Sysmon, Winlogbeat, and Security Onion!

Поділитися
Вставка
  • Опубліковано 3 січ 2025

КОМЕНТАРІ •

  • @Zyzienzergling
    @Zyzienzergling 3 роки тому +1

    I'm not upset. Just angry you got to it first lol. I was putting a paper and video together for all 3 of these together. Gj

  • @callmebigpapa
    @callmebigpapa 10 місяців тому +1

    Great video

  • @dark_hyrax5007
    @dark_hyrax5007 3 роки тому +1

    Thanks so much! I have host visibility now.

  • @peterchain1686
    @peterchain1686 2 роки тому

    Thank you so much Mr. very detailed video

  • @virtual-riot
    @virtual-riot Рік тому

    a question, how i create custom alerts ????

    • @security-onion
      @security-onion  Рік тому

      If you have questions or problems, please start a new discussion at securityonion.net/discuss

  • @seckeymaker
    @seckeymaker 9 місяців тому

    Hello, is Winlogbeat in 2.4.50 ?

    • @security-onion
      @security-onion  9 місяців тому

      Winlogbeat has been replaced by Elastic Agent in 2.4.
      Documentation:
      docs.securityonion.net/en/2.4/elastic-agent.html#elastic-agent
      Video:
      ua-cam.com/video/cGmQMsFuAvw/v-deo.html
      If you have further questions or problems, please start a new discussion at securityonion.com/discuss

  • @rj-lk4iu
    @rj-lk4iu 2 роки тому

    Is the IP you specified in the winlogbeat to forward your data too the MGMT interface IP of the security onion? Security Onion is not picking up the logs being forwarded to it by winlogbeat for me.

    • @security-onion
      @security-onion  2 роки тому

      Yes, winlogbeat should send to the IP address of the management interface. Make sure that you have run so-allow to allow the traffic through the host-based firewall:
      docs.securityonion.net/en/2.3/so-allow.html
      If you have further questions or problems, please start a new discussion at:
      securityonion.net/discuss.
      Thanks!

    • @kallenosf
      @kallenosf 2 роки тому

      @@security-onion The IP address of the management interface on which Node in a distributed architecture? The Manager Node or a Search Node. I'm guessing not on a forward node because forward nodes do not have Logstash.

    • @security-onion
      @security-onion  2 роки тому

      If you have questions or problems, please start a new discussion at securityonion.net/discuss

  • @calmeidazim
    @calmeidazim 2 роки тому

    Do you have to open the windows firewall? not getting the logs on the sec onion machine :( did everything like the video

    • @security-onion
      @security-onion  2 роки тому +1

      If you have questions or problems, please start a new discussion at securityonion.net/discuss

  • @otvs5838
    @otvs5838 Рік тому

    You should have maximized your sysmon installation screen. Anyway it's Good One !!