• Support
  • Forums
  • Blogs

Virtual remote sensor VS Virtual Sensor in a multiple ESX deployment

egeeekegeeek

New Life Form
Hello,
We are looking at deploying AlienVault USM in an architecture with 16 ESX, and significant overall bandwith.
As we want to be able to capture the traffic that is even internal to each ESX, we are considering putting 16 virtual remote sensors.
But:
 1/ If the goal of the remote sensors is just to capture traffic and have NIDS, could remote sensors be replaced by Security Onion for example and forward those logs to USM to be used as flows coming from remote sensors?
 2/ what is the difference between remote sensors VS sensors if the 2 network interfaces are enough? except for price, is there for example a max bandwith difference or bandwith is just a matter of ressources allocated to the virtual machine?
 
Thank you very much in advance

Regards

Share post:

Answers

  • If the question is too complex, I would be really thankful to have some feedbacks regarding the max throughput a remote sensor can handle if used just for this purpose depending on the allocated resources (RAM/CPUs)
Sign In or Register to comment.