Skip to content
Discussion options

You must be logged in to vote

Please see https://docs.securityonion.net/en/2.3/cases.html#data:

Cases data is stored in Elasticsearch. You can view it in Dashboards or Hunt by clicking the Options menu and disabling the Exclude case data option. You can then search the so-case index with the following query:

_index:"*:so-case"

You can also use this query in Kibana.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@Ron89
Comment options

@dougburks
Comment options

@Ron89
Comment options

@dougburks
Comment options

@dougburks
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants