Security Basics mailing list archives

Re: FW/IPS log correlation software


From: "Gleb Paharenko" <gpaharenko () gmail com>
Date: Sun, 6 Apr 2008 00:19:46 +0300

Hi.

Netforensics SIM (http://www.netforensics.com/) can do this.
You can utilize OSSEC (www.ossec.net) for this purposes as well.
For cisco products perhaps it is better to use MARS
(http://www.cisco.com/en/US/netsol/ns698/networking_solutions_solution.html),
because their SIM is based on old Netforensics.

4 Apr 2008 13:55:40 -0000, mgk.mailing () googlemail com
<mgk.mailing () googlemail com>:

 http://www.splunk.com/


 We have been looking at that for our own systems.


 mgk



-- 
Best regards.
Gleb Pakharenko.
http://gpaharenko.livejournal.com


Current thread: