It can be important to know whats going through your network.
Once we hit about 10Mb/s we found a lot of information about day to day network activity from Snort.
I has allowed us to cut down on unwanted traffic and save us money in bandwidth and CPU cycles. Verall a good thing.
Rock solid hosting and dedicated servers since 1998! StabilityHosting Where stability and uptime are king!
We run snort on freebsd with snortsam setup with various blocking rules on the firewall. Snort gives a great overview of some traffic conditions we see and then we seta few rules to trigger snortsam to automagically throw temporary blocks into the firewall for IPs that are causing trouble. (e.g brute force attacks, dos, virus propagation).