Skip to content
Discussion options

You must be logged in to vote

Take a look at the hardware requirements page https://docs.securityonion.net/en/2.3/hardware.html

There's a lot of useful planning information in there. There isn't a specific set of requirements for a forward node as it is very dependent on things like the amount of PCAP data you want to store, the speed (and utilisation) of the links you want to monitor, the types of monitoring you want to configure (Snort, Strelka etc) and other factors.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@dlazure
Comment options

@tomjones1977
Comment options

@dlazure
Comment options

@tomjones1977
Comment options

@dlazure
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants