nicklauscombs wrote: » found this as an option: Snort IDS Sensor with Sguil Framework ISO hoping to try it out in the next couple of days / early next week. any other options anyone knows of?
Bl8ckr0uter wrote: » What exactly are you looking for? Just snort based stuff? I was actually looking at bro a while back.Bro Intrusion Detection System - Bro Overview
nicklauscombs wrote: » yup, just looking for a quick easy way to get snort running to play around with a bit, bro looks interesting though ill have to look into that a little more.
JDMurray wrote: » And regardless of the IDS, you should also get some hands-on experience with Splunk. It's another tool you find a lot of people using. Just for practicing, install it in a VM snapshot and revert back to new when you need to.
Bl8ckr0uter wrote: » Good tip. What popular Siems do people use? Alienvault says they are the most popular (opensource siem). I know Arcsight is pretty popular. What other big name ones are out there?
nicklauscombs wrote: » on my hit list at some point in the future, have read parts of tao but havent checked out the other. definitely will look into that one this evening at work, thanks for the suggestion!
Bl8ckr0uter wrote: » I know Arcsight is pretty popular.
Bl8ckr0uter wrote: » http://www.turnkeylinux.org/forum/general/20101206/insta-snorby-official-snort-snorby-turn-key-solution This looks promising. In fact I might look this up this weekend.
nicklauscombs wrote: » thanks for the heads up. looks like i have some projects to work on this week as i'm mostly off work.
Bl8ckr0uter wrote: » What I am concerned about Nick is using all of these prebuilt isos will not help with complete learning. Similar to using a gui in linux, ya know? I don't know, I am still going to check it out.
nicklauscombs wrote: » agreed, however i am more concerned (for now) with the learning done inside snort more so than the initial setup.
Bl8ckr0uter wrote: » I understand that completely. How are the LPIC-1 studies coming?