Skip to content
Discussion options

You must be logged in to vote

No, Sysmon and Suricata are totally independent of each other. Sysmon generates telemetry about what is happening on an endpoint, whereas Suricata analyzes network traffic from a tap or span port. For more information, please see:
https://docs.securityonion.net/en/2.3/suricata.html
https://docs.securityonion.net/en/2.3/sysmon.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants