Snort mailing list archives
(no subject)
From: <counterping () uk2 net>
Date: Tue, 8 Oct 2002 14:57:36 GMT
This Not strictly a SNORT Question so I aplogize in advance. Newbie to the World of TCPDUMP. I am running Snort IDS and as a complimating product .... I have recently been interested in also logging ALL traffic that comes in/out my network via TCPDUMP (ip headers atleast). This is really for the purpose of Forensics etc etc and would be cool to zip up and store away. In the future I would also like to install SHADOW at some point to run these dumps for anomilies. However, the amount of data is silly !! 200 MB per HOUR !! This is far too much data to log and store away ? My question being .... Does anyone log ALL IP Headers IN+OUT of there Networks ? Should we be doing this ? Is it a good idea to take this approach ? Any ideas suggestions would be appreciated. Little Confused Matt Y P. P.S anyone know of any TCPDUMP mailing lists ? ---------------------------------------------------------- This message was sent using http://uk2.net NEWS - CHEAPEST DEDICATED SERVERS IN THE WORLD - 25/month FREE UK DIAL 0845 609 1370 - username uk2: - password: uk2 UK's FREE Domains, FREE Dialup, FREE Webdesign, FREE email ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- (no subject) Abimbola Abiola (Oct 08)
- <Possible follow-ups>
- (no subject) counterping (Oct 08)
- Re: (no subject) Matt Kettler (Oct 08)
- RE: (no subject) Beckett, Josh (Oct 08)
- RE: (no subject) Beckett, Josh (Oct 08)
- (no subject) Adrienne Kotze (Oct 10)
- (no subject) Nathan Whitehouse (Oct 14)
- Re: (no subject) hackerwacker (Oct 14)
- Re: (no subject) Erek Adams (Oct 14)
- RE: (no subject) Bob Dehnhardt (Oct 14)
- (no subject) Nanabhay Mohamed * Group (GP) (Oct 16)
- (no subject) Kreimendahl, Chad J (Oct 22)
(Thread continues...)