Re: Radium identify TLS handshakes?
"James A. Robinson" <[email protected]> Fri, 16 Mar 2018 00:24:19 +0000
| Newsgroups | gmane.network.argus |
|---|---|
| Message-ID | <CAPd04b4BxK=mY+cfPbgJ6sVE_kNabXChxQzX+oVKQjhM8z7GvQ@mail.gmail.com> |
Hello, Thank you for the fast and detailed reply. I think your reply delves deeply into the analysis portion of the exercise, which is actually a step beyond what I was even thinking about right now. My immediate concern was not running out of disk space on the radium host as it gathered flows from 1,000 hosts. So I think what I'll try and do is apply some basic port/network filtering similar to what you outlined to initially identify the hosts I'm interested in, then collect the unfiltered flows on just those hosts to perform the deeper analysis as you were outlining. Jim