[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: AW: Snort IDS



Quoting Mattia (2019-09-18 18:53:47)
> thanks for all the answers.
> 
> On Wed, 18 Sep 2019 09:55:27 +0000, Hans Ullrich 
> <hans.ullrich@loop.de> wrote:
> > Hi Mattia,
> > snort is a great tool, and I am using it since a long time. I do not know, if snort is still maintained by debian,
> > but there is a successor which is called "suricata". Suricata is in the debian repo, and it shall better work with the ressources
> >
> > (for example it is splitting into seperate processes). However, for my personal view, snort is easier to configure and its resuklts are better to be seen tahn in suricata.
> I will give suricata a try.

You might also consider sagan - prides itself of using a rule syntax 
based on snort, and on being lightweight (which is interesting for me 
personally), but not on "bells and whistles" like nice UIs.

 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

Attachment: signature.asc
Description: signature


Reply to: