Educause Security Discussion mailing list archives

Re: what host-based data is collected?


From: Valdis Kletnieks <valdis.kletnieks () VT EDU>
Date: Tue, 24 Apr 2018 01:45:16 -0400

On Mon, 23 Apr 2018 02:21:06 -0600, William “Bill” Clark said:

All incoming and outgoing IP traffic for 3 months

Per-flow accounting, or full packet capture?

(A back of the envelope calculation tells me that a 10Gbit pipe to the outside
world could potentially take 7.5 petabytes for 90 days of full packet capture,
plus whatever additional storage needed to create indexes necessary to *find* a
given piece of data, plus sufficient horsepower to deal with a sustained
ingestion rate of 1 Gigabyte/sec of data..)

Attachment: _bin
Description:


Current thread: