On 01/21/2011 09:33 PM, Jason 'XenoPhage' Frisvold wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Jan 11, 2011, at 1:21 PM, Netsyphon wrote:
Splunk is nice but I had troubles getting it to work with the ossec plugin, may 
try again. It's also somewhat cost prohibitive since it's doing only a small 
portion of what it's needed for compared to ossec.  I agree on the snare 
comparison, it's not practical for the security minded.


Unless you have a huge number of OSSEC clients, I think the free version of 
splunk handles everything just fine.  You lose some features such as automated 
reporting and the ability to create users, but it works really well.

I have noticed that (on average) the alerts for a non-domain Windows server amount to about 1MB/day. This is highly speculative and dependent on your environment, but if it holds true as a *general* rule (I know I'm going to regret saying this), then you can get several hundred agents sending alerts to the free Splunk before running into your 500MB/day limitation.

Reply via email to