Re: [ossec-list] Optimization Help for MySQL Database Containing OSSEC Alerts

2012-04-02 Thread Doug Burks
Hi Chris, You mention logstash and Splunk, but have you looked at ELSA? http://code.google.com/p/enterprise-log-search-and-archive/ Regards, Doug On Sun, Apr 1, 2012 at 8:45 PM, Decker Christopher ch...@chris-decker.com wrote: All, I'm running MySQL + Apache/PHP on a very beefy box but using

[ossec-list] Optimization Help for MySQL Database Containing OSSEC Alerts

2012-04-01 Thread Decker Christopher
All, I'm running MySQL + Apache/PHP on a very beefy box but using the out-of-box OSSEC DB schemas I'm experiencing significant latency pulling the alerts from the DB. I use the excellent OSSEC viewer (using Ext JS) [http://code.google.com/p/ossecdb-extjs/] to look at the last 30 days or so of