Greetings,
I have set up a stand alone Security Onion server and stand alone Splunk server. I have followed the instructions on setting up the Security Onion App on Splunk. I have set up Security Onion to send events via SYSLOG to the Splunk server. I see the data coming in, but the Security Onion app is not parsing and not seeing the data via the dashboards.
What am I missing in the setup?
Can I do this using separate servers, or do they both have to be installed on the same box?
Do I use the standard SYSLOG data source, or do I need to use something like SNORT or other for the context of the data source?
Thanks....
You can go with splunk forwarder.
https://www.furkancaliskan.com/dagitik-securityonion-loglarini-splunka-dusurmek/