Ingesting Netflow in Security Onion
A walkthrough of how to ingest Netflow data in your Security Onion environment, for small or remote networks where you don't have a dedicated Security Onion forward node.
Security Onion Filebeat documentation:
https://docs.securityonion.net/en/2.3/filebeat.html
Elastic Filebeat Module documentation:
https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html
Security Onion Firewall documentation:
https://docs.securityonion.net/en/2.3/firewall.html
Filebeat command to build Logstash pipeline:
# docker exec -i so-filebeat filebeat setup modules -pipelines -modules netflow -c /usr/share/filebeat/module-setup.yml
If you have questions or problems, please start a new discussion at https://securityonion.net/discuss
Thanks!
Видео Ingesting Netflow in Security Onion автора PythonAdventure
Видео Ingesting Netflow in Security Onion автора PythonAdventure
Информация
4 декабря 2023 г. 3:11:00
00:14:00
Похожие видео