Understanding log ingestion, parsing, and custom XML pipeline workflow in Security Onion #15935
-
Version2.4.211 Installation MethodOther (please provide detail below) Descriptionother (please provide detail below) Installation TypeStandalone Locationother (please provide detail below) Hardware SpecsExceeds minimum requirements CPU16 RAM128GB Storage for /1TB Storage for /nsm1TB Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsYes, there are additional clues in /opt/so/log/ (please provide detail below) DetailHello, For example:
I tried exploring:
But I still do not clearly understand the recommended workflow.
typically configured in Security Onion ?
I think part of my confusion comes from not understanding which layer is responsible for:
I would really appreciate any guidance on the recommended architecture/workflow before I go further. Thank you very much. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
|
https://docs.securityonion.net/en/3/main/ingest/ shows the ingest pipeline for logs based on deployment. That is a good starting point to understand how the logs are processed and indexed. |
Beta Was this translation helpful? Give feedback.
https://docs.securityonion.net/en/3/main/ingest/ shows the ingest pipeline for logs based on deployment. That is a good starting point to understand how the logs are processed and indexed.