Skip to content

Advice for Forwarding Logs to Security Onion #13643

Answered by reyesj2
MACKG17 asked this question in 2.4
Discussion options

You must be logged in to vote

Depending on how many devices will be sending syslog data an option might be setting up a receiver node to specifically handle ingesting the syslog data. https://docs.securityonion.net/en/2.4/architecture.html#receiver-node

For ingesting syslog you will need to open the firewall for the node intended to receive the syslog data (receiver node if you set one up as mentioned above) https://docs.securityonion.net/en/2.4/syslog.html

For differentiating log sources data sent from syslog should include a hostname field showing device that is sending the logs.

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
5 replies
@MACKG17
Comment options

@reyesj2
Comment options

@MACKG17
Comment options

@MACKG17
Comment options

@reyesj2
Comment options

Answer selected by MACKG17
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants