IPS Packet Logging
I have 2 questions that I was hoping someone would be able to provide insight on...
1) If I enabled packet logging on my IPS sensors, will that enable me to download the packets that triggered an alert in the form of a PCAP file? Or will that simply add more packet information to the log files?
2) If I enable packet logging, what possible "side-effects" should I expect to see (i.e. drastic increase in memory/CPU usage, the disk fills up quicker than expected, etc...)?
Thank You!!
