TCPDUMP ... Logging far too much traffic ?
From: counterping@uk2.netDate: 10/08/02
- Previous message: Axel Tanner: "Source of ICMP packet on Windows?"
- Next in thread: Brad Arlt: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Brad Arlt: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Alexandros Papadopoulos: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Kim Nielsen: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: phani@myrealbox.com: "Re: TCPDUMP ... Logging far too much traffic ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: security-basics@securityfocus.com From: <counterping@uk2.net> Date: Tue, 8 Oct 2002 14:32:09 GMT
Newbie to the World of TCPDUMP.
I am running Snort IDS.
I have recently been interested in also logging ALL traffic that comes in/out
my network via TCPDUMP (ip headers atleast).
This is really for the purpose of Forensics etc etc and would be cool to zip up
and store away.
In the future I would also like to install SHADOW at some point to run these
dumps for anomalies.
However, the amount of data is silly !!
200 MB per HOUR !! This is far too much data to log and store away ?
My question being ....
Does anyone log ALL IP Headers IN+OUT of there Networks ?
Should we be doing this ? Is it a good idea to take this approach ?
Any ideas suggestions would be appreciated.
Little Confused
Matt Y
P.
----------------------------------------------------------
This message was sent using http://uk2.net
NEWS - CHEAPEST DEDICATED SERVERS IN THE WORLD - 25/month
FREE UK DIAL 0845 609 1370 - username uk2: - password: uk2
UK's FREE Domains, FREE Dialup, FREE Webdesign, FREE email
- Previous message: Axel Tanner: "Source of ICMP packet on Windows?"
- Next in thread: Brad Arlt: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Brad Arlt: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Alexandros Papadopoulos: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: Kim Nielsen: "Re: TCPDUMP ... Logging far too much traffic ?"
- Reply: phani@myrealbox.com: "Re: TCPDUMP ... Logging far too much traffic ?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|