[logs] Sentry/Counterpane how is it working ?

From: Alexandre Dulaunoy (alexat_private)
Date: Tue Mar 12 2002 - 05:34:51 PST

  • Next message: John Campbell: "[logs] Distributed attack on port 6398?"

    Dear All, 
    
    We have look around http://www.counterpane.com/sentry.html. And we some 
    question of how it is working ?
    
    - If we clearly understand this is only network monitoring sniffing ? 
      (check out Question 7 : http://www.counterpane.com/questions.html)
         - How the device handles encrypted connection (like SSL/TLS, SSH...) ?
         - Maybe you can store private key on the sentry box ? (maybe quite dangerous ;-)
    
    
    - So with this type of system where can you get the system log for example ? (Event log and audit log from WIN32 ? Specific application log ?)
    
    - Another question : Is it possible to get the software of sentry ? Or having a technical overview of the software ? 
    
    Yes, I suspect, the difference between host based monitoring 
    (getting log...) and network based monitoring (sniffing network...) is 
    quite small. 
    
    Is there some user of the sentry software/appliance (or maybe Tina?) in this list? Any feedback ?  
    
    Thanks.
    
    alx
    
    -- 
    Alexandre Dulaunoy			adulauat_private
    					http://www.conostix.com/
    
    
    ---------------------------------------------------------------------
    To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    For additional commands, e-mail: loganalysis-helpat_private
    



    This archive was generated by hypermail 2b30 : Tue Mar 12 2002 - 11:58:14 PST