I am thinking that if the target of a hacker is always the server so why I need the NIDS ? I can monitor very well just the servers with some kind of HIDS like Ossec and I am done no? why should I care about the NIDS when I have a well configured HIDS on every server?

The target of an intruder is not only your servers, but any device on your network (routers, switches, ...) I've yet to see a HIDS for a Cisco router for instance :)

Also, putting 1 or more NIDS in front of your server farm might be more cost effective than putting an HIDS on each server.


