Snort mailing list archives
RE: Anyone using "Enterprise implementation"?
From: Michael Miller <michael.miller () state co us>
Date: Wed, 27 Aug 2003 09:19:29 -0600
You're not limited to a single box in watching GigE traffic. You may find it easier to a) turn off email and http traffic signatures as, presumably, your mail and webservers have detailed logs, and b) set two (or more) sensor boxes to look for specific parts of the ruleset. -----Original Message----- From: Emre Bastuz [mailto:info () emre de] Sent: Wednesday, August 27, 2003 9:00 AM Using two machines in a sensor/manager way is part of an evaluation to decide if commercial products are worth the money or if Snort is an alternative. My major concern was hardware performance when sniffing on an GigE network, that´s why I added all kinds of signatures to the snort process in the first place. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: Anyone using "Enterprise implementation"?, (continued)
- Re: Anyone using "Enterprise implementation"? Emre Bastuz (Aug 27)
- Re: Anyone using "Enterprise implementation"? Nagesh Chavan (Aug 28)
- RE: Anyone using "Enterprise implementation"? Hutchinson, Andrew (Aug 26)
- RE: Anyone using "Enterprise implementation"? Kreimendahl, Chad J (Aug 26)
- RE: Anyone using "Enterprise implementation"? Michael Steele (Aug 26)
- Re: Anyone using "Enterprise implementation"? cc (Aug 26)
- Re: Anyone using "Enterprise implementation"? Rich Adamson (Aug 27)
- RE: Anyone using "Enterprise implementation"? Tom Van Overbeke (Aug 27)
- Re: Anyone using "Enterprise implementation"? Jason Haar (Aug 31)
- Re: Anyone using "Enterprise implementation"? Emre Bastuz (Aug 27)