the sensors? Hope you can help. Thanks.
