Skip to content
Discussion options

You must be logged in to vote

Hello and welcome to Security Onion Discussions!

I am having a hard time finding the right answer. For a standalone the docs say use for "testing, Labs, POCs, very low throughput". A distributed deployment does not give specifics. However, if I am in a Windows environment with several VMs running different servers, do I need to run a distributed deployment?

Yes, for enterprise environments we recommend distributed deployments. From https://docs.securityonion.net/en/2.4/architecture.html#distributed:
This architecture may cost more upfront, but it provides for greater scalability and performance, as you can simply add more nodes to handle more traffic or log sources.

From there, what wo…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by devstrauss
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants