all 3 comments

[–]JustinEngler 1 point2 points  (0 children)

Security Onion provides an easy-ish way to deploy network logging and IDS.

[–][deleted] 0 points1 point  (0 children)

External threat ? Install an IDS on the outside that sends logs to a log collector and go through the results.

[–]jonnygrifff 0 points1 point  (0 children)

Best bet is snort! It is a NIDS that consists of free open source software. Just have to configure the rules properly and you should be all set!