Skip to content
Discussion options

You must be logged in to vote

Most Security Onion users run both Zeek and Suricata at the same time with Suricata providing NIDS alerts and Zeek providing network metadata.

In Security Onion 2.3, all alerts go into Elasticsearch and so alert retention is managed by curator. By default, curator closes Elasticsearch indices once they reach 30 days. Curator also checks disk usage so if you reach log_size_limit, it will start deleting old indices to prevent filling your disk.

For more information, please see:
https://docs.securityonion.net/en/2.3/elasticsearch.html
https://docs.securityonion.net/en/2.3/curator.html?highlight=curator

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@angcar
Comment options

@dougburks
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants