2.4.120 - elastic agent integrations placement #14291
-
Version2.4.120 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU24 RAM128 Storage for /500GB Storage for /nsm6TB Network Traffic Collectiontap Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailHi All, Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
just read the documentation again and to correct my self, i understand that i need the elasticsearch and not the logstash to parse. |
Beta Was this translation helpful? Give feedback.
-
If you want to pull down and ingest logs from a cloud service like Azure, you can do it from any Elastic Agent that's reporting back to your Security Onion installation. It doesn't have to be a member of the SO grid, it can be any device on which you've installed the agent. Simply duplicate the Agent Policy that's already there (so-grid-nodes-general for an SO host, endpoints-initial for a non-SO host), and add the integration for Azure with the relevant details. |
Beta Was this translation helpful? Give feedback.
If you want to pull down and ingest logs from a cloud service like Azure, you can do it from any Elastic Agent that's reporting back to your Security Onion installation. It doesn't have to be a member of the SO grid, it can be any device on which you've installed the agent.
Simply duplicate the Agent Policy that's already there (so-grid-nodes-general for an SO host, endpoints-initial for a non-SO host), and add the integration for Azure with the relevant details.