-
I noticed that in 2.1.130, Security Onion has introduced a new case management system. While it provides the basic functionalities of recording evidence and discussions, we find the lack of custom search ability make them hard to keep track of in the long run. Since SO2 makes heavy use of ElasticSearch, can we use it to keep the case record so that they can be easily found with flexible criteria? Or maybe increase the flexibility of the case search functionality in the SOC itself? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 5 replies
-
Please see https://docs.securityonion.net/en/2.3/cases.html#data:
|
Beta Was this translation helpful? Give feedback.
Please see https://docs.securityonion.net/en/2.3/cases.html#data: