I'm new to setting up a sensor and now have it ready to start sending. I'm using iptables logs.
Should I be sending as much as possible (eg all legitimate traffic as well as bad traffic) or should there be some filtering on my side ?
Also, there doesnt seem to be much on how often these logs should be sent. Should they be sent say once every 10 minutes ?
Aug 4th 2015
4 years ago