Advanced Log Processing / Gestion avancée des fichiers log

One of Murphy’s laws advises to « only look for those problems that you know how to solve. » In security, this means to only monitor for those attacks that you plan to respond to. It is well known that any intrusion detection system is only as good as the analyst watching its output. Thus, having nobody watching the IDS is equivalent to having no IDS at all. But what should an IDS administrator do if he or she is drowning in a flood of alerts, logs, messages and other attention grabbers?

Une des lois de Murphy dit « Il faut seulement regarder les problèmes que vous savez résoudre »…

