Skip to content
Discussion options

You must be logged in to vote

If you build a forward node at the remote site, then it will consume traffic from the SPAN port and do the analysis itself. Full packet capture remains on the forward node. The only thing sent from the forward node to the manager is the Suricata alerts and Zeek metadata and this is a much smaller amount of data than the original network traffic. For more information, please see:
https://docs.securityonion.net/en/2.4/architecture.html#forward-node

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@tsmith-spscc
Comment options

Answer selected by tsmith-spscc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants