Skip to content
Discussion options

You must be logged in to vote

I stood up a temporary single test deployment of security onion a couple years ago as a short term solution until the expensive solution forced on me by execs was set up. We are throwing out the expensive solution and planning to build out a proper distributed sec onion.

Welcome back! Make sure you're using the latest version 2.4 as it makes administration and configuration MUCH easier than previous versions:
https://docs.securityonion.net/en/2.4/administration.html

My understanding of how sec onion manages sec onion rules is that I append the config file on the manager and the salt stack pushes to all the servers.
How do I manage which rules I want to go to all sec onion servers (ie E…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by subs1138
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants