Typos, courtesy of the wireless device.
If the stats you're looking to have updated at the ones in
/var/ossec/stats, there aren't really any configuration options for
those.
This would go with the following line from
/var/ossec/stats/totals/Sep/ossec-totals-01.log on my system:
14--80516--101757--1--0
The following line:
15-370010-1-83
is hour-SID-level-firedtimes (maybe the number of times it fired
during that hour...)
If this doesn't answer your other thread as well, you can look in the
ossec source (src/analysisd/analysisd.c) for more answers.
The short answer is that ossec-analysisd is not the bottleneck. Disk I/O
and kernel parameters will slow things down first. Specifically, I
recall UDP buffers having an affect. Seems like a good topic for Week of
OSSEC. I know Daniel in particular has done extensive testing in this
area. From what I recall, I think you can reasonably expect around 1,000
eps on a well-tuned system.
--
Michael Starks
[I] Immutable Security
http://www.immutablesecurity.com
About memory i think not sure, it could be tested in deepth by
creating logs
that force more the ossec correlation engine to work