On Thu, Jan 13, 2011 at 11:21 AM, Dave S <[email protected]> wrote: > I've used Splunk, and it's a great event analyzer but it's a *very* > heavy client; even the "light" installation. So it's not something I'd > want to install on every average desktop in my enterprise. > That's why I appreciated ossec because the client and protocol are > very small, so the system scales well. >
I'm not disagreeing with you because I haven't done any testing, but according to splunk the light forwarder shouldn't use more than about 25MB of ram and 256kb of network. The trainer also mentioned he had helped with an installation where a splunk LF was installed on every desktop/laptop in the organization. Seemed like a neat idea, but knowing the machine I use at work even with the resource limits it could be a bit much. > However, we lose some robustness because of that. I've struggled with > how to handle lost events when the agent or server are down. Ossec > doesn't "catch up" when the connection is restored (at least not with > Windows) and that's unfortunate because its a great platform.
