<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Alert Data on Bill Brown:Thoughts and Reference Material Online</title><link>https://www.billbrown.info/tags/alert-data/</link><description>Recent content in Alert Data on Bill Brown:Thoughts and Reference Material Online</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>BillBrown.info</copyright><lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.billbrown.info/tags/alert-data/index.xml" rel="self" type="application/rss+xml"/><item><title>Alert Data and NSM Tools for Intrusion Detection</title><link>https://www.billbrown.info/post/alert-data-and-nsm-tools-for-intrusion-detection/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://www.billbrown.info/post/alert-data-and-nsm-tools-for-intrusion-detection/</guid><description>
&lt;!-- SOURCE: ISSC642/forum4/forum_post_4.docx --&gt;
&lt;h2 id="alert-data-and-nsm-tools-for-intrusion-detection"&gt;Alert Data and NSM Tools for Intrusion Detection&lt;/h2&gt;
&lt;p&gt;Network Security Monitoring (NSM) data that has been previously discussed are full content data (FCD), session data and statistical data. The result of an NSM specific data is to identify decisions based on views of network traffic. The NSM tool assists the analyst(s) if an event identified is nonthreatening, suspicious, or malicious. Once the event is identified it leads the analyst to the next action. NSM tools, as described by Bejtlich (2013) are to assist analysts in three ways. The first way is to make it was for them to review many types of NSM data in a single interface. A second way as Bejtlich (2013) describes, is to enable the analyst(s) to pivot from one type of data to another and the third or last way is the NSM tool capture the outcome of the analyst(s) decision making process. The use of NSM tools allow one or many analysts to complete a shared objective. Examples of data collection tools are Tcpdump, Snort, Cicso Net Flow and Cisco Account as Bejtlich (2004) points out.&lt;/p&gt;</description></item></channel></rss>