I've used Splunk, and it's a great event analyzer but it's a *very*
heavy client; even the "light" installation. So it's not something I'd
want to install on every average desktop in my enterprise.
That's why I appreciated ossec because the client and protocol are
very small, so the system scales well.

However, we lose some robustness because of that.  I've struggled with
how to handle lost events when the agent or server are down.  Ossec
doesn't "catch up" when the connection is restored (at least not with
Windows) and that's unfortunate because its a great platform.

Reply via email to