Skip to content
Discussion options

You must be logged in to vote

If you're sending via syslog protocol, run so-allow and choose the s option.

If you're sending via Elastic beats, run so-allow and choose the b option.

Configure filebeat to send to Logstash rather than Elasticsearch.

For more information, please see:
https://docs.securityonion.net/en/2.3/so-allow.html?highlight=so-allow
https://docs.securityonion.net/en/2.3/beats.html

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@banderson443
Comment options

Answer selected by dougburks
Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants