Re: IDS Reporting

From: Nicholas Bachmann (nbachmann@mail.davison.k12.mi.us)
Date: 06/20/02


Date: Wed, 19 Jun 2002 18:49:16 -0400
From: Nicholas Bachmann <nbachmann@mail.davison.k12.mi.us>
To: focus-ids <focus-ids@securityfocus.com>

samantha myers wrote:

|I am looking for information on the reporting
|capabilities of the various NIDS. Specifically what
|type of information you can report on, how the reports
|are presented, are they easy to use, can you create
|custom reports, stuff like that.

Most of the commercial IDSs come with some kind of built-in reporting
system. Snort has tcpdump and text logs and database exports and there
are several frontends, including ACID, snortreport, and Demarc. Dragon
has dragon.db and text logs and database exports and a nifty interface
to view them. Cisco uses HP OpenView, some love it, many hate it, most
could care less.

Getting a demo of any of the above IDSs shoudn't be hard; you can make
your own judgements about what's best.

-- 
	Regards,
	Nick

Nicholas Bachmann, SSCP Unix Administrator Davison Community Schools



Relevant Pages

  • Re: [fw-wiz] Handling large log files
    ... Splunk to manage firewall and switch event logs. ... we used it to alert us to switches reporting an ...  With this volume, logcheck was able to ... effectively parse the files and send out a nice email. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Handling large log files
    ... Splunk to manage firewall and switch event logs. ... we used it to alert us to switches reporting an ... output of SEC was fed back in to syslog-ng as and represented in Splunk ...  With this volume, logcheck was able to ...
    (Firewall-Wizards)
  • Re: Scheduled Server scan does not log events - Trend Micro WFBS 5.1
    ... reporting and logging facilities. ... Query-Exchange Server-Scan event logs. ... can set the cpu utilization to high, ... We have recently discovered that our Sunday morning Scheduled Server Scan ...
    (microsoft.public.windows.server.sbs)
  • RE: Firewall and Internet Reporting Software...Best One?
    ... Firewall and Internet Reporting Software...Best One? ... Webtrends offers very good graphing, reporting, etc. ... since the firewall logs IP addresses rather than user names of the ...
    (Security-Basics)
  • Re: off topic: reporting attempts to access computers
    ... My logs show a dictionary attack of invalid user names against port 22. ... I have found reporting the abuse virtually useless. ...
    (freebsd-questions)