08-29-2005 09:55 AM - edited 03-10-2019 01:36 AM
Folks,
I have a couple of questions regarding IDS MC 2.1.
1) Will it generate reports giving information about lets say critical alarms or lets say informational alarms?
2) How often does it access the database. I mean lets say the attck was happening, how soon would the security monitor be able to send an e-mail about that??
Solved! Go to Solution.
08-29-2005 11:34 AM
Use SecMon with MC2.1.
It will report severity as described in question #1.
As far as #2, secmon in MC2.1 will "subscribe" to a sensor and the events are "more or less" real time. This means that once a subscrition is established the IPS appliance will send the event as it is generated. However keep in mind that if the IPS box is busy, attack interrupts take precendnce over event reporting. Bottom line is that events should be in secmon within 10-20 second of when they fired.
08-29-2005 11:34 AM
Use SecMon with MC2.1.
It will report severity as described in question #1.
As far as #2, secmon in MC2.1 will "subscribe" to a sensor and the events are "more or less" real time. This means that once a subscrition is established the IPS appliance will send the event as it is generated. However keep in mind that if the IPS box is busy, attack interrupts take precendnce over event reporting. Bottom line is that events should be in secmon within 10-20 second of when they fired.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide