How to view windows event IDs forwarded via the elastic agent and how to control which event IDs are sent to Security Onion #13375
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU16 RAM100G Storage for /Lots Storage for /nsmLots Network Traffic Collectiontap Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailRunning sudo salt-call state.highstate give a message Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 6 replies
-
I have a standalone version of Security Onion. I have the system working and elastic agents installed. I can navigate to dashboards to see the sysmon overview to see sysmon events reported, however I am unable to find a view of the Windows Event IDs that have been shipped to Security Onion. How are those viewed and controlled (in terms of which event IDs are shipped up to SO) in 2.4.60? |
Beta Was this translation helpful? Give feedback.
You would want to make sure there is a sigma rule in Detections enabled. That would generate alerts based on matches.
If you do not see one that covers your use case, there is a template in Detections where you can tailor a sigma rule to your specific detection.