Re: Taking a traffic snapshot with network IDS

Jens Link <[email protected]> Tue, 22 Jun 2010 16:10:52 +0200
Newsgroups gmane.comp.security.firewalls.wizards
Organization -
Message-ID <[email protected]>
Farrukh Haroon <[email protected]> writes:

> Instead of capturing each packet, you would be better off going via the
> Netflow Path IMHO.
>
> There are a number of free netflow analyzers available on the Internet
> e.g.:

I like to use nfdump and nfsen for analyzing Netflow data. Nfdump
contains an accounting daemon and some tools for analyzing / converting
data on the command line, nfsen is a web interface for nfdump. 

See http://nfdump.sf.net and http://nfsen.sf.net for details.

cheers 

Jens
-- 
-------------------------------------------------------------------------
| Foelderichstr. 40   | 13595 Berlin, Germany    | +49-151-18721264     |
| http://blog.quux.de | jabber: [email protected] | -------------------  | 
-------------------------------------------------------------------------