[Bro] large notice.log

Ambros Novak ambros.novak.89 at gmail.com
Mon Oct 29 16:12:44 PDT 2018


Holla!

notice.log is extremely large before it rotates, sometimes 140G+. At times
it rotates to another log with a timestamp added to it's name. This
happened after turning on other analyzers.

Is there a way to suppress notice.log or minimize the events written to it.
The events in the other logs are more important.

There are also other logs that are extremely large as well, and I'm trying
to balance processing and space vs the visibility.

Any advice appreciated.

Merci!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20181029/8fcdf49d/attachment.html 


More information about the Bro mailing list