Skip to content
Discussion options

You must be logged in to vote

The alerts tab is going to be for your active rules whether that is suricata / sigma / yara. All configurable via the Detections tab. This is where you'll get an overview of triggered rules and can begin your investigation and potentially escalate to a Case.

If you didn't know Security Onion Solutions has a YouTube channel. Here is a video that will help answer some of your questions on how the workflow might look for you.

For the log storage:

Where are the logs usually stored?

Logs ingested by the Elastic Agent end up in Elasticsearch. Which runs on your manager & searchnodes.

How can we find the exact location of the logs (for example, hot or cold storage)?

If you have tiered storag…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by abcd123chamara
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants