Skip to content
Discussion options

You must be logged in to vote

You don't need to modify kibana.yml. You should only need to run so-allow as described in the documentation:
https://docs.securityonion.net/en/2.3/so-allow.html#so-allow

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants