• Support
  • Forums
  • Blogs

Database Fields

ic3kymic3kym

Entry Level
Hello,
I would like to ask one thing:
I have installed OSSIM version 4.0. I have configured snare on windows in order to send syslog events to OSSIM. OSSIM receives events correctly and stores them into a table called "acid_event".
Now I would like to ask you: what is the meaning of the field "ctx" and how can I read it?
I think that this field (ctx) contains the Raw events. If I'm wrong, in which table can I find the raw events?

Thanks  

Share post:

Answers

  • mysql> select hex(ctx) from acid_event;
    +----------------------------------+
    | hex(ctx)                         |
    +----------------------------------+
    | CACF632A40E711E391AC080027C279C0 |
    | CACF632A40E711E391AC080027C279C0 |
    | CACF632A40E711E391AC080027C279C0 |
    | CACF632A40E711E391AC080027C279C0 |
    | CACF632A40E711E391AC080027C279C0 |
    +----------------------------------+
    5 rows in set (0.00 sec)

This discussion has been closed.