Security Onion as NDR only #9863
Replies: 1 comment 5 replies
-
Question, if you're using NDR to mean Network Detection and Response ... if you're not ingesting network traffic there will not be anything to detect and respond to. Right? On re-reading this comment I just wanted to say, this is a legit question. I'm not trying to be rude. My apologies if that did not come across correctly. |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello community, I was wondering if anyone use SO only for monitoring network traffic? I would like to know what kind of setup (probably standalone) would be needed to have SO and then Zeek/Suricata alerts/logs from end devices only (PC/laptops), sending to SO.
Would it be possible to use SO as NDR only, without TAP/port mirroring?
Cheers!
Beta Was this translation helpful? Give feedback.
All reactions