This is probably a stupid question but I am a complete novice with snort and IDS systems but I was curious if you could just have one box do the database/sensor work for snort? I am in a very small network, 50 computers probably and my boss wanted a snort server for whatever reason. I know my way around FreeBSD well enough to give a go at this but I hear it's a major pain in the butt. Anybody with lots of experience with snort that can shed some light on a poor novice
?
Thanks much,
...Shrum
Thanks much,
...Shrum