Collecting Endpoint Logs with Elastic Agent

Поділитися
Вставка
  • Опубліковано 31 гру 2024

КОМЕНТАРІ • 24

  • @Angry.Hippie
    @Angry.Hippie 9 місяців тому +1

    This video series has been a great help in getting me hands on experience for the CySA+ cert. Wouldn't of been able to install an agent on my computer without it!

  • @fuzzyEuclid
    @fuzzyEuclid 10 місяців тому +1

    Thank you for the quick look! I'd love to see a basic osquery video :)

  • @subhuman7478
    @subhuman7478 10 місяців тому +2

    I would also love to see an osquery video. A strelka one would be great too.

  • @waseemalkurdi759
    @waseemalkurdi759 Місяць тому

    Thank you, It's very useful video.

  • @CageYim
    @CageYim 6 місяців тому

    I saw "Evaluation installs and Import installs do not support remote elastic agents. The links below are shown for demonstration purposes only." after I installed the eval version security onion following your installation guide video, is that means I have to install to other mode? Thank you.

    • @security-onion
      @security-onion  6 місяців тому +1

      If you want to deploy the Elastic Agent to remote devices, then you will need to install in STANDALONE mode or do a full distributed deployment. For more information, please see the documentation at docs.securityonion.net/en/2.4/architecture.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss. Thanks!

    • @CageYim
      @CageYim 6 місяців тому

      @@security-onion Thank you very much. Let me try again.

  • @JamesHazell-b2p
    @JamesHazell-b2p 9 місяців тому

    Great information. Is there a video to port Cisco switch log files to SO ?

    • @security-onion
      @security-onion  9 місяців тому

      Please see the Cisco IOS integration at docs.elastic.co/integrations/cisco_ios and our docs at docs.securityonion.net/en/2.4/elastic-fleet.html#elastic-fleet and docs.securityonion.net/en/2.4/elastic-agent.html. If you have further questions or problems, please start a new discussion at securityonion.com/discuss

  • @zapphoddbubbahbrox5681
    @zapphoddbubbahbrox5681 7 місяців тому

    somehow SYSMON integration not working or showing up as an integration for a windows box. i'd added SYSMON to the node after the agent was enrolled. does this require removal (big pains here also, it won't properly remove)? Would be great to have a guide for this. Also for Linux SYSMON

    • @security-onion
      @security-onion  7 місяців тому

      If you have questions or problems, please start a new discussion at securityonion.com/discuss

  • @fuzzyEuclid
    @fuzzyEuclid 6 місяців тому

    An osquery video would be awesome :)

  • @taraskobilskiy6538
    @taraskobilskiy6538 10 місяців тому

    Thank you for the video

  • @sevadamuradyan5486
    @sevadamuradyan5486 9 місяців тому

    our network firewall log is coming to my computer how can i send sec-onion?

    • @security-onion
      @security-onion  9 місяців тому

      If you have questions or problems, please start a new discussion at securityonion.net/discuss

  • @calmeidazim
    @calmeidazim 10 місяців тому +1

    Thank you, just in the time :)

  • @edvloesungen
    @edvloesungen 6 місяців тому

    Thank you very much!

  • @WatsonInfosec
    @WatsonInfosec 10 місяців тому

    Thanks