You can try it, but we do not recommend or support it. If you have further questions or problems, please start a new discussion at securityonion.net/discuss
@and_still.Ай бұрын
Can you help me? I am not seeing any alert nor any data in any tools like kibana , etc... Iam trying to find out for more than 1 week.
@security-onionАй бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss and provide detailed information.
@waseemalkurdi759Ай бұрын
Thank you, It's very useful video.
@security-onionАй бұрын
Thanks, glad you like it!
@swaterstsiafadray3292 ай бұрын
Hi! how to do this with a Eval mode? Thank you!
@security-onion2 ай бұрын
It should work the same for Eval mode. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!
@Dyosef953 ай бұрын
i try to install the nachine as shown in the video , in the end of the installation there is no way to access the web interface , i got the directory of the security onion on the machine but dont know what to do
@security-onion3 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@Sa-bk8cl23 сағат бұрын
I'm facing the same problem. Were you able to solve this problem?
@hariomojha27293 ай бұрын
Hello sir , I am stuck at : 0curl: (6) Could not resolve host:sigs.securityonion.net , So can you please help me with this issue
@AngeliteEntyshak3 ай бұрын
I am extremely excited to get my home lab set up. Thanks for the concise series, dude!
@security-onion3 ай бұрын
Happy hunting!
@Bike13373 ай бұрын
Excellent work
@TheSoliver844 ай бұрын
Hello, now I ask again: in the evaluation version, are the results under Alert real or placeholders?
@security-onion3 ай бұрын
The alerts are real. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@TheSoliver844 ай бұрын
Are there real alarms in the evaluation or are the placeholders not real?
@security-onion3 ай бұрын
The alerts are real. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@TheSoliver843 ай бұрын
@@security-onion OK, how do I find the corresponding computers or devices? Only IP addresses are displayed but no MAC addresses.
@security-onion3 ай бұрын
You may be able to find MAC addresses by pivoting to PCAP and then opening that PCAP in Wireshark or some other PCAP utility. However, depending on how you're monitoring traffic, the MAC addresses shown may not actually be the MAC addresses of the actual endpoints. For this reason, most folks focus on IP addresses rather than MAC addresses. Depending on your network, you may be able to correlate an IP address to an actual device via DNS, DHCP, or other means. If you have further questions or problems, plese start a new discussion at securityonion.com/discuss rather than replying here on KZbin. Thanks!
@ibejoe77194 ай бұрын
My adversaries will grid their teeth after weeping....there's a need for a cert of completion to proof the understanding on how to peel the onion
@security-onion3 ай бұрын
Thanks for watching Security Onion Essentials 2.3. Please keep in mind that Security Onion 2.3 has reached End Of Life and so we recommend watching Security Onion Essentials 2.4 for the latest and greatest. Regarding certificate of completion, we do offer that for our paid training classes at securityonion.com/training. We also offer the SOCP (Security Onion Certified Professional) at securityonion.com/certification.
@ibejoe77194 ай бұрын
Good stuff....thanks for sharing
@security-onion4 ай бұрын
Thanks for watching!
@L3af05534 ай бұрын
I have watched the install videos and you installed the eval version, i plan on installing the desktop version and am wondering if i will still need to use the web interface to monitor traffic
@security-onion4 ай бұрын
You will need some kind of web browser whether its inside the Security Onion Desktop or on some other machine. If you have further questions or problems, please start a new discussion at securityonion.net/discuss. Thanks!
@AbuFaizal4 ай бұрын
thanks for video
@security-onion4 ай бұрын
You're welcome!
@callmebigpapa4 ай бұрын
Thank you so much this is great. You are a gifted teacher.
@security-onion4 ай бұрын
Thanks for your kind words!
@WatsonInfosec4 ай бұрын
Thanks
@security-onion4 ай бұрын
You're welcome!
@fatushcorner4 ай бұрын
Thank u ☺️
@security-onion4 ай бұрын
You're welcome!
@edvloesungen5 ай бұрын
Thank you very much!
@security-onion5 ай бұрын
You're welcome!
@andreantunes73106 ай бұрын
miss the suricata and logs of apps of pfsense, but great work, keep doing more, and integrations with flux
@fuzzyEuclid6 ай бұрын
An osquery video would be awesome :)
@CageYim6 ай бұрын
I saw "Evaluation installs and Import installs do not support remote elastic agents. The links below are shown for demonstration purposes only." after I installed the eval version security onion following your installation guide video, is that means I have to install to other mode? Thank you.
@security-onion6 ай бұрын
If you want to deploy the Elastic Agent to remote devices, then you will need to install in STANDALONE mode or do a full distributed deployment. For more information, please see the documentation at docs.securityonion.net/en/2.4/architecture.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!
@CageYim6 ай бұрын
@@security-onion Thank you very much. Let me try again.
@flyingbyalexeiroudnev97506 ай бұрын
I do not see a way to change severity by one click, or to suppress alert temporarily, or to automatically get IP etc from alert. So it looks as a good step but it is ONLY a FIRST STEP. For example,. we reclassify events in Zabbix all the time, we set up timed reclassifications often, we may need to update a GROUP of Detection rules at once. Idea is great but it looks as very first implementation yet. (Of course I can clone the rule, then change severity in the cloned rule and disable original rule. but why to do it so complicated? or we want to suppress all alerts 'traffic with ... group' whch we do by re: expression today - it's not implemented yet (looks this way) and there are 50+ IP groups and about 10 alerts per group... so what disable can do by single re: rule, detection will require 100 updates (looks like this).
@security-onion6 ай бұрын
Yes, we have lots of improvements coming. If you have further comments or questions, please start a new discussion at securityonion.com/discuss.
@GarethLedger-pz6wl6 ай бұрын
Any chance you paste the various command line inputs
@capitalreg3187 ай бұрын
Oh this will be very useful. Cool feature indeed, thank you!! Two things: 1. Any possibility of adding an optional Elastic Defend/Predefined Rules integration to that Detections menu? Currently it is buried in Kibana and requires some additional digging to add the Predefined Rule integration, then unhide the Security tab Kibana Spaces? 2. Any chance of upgrading the OSquery Manager to the Velociraptor platform to integrate that amazing tool's DFIR capabilities with the SOC/Elastic Agent?
@security-onion7 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss
@zapphoddbubbahbrox56817 ай бұрын
somehow SYSMON integration not working or showing up as an integration for a windows box. i'd added SYSMON to the node after the agent was enrolled. does this require removal (big pains here also, it won't properly remove)? Would be great to have a guide for this. Also for Linux SYSMON
@security-onion7 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@Rabah_RAHLI7 ай бұрын
can this functionality work with pfsense comunity edition ?
@security-onion7 ай бұрын
Yes! If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@johnmosqueda10297 ай бұрын
Is there an in place upgrade option available?
@security-onion7 ай бұрын
There will be an in-place upgrade option once 2.4.70 is released. If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@juanmartinmerlo36827 ай бұрын
I can't wait to upgrade! Is there an estimated release date? Great job team!
@security-onion7 ай бұрын
2.4.70 is scheduled to release in the next few weeks. Stay tuned! If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@michaelporter82427 ай бұрын
Wow, this is a great improvement for tuning. Can't wait to give it a try!
@security-onion7 ай бұрын
Thanks, glad you like it!
@izid00d7 ай бұрын
awesome, just as i imagined it in my head! i will look forward to the update, sheesh this will shorten the tuning process by a lot. Thanks to the SO Team!!!
@security-onion7 ай бұрын
Thanks, glad you like it!
@TheLakeBodom7 ай бұрын
Wow, nice works Security Onion Team!! This will be a much better work flow
@security-onion7 ай бұрын
Thanks, glad you like it!
@cyberlabz7 ай бұрын
I've watched the new video at least four times. Super excited about the Detections module release. Great job!!!!
@security-onion7 ай бұрын
Thanks, glad you like it!
@frzen7 ай бұрын
Huge quality of life upgrade thank you I'm really looking forward to updating
@security-onion7 ай бұрын
Thanks, glad you like it!
@Roman-m3u4h7 ай бұрын
Is it possible to revert changes through history? Is there a rule validator in the Signarutre field? Will the syntax color highlighting appear?
@security-onion7 ай бұрын
If you have questions, please start a new discussion at securityonion.com/discuss
@yannickzelt92467 ай бұрын
This really is a great new feature. Can't wait to try it out.
@security-onion7 ай бұрын
Thanks, glad you like it!
@ankuryogi32987 ай бұрын
Love it
@security-onion7 ай бұрын
Thanks!
@jmcgee818 ай бұрын
Excellent keynote!
@security-onion7 ай бұрын
Thanks for watching!
@giovannisvette4499 ай бұрын
Does this still work?
@security-onion9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@sevadamuradyan54869 ай бұрын
our network firewall log is coming to my computer how can i send sec-onion?
@security-onion9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.net/discuss
@kinghenryjames13279 ай бұрын
Awesome, great material great teacher.
@security-onion9 ай бұрын
Thanks, glad you liked it!
@olivertatzmann30389 ай бұрын
Thank you - Great tutorial. Unfortunately I failed to get it working neiger with pfSense nor with fortigate. tcpdump shows the incoming packages, but they are not parsed. Do you have any hint how to start toubleshooting?
@security-onion9 ай бұрын
If you have questions or problems, please start a new discussion at securityonion.com/discuss
@seckeymaker9 ай бұрын
Hello, is Winlogbeat in 2.4.50 ?
@security-onion9 ай бұрын
Winlogbeat has been replaced by Elastic Agent in 2.4. Documentation: docs.securityonion.net/en/2.4/elastic-agent.html#elastic-agent Video: kzbin.info/www/bejne/mXjQgoCpe9p0rNk If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@JamesHazell-b2p9 ай бұрын
Great information. Is there a video to port Cisco switch log files to SO ?
@security-onion9 ай бұрын
Please see the Cisco IOS integration at docs.elastic.co/integrations/cisco_ios and our docs at docs.securityonion.net/en/2.4/elastic-fleet.html#elastic-fleet and docs.securityonion.net/en/2.4/elastic-agent.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss
@Angry.Hippie9 ай бұрын
This video series has been a great help in getting me hands on experience for the CySA+ cert. Wouldn't of been able to install an agent on my computer without it!
@security-onion9 ай бұрын
Thanks, glad to help!
@subhuman74789 ай бұрын
I would also love to see an osquery video. A strelka one would be great too.
@WatsonInfosec10 ай бұрын
Thanks
@security-onion9 ай бұрын
You're welcome!
@taraskobilskiy653810 ай бұрын
Thank you for the video
@security-onion9 ай бұрын
You're welcome!
@GINACOMMISSO10 ай бұрын
Does the IP of the virtual machine (to access the SOC) has to be the same as that of the host computer?
@security-onion9 ай бұрын
No, the VM and the host computer should have different IP addresses. If you have further questions or problems, please start a new discussion at securityonion.com/discuss