Logo
2.4

Table of Contents

  • About
  • Introduction
  • License
  • First Time Users
  • Getting Started
  • Security Onion Console (SOC)
  • Security Onion Desktop
  • Network Visibility
  • Host Visibility
  • Logs
    • Ingest
    • Logstash
    • Redis
    • Elasticsearch
    • ElastAlert
    • Curator
    • Data Fields
    • Alert Data Fields
    • Elastalert Fields
    • Zeek Fields
    • Community ID
    • SOC Logs
    • Other Supported Logs
    • Related Information
  • Updating
  • Accounts
  • Services
  • Customizing for Your Environment
  • Tuning
  • Tricks and Tips
  • Utilities
  • Help
  • Security
  • Release Notes
  • Appendix
  • Cheat Sheet
Security Onion
  • Docs »
  • Logs
  • Edit on GitHub

Logs¶

Once logs are generated by network sniffing processes or endpoints, where do they go? How are they parsed? How are they stored? That’s what we’ll discuss in this section.

  • Ingest
    • Import
    • Eval
    • Standalone
    • Fleet Standalone
    • Manager (separate search nodes)
    • Manager Search
    • Heavy
    • Search
    • Forward
  • Logstash
    • Configuration
    • Parsing
    • Forwarding Events to an External Destination
    • Original Event Forwarding
    • Modified Event Forwarding
    • Queue
    • Diagnostic Logging
    • Errors
    • More Information
  • Redis
    • Queue
    • Tuning
    • Diagnostic Logging
    • More Information
  • Elasticsearch
    • Data
    • Querying
    • Authentication
    • Diagnostic Logging
    • Storage
    • Parsing
    • Templates
    • Community ID
    • Configuration
    • Closing Indices
    • Deleting Indices
    • Distributed Deployments
    • Re-indexing
    • Clearing
    • GeoIP
    • More Information
  • ElastAlert
    • Configuration
    • ElastAlert Rules
    • Diagnostic Logging
    • More Information
  • Curator
    • Configuration
    • Diagnostic Logging
    • More Information
  • Data Fields
    • ECS
    • Fields
    • Template files
  • Alert Data Fields
  • Elastalert Fields
  • Zeek Fields
  • Community ID
    • More Information
  • SOC Logs
    • SOC Auth Logs
  • Other Supported Logs
    • Example: pfSense
    • Example: RITA
  • Related Information
    • RITA
    • Endgame
Next Previous

© Copyright 2023 Revision 525fc0c7.

Built with Sphinx using a theme provided by Read the Docs.
Read the Docs v: 2.4
Versions
latest
Downloads
pdf
htmlzip
epub
On Read the Docs
Project Home
Builds

Free document hosting provided by Read the Docs.