How to get syslog logs into securityonion 2.3? #2349
-
I have a single manager with four sensors and two search nodes, after running so-allow, which host am I supposed to send traffic to? I ran across this thread, but it doesn't answer my question directly, good start for syslog setup though: This link suggests they get sent to the individual sensor: |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
You can send syslog to any node (since every node type runs Filebeat, which is the syslog receiver). You just need to make sure the firewall allows the connection. |
Beta Was this translation helpful? Give feedback.
You can send syslog to any node (since every node type runs Filebeat, which is the syslog receiver). You just need to make sure the firewall allows the connection.