Hello.. i have some queries with respect to HIDS. I have a VMS server running CSA MC. I have a windows server running the agent. Now, this agent is synchronised with the CSA MC. I have added the CSA MC on the sec mon event viewer. When i open the security monitor, I get only application specific events like audit logs.. i dont see any signature specific attacks .. what do I need to do to see this ?
Doesnt the HIDS agent serve to stop network or application specific attacks onto the server ?