-
Version2.4.30 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU4 RAM32 Storage for /100 Storage for /nsm200 Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHow I can add custom address-groups in SOC, for example FILE_SERVERS Guidelines
|
Beta Was this translation helpful? Give feedback.
Answered by
reyesj2
Jan 5, 2024
Replies: 1 comment 4 replies
-
The documentation on configuring additional host groups can be found here: https://docs.securityonion.net/en/2.4/firewall.html#host-groups |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This would be under Administration -> Configuration. At the top of the configuration page hit the drop down 'Options' menu and enable 'Show all configurable settings'.
Then navigate to the Suricata section, at the bottom there is an 'Advanced' section for suricata. Here is an example of how you'd make custom address-groups.
(for copy paste)
Once you have added that to your suricata config under advanced, at top of the configuration screen open the 'Options' menu again and press 'Synchronize grid'. That will take some ti…