How to ingest ADAudit data #14280
-
Version2.4.120 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPUmany RAMmuch Storage for /lots Storage for /nsmlots Network Traffic Collectionother (please provide detail below) Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHello, we have a system called AD Audit Plus. It has a section that allows it to send it's data to a SIEM. I was wondering if anyone out there has AD Audit Plus and has connected it to their Security Onion SIEM, and was hoping for some instructions. What do I need to do on the SO side to ingest the data, and what do I define on the ADAudit side to send the data. Here's a screenshot of the ADAudit screen. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Hello there, |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
It was super easy to accomplish this. I allowed the source IP into Administration>Configuration>firewall>hostgroups>syslog
Then I simply enabled the service on the AD Audit server, and I can see the logs coming into Security Onion. Very smooth!