SO setup only for syslogs and windows events #10549
-
Hello, I have already a SO server as IDS. I like to have another one only for collecting syslog messages and Windows events and analyzing them. Should I only create an analyst VM? Would it be enough? What is your recommendation? Thank you. Cheers, Isac |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Jun 23, 2023
Replies: 1 comment 2 replies
-
If you're trying to collect logs to review, you can do that with your current SO server. Simply use so-allow to allow traffic from the endpoints that will be sending logs and they should be parsed and available for you in Hunt. Dcoumentation:
|
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Yes, you can install a single ManagerSearch box or you can install a Manager box with a separate Search box:
https://docs.securityonion.net/en/2.3/architecture.html#distributed