Skip to content
Discussion options

You must be logged in to vote

We have come across a LARGE number of monitoring/alerting toolsets that just don't understand the concept of wall screens and rotating display. SIGH

I understand the concept of wall screens and rotating displays. I also understand the type of data that is in SO and what can be done with some of that data. You should NEVER allow access to SO by just IP alone. The solution here is pretty simple. Create a limited auditor user to use to log into SOC. The limited auditor role was added to the roles for exactly the use case of a screen in a operations center. https://docs.securityonion.net/en/2.3/rbac.html#default-roles

Then adjust your timeout value to be a week or so.
https://docs.securityo…

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@I-Simon-I
Comment options

@TOoSmOotH
Comment options

Answer selected by TOoSmOotH
@I-Simon-I
Comment options

@TOoSmOotH
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants