This video walks through how to setup Netflow from OPNsense/PFsense to Security Onion
Пікірлер: 4
@HunterPredd1Ай бұрын
Do you see an advantage to having netflow as well as inline sensor data? If my sensor is picking up all traffic along a trunk between my main switch and firewall, it would essentially be getting all the information that i would be getting from netflow already, correct? Also, if i have a 2 node environment (1 sensor/Forward and 1 managersearch), Would netflows go to my Forward node? It has a larger harddrive for NPM data.
@georgewere1006 ай бұрын
Hello Garrett, I found your video to be incredibly informative. I have a quick question regarding the activation of Suricata and Zeek alerts; I'm having trouble figuring it out. Could you provide some guidance on how to enable these alerts? I appreciate your help.
@Xboarder5 ай бұрын
I don’t believe it’s possible to activate them on the Netflow data. If you do find a way I would be curious if you don’t mind sharing but I couldn’t find a way.