[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Snort vs Suricata

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 9
Thread images: 1

File: hqdefault.jpg (32KB, 480x270px) Image search: [Google]
hqdefault.jpg
32KB, 480x270px
This thread is about all things snort, suricata, IPS, or IDS.

Just started using suricata and why is it so much better than snort?

any other anons out there use an ids at home?
>>
>>60787912
use snort at work, at home feels like overkill unless you have a pet project going on

combine with a netflow tool for full visibility. I never got into IPFIX though
>>
>>60787912
You really should be comparing to Sourcefire Firepower rather than Snort.
>>
>>60787912
since suricata was built because of snort shortcomings, did snort ever get SMP support?
>>
>>60788151
im not sure it does.
suricata literally just built on top of snort and that was a feature they added
>>
>>60788151
>SMP
As in multithreading? If so Firepower has it
>>
>>60788232
Looks neat but when I read "acquired by Cisco for $2.7 billion" I have to ask what's licensing like?

Smartnet is brutal enough until a business is established.
>>
>>60788336
Its pretty much all hardware packages. They have a virtual appliance i've been meaning to try out since its not like I need 90Gbps of inspection throughput. Not entirely related but so far the ASA 1000v appliance seems like it can be setup for ~6 months on a invalid license before it shits itself and needs to be reinstalled. Since it just uses a config file like most Cisco stuff its not like it is time consuming to resetup.
>>
>>60788151

snort 3.0 says it does multiple threads, but it's still alpha software. suricata is great, but bro seems to be the best thing out there. the only problem is the learning curve and complicated config files/rules.
Thread posts: 9
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.