-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationcloud Hardware SpecsExceeds minimum requirements CPU16 RAM250 Storage for /1TB Storage for /nsm500 Gb Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI have a Security Onion distributed deployment in a production cloud environment, with one manager node, one search node, and one sensor node. The sensor node currently has two NICs (one for the management interface and one for monitoring). My goal is to monitor all network traffic across multiple VLANs. Environment Details: The deployment is on a Proxmox setup with 5 nodes.
My questions:
Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Yes, you can add many interfaces to the sensor. Then you would run |
Beta Was this translation helpful? Give feedback.
Yes, you can add many interfaces to the sensor. Then you would run
sudo so-monitor-add
(on the sensor) to configure the sensor to start ingesting traffic from the additional interfaces. https://docs.securityonion.net/en/2.4/so-monitor-add.html#so-monitor-add