How to alert on firewall IPs outside HOME_NET + bulk-loading 1000 + custom rules #14810
-
Version2.4.160 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM24GB Storage for /200 gb Storage for /nsm200 gb Network Traffic Collectionspan port Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailSetup Summary: Problem: I want to:
What I’ve Tried: Traffic is confirmed to reach the sensor (via tcpdump) The IPs are excluded from HOME_NET, so existing rules won’t trigger I haven’t found a clear path for bulk uploading custom rules in SO 2.4 or for writing rules targeting IPs outside HOME_NET My Questions:
Any help or best practices would be greatly appreciated. Thanks! Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Beta Was this translation helpful? Give feedback.
What do you mean? I have FortiGate logs on my SO in Elastic and in Dashboards.
Integration process is the same as described at this video:
https://www.youtube.com/watch?v=aoH8qZwAxek
except instead of pfSense you use Fortigate integration. In result you will have fortigate dataset with all searchable logs.