[Snort-users] Monitoring Sensors
bet at ...6163...
Mon Sep 23 07:49:01 EDT 2002
Different folks have different strategies for monitoring.
My own preference is for end-to-end functional monitoring.
For IDS sensors, I like to arrange for a special signature that will
trigger a keepalive "alarm" when I send a special probe packet past
it; then I arrange a generator to send one of those packets every
so often, and then process the alerts, wherever they're ultimately
forwarded, to move the keepalives aside for special examination;
then a periodic monitor process sets off an alarm if it doesn't
see one of these keepalive alerts for too long (several "probe"
Same trick as I use for other server monitoring wherever I can
figure out a way to; e.g. I'll monitor an email relay server by
periodically routing a keepalive message through it to a monitoring
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Size: 189 bytes
Desc: not available
More information about the Snort-users