The attack on internet systems increasingly rampant, almost all of the information in the system vulnerableto attack and also generated a lot of financial losses due to these attacks, of course, as networkadministrators, is not an easy job to monitor the hundreds of IP in and out of clients. Install the honeypot tofool hackers also not the only way to better secure the internal regions and Demilitary Zone (DMZ). Weneed the help of a system that can monitor the data packet and record it and provide further information tobe analyzed further. System Intrusion Detection System (IDS) can help users monitor and analyze problemsin network security. In this case the IDS used a snort for windows software to monitor user activities on thesystem and out of the corporate network. The expected result is to know how much inconvenience caused tothe system through a corporate network traffic. Data Base created using MySQL and what actions shouldbe taken on these disorders will be the future. Testing of IDS performed on a local network of PT. AsuransiJiwa Inhealth Indonesia for six days. Observations were made to the directory the user can monitor thedaily activities in the network and the result will be a reference in determining how much disk capacity isneeded for the system is not disturbed or damaged. Observations also held with the activities of suspectedhacker activities, such as sending large data packets that can make the system unstable or monitor activityin and out of IP networks that are not known or suspected. The results of this analysis is that with as manyas 45 (fourty five) user disk capacity to be provided for one year is 40 GB.Keywords : hacker, Intrusion Detection System, snort for windows