Re: Sought Fraud Rule-Set

2009-10-05 Thread John Hardin
On Mon, 5 Oct 2009, Warren Togami wrote: On 10/05/2009 03:52 PM, Karsten Bräckelmann wrote: On Mon, 2009-10-05 at 15:44 -0400, Warren Togami wrote: > On 10/05/2009 02:53 PM, Karsten Bräckelmann wrote: > > Well, the Sought rule-set (and thus Fraud sub-set) is being > > re-generated every 4

Re: Sought Fraud Rule-Set

2009-10-05 Thread Warren Togami
On 10/05/2009 03:52 PM, Karsten Bräckelmann wrote: On Mon, 2009-10-05 at 15:44 -0400, Warren Togami wrote: On 10/05/2009 02:53 PM, Karsten Bräckelmann wrote: Well, the Sought rule-set (and thus Fraud sub-set) is being re-generated every 4 hours -- with an exception of night-time, UTC. They

Re: Sought Fraud Rule-Set

2009-10-05 Thread Karsten Bräckelmann
On Mon, 2009-10-05 at 15:44 -0400, Warren Togami wrote: > On 10/05/2009 02:53 PM, Karsten Bräckelmann wrote: > > Well, the Sought rule-set (and thus Fraud sub-set) is being re-generated > > every 4 hours -- with an exception of night-time, UTC. > They are really being generated every 4 hours when

Re: Sought Fraud Rule-Set

2009-10-05 Thread Warren Togami
On 10/05/2009 02:53 PM, Karsten Bräckelmann wrote: On Mon, 2009-10-05 at 13:30 -0500, McDonald, Dan wrote: On Mon, 2009-10-05 at 20:17 +0200, Karsten Bräckelmann wrote: Just a minor nit, in case it isn't just different terminology. Installed sounds like a one-time operation -- the Sought rule

Sought Fraud Rule-Set (was: Low score? Recommendations?)

2009-10-05 Thread Karsten Bräckelmann
On Mon, 2009-10-05 at 13:30 -0500, McDonald, Dan wrote: > On Mon, 2009-10-05 at 20:17 +0200, Karsten Bräckelmann wrote: > > Just a minor nit, in case it isn't just different terminology. Installed > > sounds like a one-time operation -- the Sought rule-set needs to be > > updated using sa-update f