-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU64 RAM64 Storage for /500G Storage for /nsm20T Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi all. I have set up SO integration with AlienVault OTX. Integration has been added to the so-grid-nodes_general policy. Now when viewing indicators in Kibana I see quite a lot of duplicates when viewing one indicator. What solutions to the problem are possible in this case? I believe that due to the addition of integration to the so-grid-nodes_general policy, indicators are loaded from all 4 agents that are under this policy. For now, the solution seems to be to remove the node manager from this policy and assign it a separate policy. We have a distributed deployment. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
You should add the alienVault integration to the fleet server policy
https://docs.securityonion.net/en/2.4/elastic-fleet.html#adding-an-integration |
Beta Was this translation helpful? Give feedback.
You should add the alienVault integration to the fleet server policy
https://docs.securityonion.net/en/2.4/elastic-fleet.html#adding-an-integration