Skip to content
Discussion options

You must be logged in to vote

I have a newly installed Standalone version of Security Onion (v2.3.182) runnnin on hypervisor thats not producing any alerts in the SOC Console. I have 6 Windows Servers running winlogbeat and with sysmon installed.

Winlogbeat+sysmon won't produce any alerts by default, but you could define criteria to generate an alert if you'd like:
https://docs.securityonion.net/en/2.3/playbook.html

I do have Eth1 configured for monitoring but we dont have SPAN port confgured on the virtual switch yet

Once you have your SPAN port configured, you will most likely start seeing NIDS alerts. If not, you can follow the troubleshooting steps here:
https://docs.securityonion.net/en/2.3/suricata.html#trou…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Wilks2222
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants