Skip to content

Conversation

@AdUser
Copy link

@AdUser AdUser commented Nov 24, 2023

This patch changes insertion of srcip/dstip alert fields to database table from "NULL" (varchar string) value to true sql NULLs.
it takes less space in table and add ability to use IS NULL/NOT NULL/... sql expressions instead slower string comparision.

CREATE TABLE alert
    (
   ...
    src_ip          VARCHAR(46), -- nullable
    dst_ip          VARCHAR(46), -- nullable
    ...
    );

@AdUser
Copy link
Author

AdUser commented Nov 24, 2023

P.S. This patch tested with postgresql database about ten months, and have no issues in my ossec setup, but feel free to do more testing if you consider so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant