Page 1 of 1

disable or change definition: suspicious process and excessive resource

Posted: 22 Mar 2017, 22:11
by guygreg2
Hi,
I really like the CSF tool but am getting lots of alerts for "suspicious process" and "excessive resource usage". These are for processes I know about and am ok with the resource usage.
I've got them filtered to go into a special mail folder, but the constant alerting obscures when I get an email I want to read. Similarly, I'll never know if I really DO have something problematic because the alert for it will be lost and ignored in a sea of others.

It would be nice if the interface allowed you to define what is "suspicious" and what is "excessive". In the meantime, can anyone point me to the config file so I can adjust this, or else disable the alerts?

Thank you!

Re: disable or change definition: suspicious process and excessive resource

Posted: 05 Apr 2017, 03:21
by FutherForward20
Hi all

I came here looking for an answer on this matter also.

The "Excessive resource usage" notifications can be a bit of a nuisance if you already know about the user / program etc. So what is the best way to curtail these based on a specific user - or perhaps increase the notification thresh-hold.

Thanks

Re: disable or change definition: suspicious process and excessive resource

Posted: 06 Apr 2017, 06:04
by Sergio
Have you tried to use pignore?