-
Version2.4.20 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU8 RAM32 Storage for /1T Storage for /nsm80% Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi How can I differentiate which host(s) are coming from which office (or Forward Nodes) from the perspective of SecOnion Kibana page? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
The events coming from different forward nodes will be tagged up as such in kibana/SO. In the 'host.name' field, events from forward node A will have 'forward node A' and so on. On the 'Alerts' page you can also filter by sensor etc. |
Beta Was this translation helpful? Give feedback.
The events coming from different forward nodes will be tagged up as such in kibana/SO. In the 'host.name' field, events from forward node A will have 'forward node A' and so on. On the 'Alerts' page you can also filter by sensor etc.