| |
| | Argus - FAQ |
 | | Argus is run either as a persistant daemon, reading live packets from a network interface, or as a user program, reading packets from a packet capture file. |
 | | Argus has a large number of options, which can be set through an.Argusrc file, the use of command line options, or through a separate configuration file that is specifed at run time. |
 | | Argus can be easily tuned to be more timely in reporting audit events, but without that tuning, Argus could take as long as 30-120 seconds to print out a particular record, depending on the load of the Argus, the protocol and when the last packet was seen. |
| www.qosient.com /argus/faq.htm (2834 words) |
|