I like that it is easy to set up, very flexible with rules (I can write my own or use existing ones) and capable of handling many different protocols/protocols simultaneously. It's not as good at finding malicious activity when compared against other software such as FOG but this has more to do with its configuration than anything else. If you are looking for something cheap then go ahead! Otherwise there are better solutions out there which will offer much greater functionality without breaking your budget. You're goal should be security monitoring so if price isn't an issue look elsewhere. Security issues from both internal users and external threats.