Skip to content
Discussion options

You must be logged in to vote

I expect this could be done by setting it up as a grid with separate forward

Yes, most folks doing an enterprise deployment are going to have a distributed deployment anyway and that provides many other advantages as well.

Here are a few other options that might help depending on the scenario.

Modify alerts:
https://docs.securityonion.net/en/2.4/managing-alerts.html#modify-the-alert

Rewrite alerts:
https://docs.securityonion.net/en/2.4/managing-alerts.html#rewrite-the-alert

Suppress alerts:
https://docs.securityonion.net/en/2.4/managing-alerts.html#threshold

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by petiepooo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants