Install Sguil Squert & ElastiFlow to use with S.O2.3 #1970
-
Hi Mates, I know that Sguil & Squert don't support IPv6 so we replace it with the Alert. But I don't need IPv6, and Sguil meets my need. There are any ways that Sguil installed and work with S.O2.3? ElastiFlow have useful dashboards to me. Can I change the logstash pipeline, create new index and add Elastiflow to S.O2.3 Kibana? Thanks & Regards |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
How could we install more logstash plugin and ingest pipeline when logstash is running in docker? |
Beta Was this translation helpful? Give feedback.
-
We do not support Sguil or Squert in Security Onion 2.3. You may be able to make ElastiFlow work but we have no experience with that. |
Beta Was this translation helpful? Give feedback.
We do not support Sguil or Squert in Security Onion 2.3. You may be able to make ElastiFlow work but we have no experience with that.