powered by performancing firefox
Perfection is attained, not when no more can be added, but when no more can be removed. (Il semble que la perfection soit atteinte non quand il n'y a plus rien à ajouter, mais quand il n'y a plus rien à retrancher.) Antoine de Saint Exupéry
Thursday, September 28, 2006
Volumes of Network metadata
So I'm doing a firewall ruleset review for a customer and decide to create a toy database just to play around with some queries on the logs...~55 million rows and 19G later...this is why people who ask for full event correlation usually don't know what they're asking for. The volumes of data involved are large. And I'm not not talking about session captures above. That's just "this ip address tried talking to this ip address on this udp port and was dropped on this interface of this firewall at this time"...On the plus side, iPods are now up to 80G!
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment