RE: iss alert forwarding capabilities
From: malj32 (malj32@dial.pipex.com)Date: 05/30/02
- Previous message: Justin Stanford: "RE: Prelude IDS"
- In reply to: Ralph Emery: "RE: iss alert forwarding capabilities"
- Next in thread: Andrew Bailey: "Re: iss alert forwarding capabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "malj32" <malj32@dial.pipex.com> To: <remery@guarded.net>, <dlaumann@suntzu.net>, <focus-ids@securityfocus.com> Date: Thu, 30 May 2002 11:57:05 +0100
Guys,
With site protector 1.0 the alert mechanism has altered slightly.
Alerts go to the enterprise database from the event collector and not
the display. The display reads them from the database every 60 seconds
which is why it's no longer real-time
Mal
-----Original Message-----
From: Ralph Emery [mailto:remery@guarded.net]
Sent: 29 May 2002 17:46
To: dlaumann@suntzu.net; focus-ids@securityfocus.com
Subject: RE: iss alert forwarding capabilities
No the events are streamed back to the event collector and then to the
display as for the snmp traps those come directly from the network
sensor or host sensor.
-----Original Message-----
From: dlaumann@suntzu.net [mailto:dlaumann@suntzu.net]
Sent: Tuesday, May 28, 2002 1:43 PM
To: focus-ids@securityfocus.com
Subject: iss alert forwarding capabilities
hi,
can iss host sensors (h) send their alerts to an iss "collection server"
(c), and then have this "collection server" send out snmp alerts, for
each
host sensor alert collected, to an snmp management station (o); as
opposed
to each host sensor sending snmp alerts directly? if so, what products
(just
real secure, or real secure site protector, etc) and versions are
required?
+---+ +---+
| h | | h |
+---+ +---+
| |
\ /
\ / <-- iss' or <xyz> communication protocol
|
+---+
| c |
+---+
|
| <-- snmp
|
+---+
| o |
+---+
i haven't gotten a clear answer from iss yet. it looks as if iss does
not
support this, but thought i would check here first.
-- thanks, dave
- Previous message: Justin Stanford: "RE: Prelude IDS"
- In reply to: Ralph Emery: "RE: iss alert forwarding capabilities"
- Next in thread: Andrew Bailey: "Re: iss alert forwarding capabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|