Controlling the size of ipsattacksdb files

Technote (troubleshooting)


Problem(Abstract)

With the introduction of the 4.x line of firmware for Proventia IPS appliances, the method of storing events for display in the Local Management Interface (LMI) changed to utilize a SQLite database.

On the GV1000 virtual appliance, the files used to store the event data may grow to fill the / partition on the virtual appliance. This article details how to control the number of files and the maximum size of the files to prevent the files from filling the partition.

Resolving the problem

Important: When performing administration tasks via ssh or local console, configuration changes made to your IBM appliance by any user other than admin could degrade appliance performance. Installing or activating other services or applications may also impact appliance performance or security. IBM Infrastructure Security Support will not support configuration changes made using the root user account unless specifically directed by a support engineer or IBM documentation. The following DCF Technote content is supported. Any further changes made that are not included in this document will place your product into an unsupported state and IBM product support may require you to reimage your appliance to restore it to a supported state.


There are two parameters that may used to control the amount of hard disk space used by the database:

crmdb.ipsdbarchivecount controls the number of files that may be created to store events. The default value is 8,

crmdb.ipsdbarchiveeventthreshold controls the maximum number of events that may be stored per file. The default value is 40,000.

To edit the values:

1. Log into the appliance via SSH or a local console as the root user.

2. Change the working directory:
cd /var/iss-db

3. Start the SQLite command prompt:
sqlite3 crm.db

4. Run the following commands individually in the SQLite prompt:

insert into config (ParamName, ParamValue) values ("crmdb.ipsdbarchivecount", <insert desired value>);

insert into config (ParamName, ParamValue) values ("crmdb.ipsdbarchiveeventthreshold", <insert desired value>);

.exit

5. Recycle the issDaemon (serivce issDaemon restart).


If the above information does not resolve your issue, please contact IBM Security Systems Technical Support.

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

IBM Security Network Intrusion Prevention System
General Information

Software version:

4.3, 4.4, 4.5, 4.6, 4.6.1, 4.6.2

Operating system(s):

Firmware

Reference #:

1608721

Modified date:

2012-08-22

Translate my page

Machine Translation

Content navigation