[ Date Index ][
Thread Index ]
[ <= Previous by date /
thread ]
[ Next by date /
thread => ]
How about adding a daemon that deletes lines from your log if they ae characteristic of the Nimda attack? It could perhaps keep a log of its own holding the first and last times for each individual IP address that they come from, and discard other information. It probably exists or is implicit in the logging facilities of Apache though, just that I do not know of it yet. -- The Mailing List for the Devon & Cornwall LUG Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the message body to unsubscribe.