Re: rules format
Matt Kettler <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
Jules wrote: > Hi there > > > > I am trying to learn about prelude. > > > >>From I can see, prelude use log files. I am wondering if prelude deals with > live packet. > > > > Any indication of the format used by prelude to capture live data? > In the generally recommended use, Prelude doesn't capture live network packets. Prelude is really a "meta-ids" of sorts. It's essentially a centralized logger with event correlation, categorization and analysis. Prelude gathers information from system logs, firewall logs, NIDS packages (snort), etc and helps you identify the important events from the background noise. For live capture and analysis, you should use snort. prelude-nids does exist and performs this function, but last I checked it was deprecated in favor of snort. _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel