Skip to content
Discussion options

You must be logged in to vote

If you want to pull down and ingest logs from a cloud service like Azure, you can do it from any Elastic Agent that's reporting back to your Security Onion installation. It doesn't have to be a member of the SO grid, it can be any device on which you've installed the agent.

Simply duplicate the Agent Policy that's already there (so-grid-nodes-general for an SO host, endpoints-initial for a non-SO host), and add the integration for Azure with the relevant details.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@udi-mosh
Comment options

Answer selected by udi-mosh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants