Where does my router syslog get sent to in SecurityOnion? #10008
Replies: 2 comments
-
One the data goes through the ingest pipeline it will be in an index |
Beta Was this translation helpful? Give feedback.
0 replies
-
@tanc7 fwiw you can also use |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I configured my router to send it's syslog over the LAN to my SecurityOnion node listening on port 514. I seen it working but I don't know where this information is stored.
https://docs.securityonion.net/en/2.3/syslog.html
I would like to parse through them so I can report on the IP addresses scanning my public IP by looking at it's firewall notifications. I already can do this and make a formatted csv file.
Beta Was this translation helpful? Give feedback.
All reactions