Replies: 1 comment
-
Why two separate ELK? You can enable ELK SIEM feature into ELK stack of Security Onion, The only problem is you won't be able to use ELK SIEM prebuilt rules as they works on ECS compliant default indexes and SO do not have those indexes. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Greetings,
I have an ELK SIEM and Security Onion 2 on my home lab.
Since Security Onion is using Elasticsearch, I would like to combine these two and just use Security Onion as a SIEM as well.
I'm new to Security Onion.
I would like to know if I can use the packet beat and point it to Security Onion's Elasticsearch.
Or my approach is wrong? Use ELK SIEM as the main Elasticsearch and point the Security Onion to it?
Beta Was this translation helpful? Give feedback.
All reactions