-
Version2.4.90 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationairgap Hardware SpecsMeets minimum requirements CPU24 RAM128 Storage for /500GB Storage for /nsm6TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusNo, one or more services are failed (please provide detail below) Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello, Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
If you use a specific integration for a specific log type, then the logs will be fully parsed allowing you to slice and dice all of the fields separately in our user interfaces like Dashboards and Hunt. If you don't use a specific integration, but instead use plain syslog, then the logs will not be parsed by default and you would need to develop your own parsers from scratch. We recommend using a specific integration so that you get fully parsed logs without additional effort. For more information, please see: |
Beta Was this translation helpful? Give feedback.
If you use a specific integration for a specific log type, then the logs will be fully parsed allowing you to slice and dice all of the fields separately in our user interfaces like Dashboards and Hunt.
If you don't use a specific integration, but instead use plain syslog, then the logs will not be parsed by default and you would need to develop your own parsers from scratch.
We recommend using a specific integration so that you get fully parsed logs without additional effort.
For more information, please see:
https://docs.securityonion.net/en/2.4/syslog.html
https://docs.securityonion.net/en/2.4/third-party-integrations.html