1833992 Members
3637 Online
110063 Solutions
New Discussion

Re: IDS/9000 Overhead

 
SOLVED
Go to solution
Ed Hon
Regular Advisor

IDS/9000 Overhead

What kind of performance impact should I expect from implementing IDS/9000 on an N-Class 2x440Mhz with about 70 users, used as a database and application server, not a web-server?
5 REPLIES 5
Stefan Farrelly
Honored Contributor

Re: IDS/9000 Overhead


Excuse my ignorance, whats IDS ? (I know what IFS is - Internet file system).
Im from Palmerston North, New Zealand, but somehow ended up in London...
Rainer von Bongartz
Honored Contributor

Re: IDS/9000 Overhead

what do you want to install ??

IDS/9000 agent only or IDS/9000
manager and agent system ??

I found the impact on performance depends very much on what you are monitoring, so a general guidline is very difficult to give.

Regards
Rainer

He's a real UNIX Man, sitting in his UNIX LAN making all his UNIX plans for nobody ...
Rainer von Bongartz
Honored Contributor
Solution

Re: IDS/9000 Overhead

sorry I forgot to mention that on production systems you should only run the IDS agent

Build up a separate box as the management system.

This will have the minimum performance issue on your production system.

He's a real UNIX Man, sitting in his UNIX LAN making all his UNIX plans for nobody ...
Ed Hon
Regular Advisor

Re: IDS/9000 Overhead

IDS = Intruder Detection System
I was originally going to install both the manager and the agent on the same machine, but from Ranier said, it might be a better to put the manager on my development machine.
Mark Crosbie
New Member

Re: IDS/9000 Overhead

Hi Ed (and all)

There's absolutely no problem installing IDS/9000 agents and the admin GUI on the same system for evaluation purposes. We do it all the time while testing in the lab.

True, the java interpreter will run a CPU at about 100% load, but you can quit the GUI and leave the agent running in the background. Alerts will be logged into the /var/opt/ids/alert.log file.

In a production environment we recommend only running an agent on a server that you are monitoring. The GUI can run on any other HPUX machine with java and a network connection.

How does IDS/9000 impact your system? As a previous poster mentioned it is highly dependent on your system profile. I have attached a short text document that outlines some "Best Practices" that I wrote up about configuring IDS. It will grow into a full white paper on configuration and deployment.

Hope this helps,
Mark
--
Mark Crosbie IDS/9000 Product Architect
http://www.hp.com/security/products/ids