How To Ship Linux Intrusion Detection Logs To Security Onion Using The Wazuh Agent

Поділитися
Вставка
  • Опубліковано 3 січ 2025

КОМЕНТАРІ • 10

  • @ozzykampha2776
    @ozzykampha2776 Рік тому

    Can you do a test of Security onion 2.4?

  • @kunalhiremath7782
    @kunalhiremath7782 Рік тому +1

    At 7:43 on the alerts page under event.module why are we not seeing wazuh as the module name why we are seeing OSSEC.

  • @DenisGWahome
    @DenisGWahome 7 місяців тому

    What I am looking at is Shipping Logs in SysLog format from Wazuh Server to Security Onion and Corelate, otherwise configuring hundreds of agents in this way may not be practical for larger deployments.

  • @ryuzakifreak14
    @ryuzakifreak14 10 місяців тому

    Does anyone know if adding Wazuh is possible on Security Onion 2.4?

  • @rahulmishra0802
    @rahulmishra0802 2 роки тому

    Sir , I'm still unable to take logs of ubuntu on security onion.
    Please help

    • @bilaichacha8388
      @bilaichacha8388 2 роки тому

      Did you manage?

    • @mohammednasser2669
      @mohammednasser2669 Рік тому

      @@bilaichacha8388 my webserver is from amazon and it has public IP address. However, my security onion is local and doesn't have IP address. How can I connect webserver to SecurityOnion?

    • @Zyzienzergling
      @Zyzienzergling Рік тому

      ​@@mohammednasser2669you will likely have to tunnel into your local network or port forward those two wazuh ports on your router to target your security onion.
      You mentioned your security onion doesn't have an IP but that doesn't really make sense to me. So forward to the IP of the onion, which is your public IP or local IP for tunnel.

  • @ripits_62
    @ripits_62 Рік тому

    I love you