Re: session logging IDS
From: Stefan Keller (stefan.keller_at_gmail.com)
Date: 09/01/04
- Previous message: Konrad Rieck: "Re: need your help,thanks"
- In reply to: David W. Goodrum: "Re: session logging IDS"
- Next in thread: Alex Butcher, ISC/ISYS: "Re: session logging IDS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 1 Sep 2004 10:50:51 +0200 To: Raj Malhotra <ral.mal@gmail.com>, focus-ids@securityfocus.com
Hi,
for high-level session overview information older software like ARGUS
would work, too.
As for the size of the hard drive, that would depend on the volume of
traffic that is actually monitored and the frequency of the reviews.
If you rotate logs and automatically delete the old ones...
All in all, the "log all" approach seems very ambitious, esp. as IDS
has a reputation as a dust-collector in many companies. - Will you
have staff monitoring the IDS 24/7? With periodic reporting from them?
Regards
Stefan
- Previous message: Konrad Rieck: "Re: need your help,thanks"
- In reply to: David W. Goodrum: "Re: session logging IDS"
- Next in thread: Alex Butcher, ISC/ISYS: "Re: session logging IDS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]