Determining Your Events per Second

Although the numbers presented in Table 3-3 might not be realistic in your network, they do give you an idea of which types of devices tend to send the most events. The noisiest devices on your network are likely in this order 3 Intrusion detection systems intrusion prevention systems (IDS IPS) 4 Virtual Private Network (VPN) devices 7 Other devices, such as databases, operating systems, antivirus software, desktop and server protection software (such as Cisco Security Agent), and so on This...

Security Device Event Exchange SDEE

SDEE is a somewhat open standard used by many IPS IDS vendors, including Cisco, ISS, Sourcefire, and TruSecure. Somewhat open means that you can use it, but it is ultimately owned by the International Computer Security Association (ICSA). SDEE uses Extensible Markup Language (XML) to organize the format of IDS alerts (or events) and specifies the protocol as HTTP. SDEE was designed to be both flexible and extensible. SDEE, when used on Cisco IDS IPS sensors, is backward compatible with Remote...