Global Pillar File #14129
-
Version2.4.111 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU8 RAM64 Storage for /250GB Storage for /nsm7TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi Everybody, i think i am missing something but for the life of me i cant seem to figure this out, so im hoping this is a very quick fix and answer from you guys. Im just looking at tuning some NIDS rules, and im following a you tube video on the offical Security Onion channel called "Tuning NIDS Rules in Security Onion" No its telling me to edit the Global.sls file in /opt/so/saltstack/local/pillar/ but at this location there is no global.sls file, if i go into the global folder in that location i can see a soc_global.sls but i think this is different. Am i missing something or has this changed since this video was released? Any help would be really appreciated. Many Thanks P Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
It looks like you're looking at an older video. The latest video walks you through using the Detections interface for your rule tuning. |
Beta Was this translation helpful? Give feedback.
It looks like you're looking at an older video. The latest video walks you through using the Detections interface for your rule tuning.
https://www.youtube.com/watch?v=DelAmqtU2hg. Much simpler and no modifying pillar files!