I have set up a stand alone Security Onion server and stand alone Splunk server. I have followed the instructions on setting up the Security Onion App on Splunk. I have set up Security Onion to send events via SYSLOG to the Splunk server. I see the data coming in, but the Security Onion app is not parsing and not seeing the data via the dashboards.
What am I missing in the setup?
Can I do this using separate servers, or do they both have to be installed on the same box?
Do I use the standard SYSLOG data source, or do I need to use something like SNORT or other for the context of the data source?