Swatch replacement

From Finninday
Revision as of 23:43, 29 November 2007 by Rday (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Thursday, May 12th, 2005

I just learned that what I wanted to do with swatch is really event correlation. Imagine that. I just wanted to identify similar attacks from the same source within a window of time to automatically respond to them. Swatch is a favorite old tool of mine and I tried to make it work for this task, but I just couldn’t get the threshhold feature to work. So I looked around and found Simple Event Correlation. Very nice. But way more complex than I would like. Oh well, I just need a good article with lots of examples to help me understand it.