IDS
IDS, or Intrusion Detection System, is an application that monitors for malicious activity and policy violations on your network. When configuring this event source in InsightIDR, the IDS data is attributed to the user and asset details page and allows you to search through the data. However, it does not produce alerts.
IDS Event Sources
InsightIDR can collect events from these types of IDS/IPS devices:
- Cisco FirePower
- Corero IPS
- Dell iSensor
- F5 Networks BIG-IP Local Traffic Manager
- HP TippingPoint
- Juniper Junos
- McAfee IDS
- Metaflows IDS
- Security Onion
- Sentinel IPS
- Snort IDS
- Network Sensor
To collect IDS/IPS events, you need to configure the device to send syslog to the collector.
Did this page help you?