Controlling the size of ipsattacksdb files on Security Network IPS sensors
With the introduction of the 4.x line of firmware for Security Network IPS sensors (GX), the method of storing events for display in the Local Management Interface (LMI) changed to utilize a SQLite database.
On the GV1000 virtual appliance, the files used to store the event data may grow to fill the / partition on the virtual appliance. This article details how to control the number of files and the maximum size of the files to prevent the files from filling the partition.
Resolving the problem
Important: When performing administration tasks via ssh or local console, configuration changes made to your IBM appliance by any user other than admin could degrade appliance performance. Installing or activating other services or applications may also impact appliance performance or security. IBM Infrastructure Security Support will not support configuration changes made using the root user account unless specifically directed by a support engineer or IBM documentation. The following DCF Technote content is supported. Any further changes made that are not included in this document will place your product into an unsupported state and IBM product support may require you to reimage your appliance to restore it to a supported state.
There are two parameters that may used to control the amount of hard disk space used by the database:
crmdb.ipsdbarchivecount controls the number of files that may be created to store events. The default value is 8.
crmdb.ipsdbarchiveeventthreshold controls the maximum number of events that may be stored per file. The default value is 40,000.
To change the values, follow the instructions below:
- Log into the appliance via SSH or a local console as the root user.
- Change the working directory:
- Start the SQLite command prompt:
- Run the following commands individually in the SQLite prompt:
insert into config (ParamName, ParamValue) values ("crmdb.ipsdbarchivecount", <insert desired value>);
insert into config (ParamName, ParamValue) values ("crmdb.ipsdbarchiveeventthreshold", <insert desired value>);
- Restart the issDaemon service with the following command:
service issDaemon restart
Note: Restarting the issDaemon service will cause a brief disruption in traffic. Schedule for this accordingly.
More support for:
IBM Security Network Intrusion Prevention System
Software version: 4.6, 4.6.1, 4.6.2
Operating system(s): Firmware
Reference #: 1608721
Modified date: 22 August 2012