Re: [Simple-evcorr-users] how not to keep monitored files permanently open (not only) on NFS

2020-02-04 Thread Risto Vaarandi
hi Richard, I have never used SEC for monitoring files on NFS file systems, but I can provide few short comments on how input files are handled. After SEC has successfully opened an input file, it will be kept open permanently. When input file is removed or renamed, input file is still kept open

[Simple-evcorr-users] how not to keep monitored files permanently open (not only) on NFS

2020-02-04 Thread Richard Ostrochovský
Hi Risto and friends, I am unsure about one conceptual question about how SEC keeps open monitored files. Using SEC as systemd service, when files stored in NFS (opened via addinput) being watched by SEC are moved elsewhere, and then their removal is tried, NFS persistently keeps .nfsNUMBER

Re: [Simple-evcorr-users] SEC rules performance monitoring and tuning

2020-02-04 Thread Risto Vaarandi
hi Richard, That's an interesting question. Dump files in JSON format have been supported only across few recent versions (from 2.8.0 to 2.8.2) and don't have long history behind them, but so far their format has stayed the same. As for dump files in text format, there have been a number of

Re: [Simple-evcorr-users] SEC rules performance monitoring and tuning

2020-02-04 Thread Richard Ostrochovský
Hi Risto, thank you for positive answer - dumping period in minutes in enough, not needed many times per second. And also for useful tips - I already noticed JSON option, just considering, that default is maybe more universally usable, because extra modules (JSON.pm) may not be installed or