Hacker News new | ask | show | jobs
by monkey26 4425 days ago
It's true. I develop such software commercially. Sure we have some govt. users, but the majority is the enterprise.

Full packet capture for how much disk space you want to allocate to it (many like 48 hours) then longer term storage of flow records, DNS and http metadata, etc.

The majority of the use cases are watching the internal uses of the network as well - not generally being used to detect intruders.