Understanding Log Storage and Alerts in Security Onion Distributed Setup #14248
Replies: 1 comment 7 replies
-
Logs are stored on search nodes:
Yes, take a look at the ILM documentation:
If you have a forward node that is consuming network traffic from a tap or span port, then you can go through the Troubleshooting Alerts section of the documentation:
Go to SOC Dashboards, click the query dropdown, select the Elastic Agent Overview dashboard, and check to see if you have logs from your PC's Elastic Agent. For more information, please see: |
Beta Was this translation helpful? Give feedback.
-
Hi everyone,
I have set up a distributed Security Onion deployment with search, forward, receiver, and manager nodes, all connected to the manager node. I have a few questions regarding how logs are handled in this architecture.
3.Elastic Agent Logs Visibility:
I would appreciate any guidance on these issues. Thanks in advance!
Beta Was this translation helpful? Give feedback.
All reactions