skip to content
BooksReddit

Book · 2013

The Practice of Network Security Monitoring

by Richard Bejtlich

Richard Bejtlich's field manual for catching intruders by watching the wire, built around Security Onion and the assumption that prevention will fail.

6
Total mentions
1
Unique Reddit accounts
case-insensitively deduplicated across the selected corpus
Not scored
Avg sentiment
scored published excerpts: −1 pan ↔ +1 praise
1
Subreddit
where it's mentioned

What does Reddit think of The Practice of Network Security Monitoring?

Reddit barely talks about this one in the programming subs. The highest-upvoted appearance (↑58) is a thread about SELinux and Linux fundamentals where Bejtlich's title gets included next to the Cisco CCNA two-volume set and a stack of cert prep. The ↑43 comment is the same shape: a networking-focused sysadmin sharing his bookshelf. There is no contested take here, no GRRM-style debate, no 'DDIA as the necessary companion' moment. What you can say from the data: working network admins keep it on the shelf they recommend, alongside CCNA prep and the r/netsec wiki. What you cannot say: that anyone on r/programming, r/cscareer, or r/ExperiencedDevs has weighed in at all. They haven't.

Community feedback & reader fit

Themes

  • · Network security monitoring as a discipline distinct from prevention
  • · Security Onion as the tooling spine of the book
  • · NSM workflow: collection, detection, analysis, escalation
  • · Treated by r/sysadmin as a shelf companion to CCNA-level networking prep
  • · Assumes the perimeter has already been breached

Common praise

  • + r/sysadmin posters keep slotting it into their personal 'books I actually recommend' lists, which is rare for a 2013 No Starch title.
  • + The Security Onion walkthroughs give a sysadmin something to install on Monday rather than a framework to nod at.
  • + The assume-breach posture aged well; the ↑58 SELinux thread treats it as still-current reading in 2025.

Common criticism

  • − Almost nobody on Reddit argues about the content itself. The mentions are bookshelf dumps, not debates.
  • − Zero traction in r/programming, r/cscareerquestions, r/ExperiencedDevs, or r/netsec across the seven-year window we pulled.
  • − Published 2013, and no commenter steps up to say which chapters still hold and which are dated.
  • − If you want a thread where people fight over the tooling choices, you will not find one in this dataset.

Who it's for

Run networks for a living, or want to. If your weekly work involves pcap, IDS alerts, or wondering what just talked to that host, Bejtlich is writing for you. Treat it as the NSM-shaped gap next to your CCNA materials and your r/netsec wiki bookmarks. Pure application developers who never touch the wire will find it well outside their lane, and the Reddit silence from r/programming and r/ExperiencedDevs reflects that. Pick it up if 'Security Onion' already sounds like a tool and not a vegetable.

Mentions over time

Q2 2022 peak: 1/qtr Q2 2025

Top subreddits

Which Reddit comments matter for The Practice of Network Security Monitoring?

Top-upvoted quotes across the subreddits where this book is mentioned. Click through to read the full thread.

It's not insane... but it's not ideal either. SELinux didn't launch until 2000, and that's a pretty significant change in Linux fundamentals. ----- Nerd Books: [Cisco CCNA Certification, 2 Volume Set: Exam 200-301](

r/sysadmin ↑ 58 Not scored

Readers also mention

Books that share discussion threads with The Practice of Network Security Monitoring — counted from the comments, not curated.

The Practice of Network Security Monitoring — frequently asked

What does Reddit think of The Practice of Network Security Monitoring?+

Reddit, in the programming subs we track, barely thinks about it at all. The book keeps appearing inside multi-link 'Nerd Books' lists next to the Cisco CCNA two-volume set, never as the subject of a thread. Working sysadmins clearly keep it on the shelf; nobody in r/programming or r/ExperiencedDevs has weighed in across the window.

Is The Practice of Network Security Monitoring still worth reading in 2026?+

Probably yes if you do network work, with a caveat. The most recent r/sysadmin mentions are from 2025, including the ↑58 SELinux thread, so practitioners still cite it. But it was published in 2013 and no Reddit commenter in our data steps up to say which chapters held up. Treat the Security Onion specifics as a starting point and check current docs; the NSM mindset is what's durable.

Who is The Practice of Network Security Monitoring for?+

Network-side sysadmins and security-curious infrastructure people. The only sub talking about it is r/sysadmin, and the commenters who recommend it pair it with CCNA prep and the r/netsec and r/networking wikis. If you write application code and never look at packets, the Reddit silence from r/programming and r/cscareerquestions is your signal. If pcap and IDS rules are part of the job, it's aimed at you.

How does The Practice of Network Security Monitoring compare to other NSM resources Reddit recommends?+

Hard to say from the data, which is itself the answer. Across six mentions, no commenter draws a contrast with another NSM title. They list it alongside CCNA materials, not alongside competing books. That means there is no Reddit-sourced 'X vs Bejtlich' debate to report. If you want a comparison shootout, this dataset cannot give it to you; cross-reference r/netsec directly.