SO vs Suricata & Zeek #9264
Replies: 1 comment 2 replies
-
Using our Security Onion distributed architecture allows you to take advantage of our centralized management so that you can do everything from one manager rather than having to individually manage a bunch of different sensors. You might also consider a best-of-both-worlds approach by building a full Security Onion deployment including the Elastic stack (so that you can take full advantage of our Alerts interface, dashboards, threat hunting, pcap and other capabilities) and then configuring cross cluster search so that you can query both Elastic deployments from one location. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm wondering what the benefit would be to installing a SO distributed architecture (manager and some forward nodes as sensors) as opposed to installing Suricata and Zeek on systems to act as sensors. We already have an Elastic cluster used by ~250 elastic agents to forward log data to. If I installed SO, I wouldn't need the ELK portion so what benefit would I gain by installing SO instead of just Suricata and Zeek and then using elastic agent integrations to foward the Suircata and Zeek data to our existing ES cluster? TIA
Beta Was this translation helpful? Give feedback.
All reactions