ossec clear database

To delete all currently stored alerts and related data in the ossec database execute these commands in

MySQL Editor:


truncate table alert;
truncate table data;

Bash Script:

#!/usr/local/bin/bash
#
#Stop ossec, remove old alerts, start ossec

echo "stopping ossec"

/var/ossec/bin/ossec-control stop

echo 'TRUNCATE TABLE `alert` ;' | mysql ossec -p;echo 'TRUNCATE TABLE `data` ;' | mysql ossec -p

echo "rules cleared"
echo "starting ossec"
/var/ossec/bin/ossec-control start

Leave a Reply

To create code blocks or other preformatted text, indent by four spaces:

    This will be displayed in a monospaced font. The first four 
    spaces will be stripped off, but all other whitespace
    will be preserved.
    
    Markdown is turned off in code blocks:
     [This is not a link](http://example.com)

To create not a block, but an inline code span, use backticks:

Here is some inline `code`.

For more help see http://daringfireball.net/projects/markdown/syntax

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>