Re: Download packet
ScottO <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
Konrad Kosmowski wrote: >> You already have packet payload in Prewikka, >> > > In what format it is stored? I've looked at database and it is BLOB > type (obviously) but for packets - how are they stored in IDMEF spec? > Seriously I am ignorant. Please explain. ;) > > I'm unsure how the payload data is stored in the database, but it is readily available in Prewikka, at the bottom of a Snort alert in the Network Centric Information area. It is the same amount of information you would get in ACID/BASE, Sguil (prior to querying additional pcap data), etc. > Don't get me wrong guys - really Prelude has much potential right now. > It is well designed and shows promise. But for me it has a strange > status - when I asked about database performance (poor) I was offered > an solution priced 3000EUR which is quite expensive. > > So the impression I've got was - "yes it has poor DB performance - > wanna better - pay us". It's OK but how exactly should this encourage > me to participate as in open source project? > > I directed you to the link, since I highly recommend the XLR plugin. I was in a situation where we have more than a handful of network sensors, LML instances, and HIDS - which requires more enterprise-level performance, which XLR definitely provides. I think when you move from a small number of sensors, to one where enterprise-level numbers of alerts come into play, 3000euro is small money. Besides, contributing to the creators and commercial backing of Prelude, helps features and fixes get added to the open source project as well. > Right now I work in quite big enterprise and I am implementing Snort > probes in places where we cannot implement other (commercial) probes > since we don't have budget for that. Paying 3000EUR would be > equivalent to just getting the probes we need in system we already > have. > In our instance, we use Prelude, not as a traditional IDS, but as a SIM/event management tool - correlating and collecting among large numbers of NIDS, HIDS, log servers, Nessus scanners, and plenty of homegrown security sensors. Any commercial tool that came close to providing the capabilities it provides was much more than the money we have spent on the various commercial plugins and other expenses. Prelude is more than just a place to store and view your Snort alerts, it provides secure transport of messages, various types of relaying, modularity of plugins, correlation among infinite types of sensors/agents, log analysis, etc. > Please don't get is as trolling/flame etc. I've just stated my (as an > user of your software) ideas about it. That's it. Think about it. > I sincerely believe that you do not intend this post to be trolling or flaming. I guess as they say, beauty (and in this case value) is in the eye of the beholder. Scott _______________________________________________ Prelude-user site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-user