Book · 2013
The Practice of Network Security Monitoring
by Richard Bejtlich
Richard Bejtlich's field manual for catching intruders by watching the wire, built around Security Onion and the assumption that prevention will fail.
What does Reddit think of The Practice of Network Security Monitoring?
Reddit barely talks about this one in the programming subs. The highest-upvoted appearance (↑58) is a thread about SELinux and Linux fundamentals where Bejtlich's title gets included next to the Cisco CCNA two-volume set and a stack of cert prep. The ↑43 comment is the same shape: a networking-focused sysadmin sharing his bookshelf. There is no contested take here, no GRRM-style debate, no 'DDIA as the necessary companion' moment. What you can say from the data: working network admins keep it on the shelf they recommend, alongside CCNA prep and the r/netsec wiki. What you cannot say: that anyone on r/programming, r/cscareer, or r/ExperiencedDevs has weighed in at all. They haven't.
Community feedback & reader fit
Themes
- · Network security monitoring as a discipline distinct from prevention
- · Security Onion as the tooling spine of the book
- · NSM workflow: collection, detection, analysis, escalation
- · Treated by r/sysadmin as a shelf companion to CCNA-level networking prep
- · Assumes the perimeter has already been breached
Common praise
- + r/sysadmin posters keep slotting it into their personal 'books I actually recommend' lists, which is rare for a 2013 No Starch title.
- + The Security Onion walkthroughs give a sysadmin something to install on Monday rather than a framework to nod at.
- + The assume-breach posture aged well; the ↑58 SELinux thread treats it as still-current reading in 2025.
Common criticism
- − Almost nobody on Reddit argues about the content itself. The mentions are bookshelf dumps, not debates.
- − Zero traction in r/programming, r/cscareerquestions, r/ExperiencedDevs, or r/netsec across the seven-year window we pulled.
- − Published 2013, and no commenter steps up to say which chapters still hold and which are dated.
- − If you want a thread where people fight over the tooling choices, you will not find one in this dataset.
Who it's for
Run networks for a living, or want to. If your weekly work involves pcap, IDS alerts, or wondering what just talked to that host, Bejtlich is writing for you. Treat it as the NSM-shaped gap next to your CCNA materials and your r/netsec wiki bookmarks. Pure application developers who never touch the wire will find it well outside their lane, and the Reddit silence from r/programming and r/ExperiencedDevs reflects that. Pick it up if 'Security Onion' already sounds like a tool and not a vegetable.
Mentions over time
Top subreddits
Which Reddit comments matter for The Practice of Network Security Monitoring?
Top-upvoted quotes across the subreddits where this book is mentioned. Click through to read the full thread.
“It's not insane... but it's not ideal either. SELinux didn't launch until 2000, and that's a pretty significant change in Linux fundamentals. ----- Nerd Books: [Cisco CCNA Certification, 2 Volume Set: Exam 200-301](
Convinced? Pick up The Practice of Network Security Monitoring
Readers also mention
Books that share discussion threads with The Practice of Network Security Monitoring — counted from the comments, not curated.
Network Warrior
Gary A. Donahue
Gary Donahue's field manual for the network engineer who inherits a closet full of Cisco gear and has to keep packets moving by Monday.
Practical Packet Analysis
Chris Sanders
Chris Sanders walks you through Wireshark captures of real attacks, slow networks, and broken handshakes until the protocol stack stops being abstract.
The Practice of Cloud System Administration
Thomas A. Limoncelli
Limoncelli's Volume 2 on running large distributed web services, the one r/sysadmin keeps listing right next to Volume 1 and rarely talks about on its own.
The Practice of System and Network Administration
Thomas A. Limoncelli
Thomas Limoncelli's field manual for the sysadmin who wants to stop firefighting and start running a shop that doesn't wake them up at 3 a.m.
TCP/IP Illustrated, Vol. 1
W. Richard Stevens
W. Richard Stevens wrote 24 Reddit-cited pages per year's worth of networking protocol detail so you'd stop guessing what's on the wire.
The Practice of Network Security Monitoring — frequently asked
What does Reddit think of The Practice of Network Security Monitoring?+
Reddit, in the programming subs we track, barely thinks about it at all. The book keeps appearing inside multi-link 'Nerd Books' lists next to the Cisco CCNA two-volume set, never as the subject of a thread. Working sysadmins clearly keep it on the shelf; nobody in r/programming or r/ExperiencedDevs has weighed in across the window.
Is The Practice of Network Security Monitoring still worth reading in 2026?+
Probably yes if you do network work, with a caveat. The most recent r/sysadmin mentions are from 2025, including the ↑58 SELinux thread, so practitioners still cite it. But it was published in 2013 and no Reddit commenter in our data steps up to say which chapters held up. Treat the Security Onion specifics as a starting point and check current docs; the NSM mindset is what's durable.
Who is The Practice of Network Security Monitoring for?+
Network-side sysadmins and security-curious infrastructure people. The only sub talking about it is r/sysadmin, and the commenters who recommend it pair it with CCNA prep and the r/netsec and r/networking wikis. If you write application code and never look at packets, the Reddit silence from r/programming and r/cscareerquestions is your signal. If pcap and IDS rules are part of the job, it's aimed at you.
How does The Practice of Network Security Monitoring compare to other NSM resources Reddit recommends?+
Hard to say from the data, which is itself the answer. Across six mentions, no commenter draws a contrast with another NSM title. They list it alongside CCNA materials, not alongside competing books. That means there is no Reddit-sourced 'X vs Bejtlich' debate to report. If you want a comparison shootout, this dataset cannot give it to you; cross-reference r/netsec directly.