• A collection facility can be implemented that generates
audit records containing only that information required
by the intrusion detection system.
• One advantage of such an approach is that it could be
made vendor independent and ported to a variety of
systems.
• The disadvantage is the extra overhead involved in
having, in effect, two accounting packages running on a
machine.