Skip to content
Discussion options

You must be logged in to vote

You can send the Netflow data to any computer in your environment that's running the Elastic Agent and is reporting to Security Onion. Simply add the Netflow integration to that agent's policy and open up the appropriate firewall hole.

This Youtube video walks through the process for the PFSense integration, but the steps are largely similar: https://www.youtube.com/watch?v=aoH8qZwAxek

You can set the ILM policies through the Administration --> Configuration interface. Click on Options at the top, toggle on the Advanced settings, and then go to this location in the tree:

elasticsearch > index_settings > so-logs-netflow_x_log > policy > phases

You can set the values there for how long to r…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ejgh-oe
Comment options

Answer selected by ejgh-oe
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants