No Alerts in Dashboard #9244
-
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Winlogbeat+sysmon won't produce any alerts by default, but you could define criteria to generate an alert if you'd like:
Once you have your SPAN port configured, you will most likely start seeing NIDS alerts. If not, you can follow the troubleshooting steps here: |
Beta Was this translation helpful? Give feedback.
Winlogbeat+sysmon won't produce any alerts by default, but you could define criteria to generate an alert if you'd like:
https://docs.securityonion.net/en/2.3/playbook.html
Once you have your SPAN port configured, you will most likely start seeing NIDS alerts. If not, you can follow the troubleshooting steps here:
https://docs.securityonion.net/en/2.3/suricata.html#trou…