3 ms·
> you can't practically log/monitor/IPS/SIEM...or am I misinformed? It depends the hardware you're using (specifically router), but using netflow / sflow / ipf
by nmjohn 10y ago
> you can't practically log/monitor/IPS/SIEM...or am I misinformed?
It depends the hardware you're using (specifically router), but using netflow / sflow / ipfix [0] you can get pretty high visibility even for high bandwidth networks. This only gets you "metadata" and not a full packet capture - but for monitoring and the like, the metadata can be far more useful.
I'm not entirely sure what level of traffic you're talking about, but I know it's possible with the right hardware to use netflow with 100GbE links without having to sample (ie: Recording flows for every packet, not 1 in every n packets)
[0]: Good sflow vs. netflow beakdown: http://networkengineering.stackexchange.com/a/1335 http://networkengineering.stackexchange.com/a/1335