ClearFoundation Tracker - ClearOS
View Issue Details
0000127ClearOSapp-intrusion-detection - Intrusion Detectionpublic2010-08-23 08:472013-02-01 15:19
timb80 
user2 
normalminoralways
closedsuspended 
5.2 
 
0000127: Intrusion detection reports shows entries from previous year
The intrusion detection report is not 'year friendly'. It shows entries which occured last August, this was apparent after attempting to locate an attacking IP from this months summary report, and it was specified with a forward date of 25th August. Today is the 23rd.

With a bit of investigation is appears the logs are stored in /var/webconfig/reports/snort/ under monthly numbered folders. By inspecting the file /var/webconfig/reports/snort/08/25/details.gz it was apparent that the IP was present but presumably from last year (2009)

Please can we prevent these old entries from appearing or flush them?

[root@starlane ~]# ls -la /var/webconfig/reports/snort/08/25/details.gz
-rw-r--r-- 1 root root 488 Aug 25 2009 /var/webconfig/reports/snort/08/25/details.gz
Another useful addition - would be the ability to hide local known WAN/LAN IP addresses from the attackers / victim list. They tend to obscur the data and these could(?) be whitelisted from the reports
No tags attached.
Issue History
2010-08-23 08:47timb80New Issue
2010-08-23 09:00timb80Note Added: 0000216
2010-08-24 18:45user2Statusnew => assigned
2010-08-24 18:45user2Assigned To => user2
2011-02-08 15:30user2CategoryReports - Intrusion Detection => app-intrusion-detection - Snort
2013-02-01 15:18user2Statusassigned => resolved
2013-02-01 15:18user2Resolutionopen => suspended
2013-02-01 15:19user2Statusresolved => closed

Notes
(0000216)
timb80   
2010-08-23 09:00   
Appears to be an old 'bug', work around here:-
http://ccforums.clearfoundation.com/showflat.php?Cat=0&Number=105834&Main=105410 [^]