Skip to content
Discussion options

You must be logged in to vote

We've invested significant time and effort into building a web config interface so that the text-based portion of Setup can be as simple as possible. We have no plans to add back any complexity to the text-based portion of Setup. Here's a possible workaround:

  1. Disable stenographer by changing your grid default PCAP engine to Suricata:
    https://docs.securityonion.net/en/2.4/suricata.html#pcap

  2. Then change your grid default Suricata configuration to only record PCAP for NIDS alerts OR perhaps use the tag option but don't define any tags:
    https://docs.securityonion.net/en/2.4/suricata.html#conditional-pcap

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@kspringer-maf
Comment options

Answer selected by kspringer-maf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants