Net/FSE (Packet Analytics)
The FSE in Net/FSE stands for “Forensic Search Engine.” This browser-based tool is aimed at network security analysts to allow them to sort through network data in the event of a security alert from intrusion prevention and detection systems, firewalls, etc. Packet Analytics says this helps analysts determine what hosts are associated with the alert, when the activity started and whether it’s ongoing, where the activity started from and how many hosts are involved.
Net/FSE does this by acting as a NetFlow collector and syslog server, so if you’re primarily a Cisco shop, you’re good. According to the company, custom agents can be designed if Netflow’s no use to you. Two presumptions here, since the company hasn’t returned calls asking the questions: We’re presuming the custom agents aren’t free, and that agents for Juniper’s jFlow and Huawei’s NetStream would likely be in stock. Hopefully, CEO Andy Alsop will have set us straight before we have to publish this. (Or, if not, I’m sure he will shortly after.)
Net/FSE was built in Mac OS X and runs on OS X and most distributions of Linux. Check for compatibility here.
And Net/FSE is free … sort of. The free licence captures up to one million events per day and offers free e-mail support. Beyond that, annual licences and support range from $1,495 plus $299 (up to three million events per day) to $18,950 plus $3,790 for up to 50 million events per day.
Remember to rate this if you use it, and use the e-mail link to suggest other handy downloads.
UPDATE: Andy Alsop of Packet Analytics has this to say about agents for Net/FSE:
Net/FSE does not natively handle jFlow or Netstream but custom handlers can be developed. We are working with customers to develop the library of log handlers and the types of log handlers in Net/FSE is all based on the customers needs and infrastructure. In your post about Net/FSE, yes the custom handlers aren’t free but if they have broad market applicability we will most likely do the work at no charge as it enhances our library of handlers.
Add to: del.icio.us | Digg IT | Furl | Google | magnolia | StumbleIT | Wink | Yahoo! Technorati

