Security Onion Documentation
Welcome to the Security Onion Documentation!
Security Onion is a free and open source Linux distribution for intrusion detection, enterprise security monitoring, and log management. It includes Elasticsearch, Logstash, Kibana, Snort, Suricata, Bro, Wazuh, Sguil, Squert, CyberChef, NetworkMiner, and many other security tools. The easy-to-use Setup wizard allows you to build an army of distributed sensors for your enterprise in minutes!
For more information about Security Onion not contained in this Documentation, please see our main site:
Table of Contents
- About This Documentation
- Introduction
- Use Cases
- Hardware Requirements
- Download/Install
- ISO Release Notes
- Quick Evaluation using Security Onion ISO image
- Quick Evaluation on Ubuntu
- Production Deployment
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthough
- Videos
- Architecture
- Cheat Sheet
- Conference
Update/Upgrade
Network Visibility
Elastic Stack
Customizing for your network
- Network Configuration
- Proxy Configuration
- Firewall
- Email Configuration
- so-email
- Sguil client
- Overview
- How do I configure the OS itself to send emails?
- How do I configure Sguil to send alerts via email?
- How do I configure Wazuh to send emails?
- How do I configure Bro to send emails?
- How do I configure Elastalert to send emails?
- How can I get an email alert when my sensor stops seeing traffic?
- Changing IP Addresses
- NTP
Tuning
- Managing Alerts
- Testing to make sure the IDS is working
- Identifying overly active signatures
- From Squert
- From Sguil
- From the Command Line
- Listing the top twenty signatures
- Identifying rule categories
- Recovering from too many alerts
- So what’s next?
- Disable the sid
- Disable the category
- modifysid.conf
- Rewrite the signature
- Threshold
- Suppressions
- Autocategorize events
- Why is pulledpork ignoring disabled rules in downloaded.rules
- Sguil Days To Keep
- Managing Rules
- Adding Local Rules
- Disabling Processes
- BPF
- PF_RING
- AF-PACKET
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs
Tricks and Tips
- Airgapped Networks
- Analyst VM
- Automating Setup
- Best Practices
- Cloud Client
- Connecting to Sguild
- Disabling Desktop
- DNS Anomaly Detection
- ICMP Anomaly Detection
- Metapackages
- PCAPs for Testing
- Removing a Sensor
- Salt
- What is OnionSalt?
- Best Practices
- Salt and OnionSalt are optional packages
- Firewall Requirements
- Installation
- Checking Status
- Remote Execution
- Features
- Using Salt to Install Updates Across Your Entire Deployment
- Modifying Salt config files
- Changing Minion ID
- Salting an Existing Deployment
- Configure the Master Server first
- Now configure salt-minion on a Sensor
- Now return to the Master and accept the new minion
- Maximum Event Size
- Additional Reading
- Sensor Stops Seeing Traffic
- SSH
Integrations
Other