Questions about Elastic Detection Rules and Sigma Correlation in Security Onion #15909
-
Version2.4.211 Installation MethodOther (please provide detail below) Descriptionother (please provide detail below) Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM128GB Storage for /1TB Storage for /nsm1TB Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHello, I am currently working on detection rules in Security Onion, using Elastic (Kibana) and experimenting with SSH-related detections (brute force, off-hours login, correlation, etc.). I have a few questions to better understand how detection engineering should be handled in Security Onion.
I created several detection rules directly in Kibana (Elastic Security), and I can see the generated alerts in:
However, these alerts do not appear in the Security Onion SOC interface. My questions:
I am also exploring Sigma rules, especially for use cases like:
My questions:
I looked into Sigma correlation rules (multi-event sequences), such as:
My questions:
One important question about workflow:
In other words:
I tried multiple approaches but I am unsure what is considered best practice in Security Onion. Summary:
Thank you in advance for your help. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
To answer your summary questions.
|
Beta Was this translation helpful? Give feedback.
To answer your summary questions.
.alerts-security.alerts-defaultwith a Data View that is.alerts-security.alerts-defaultand Detections will look inlogs-*You might be able to add the Data View heresoc > config > server > modules > elastic > index [adv]for SOC to search for records.