Skip to content
Discussion options

You must be logged in to vote

How long are logs typically stored in Security Onion by default?

This depends on how much disk space you have:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Is it possible to change the log retention period? If so, how can this be configured?

Yes:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Where are logs normally stored in Security Onion?

/nsm:
https://docs.securityonion.net/en/2.4/directory.html

If logs are overwritten, how many days of logs are retained before they are overwritten?

This depends on how much disk space you have:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Is it possible to st…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@SankaGamage
Comment options

@dougburks
Comment options

Answer selected by SankaGamage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants