On Sunday, February 21, 2016 at 7:52:17 AM UTC-8, Brian Haugli wrote:
> Dough, what configuration do you propose gets the pcap to disk that is only associated with the alerted signature?
Hi Brain, so what were the hardware specs you went with? I am looking to deploy a master server VM with 3 remote sensors. Each site has around 500mb tops of bandwidth to monitor. I don't think I am going to save every pcap, but like you, only want the pcap involved with alerts.
Let me know what you went with.
Thanks!