Skip to content
Discussion options

You must be logged in to vote

If you are referring to collecting logs only, you could consider using the AWS Filbeat module:
https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-aws.html
https://docs.securityonion.net/en/latest/filebeat.html#modules

If you are referring to actually monitoring traffic in AWS and feeding that back to your on-prem stack, you could consider running a sensor in AWS, and your manager and search node(s) locally:
https://docs.securityonion.net/en/latest/cloud-ami.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants