All Apps and Add-ons

Security Onion App for Splunk software: How to get data from a Security Onion stand alone server into a stand alone Splunk server?

dt2525
New Member

Greetings,

I have set up a stand alone Security Onion server and stand alone Splunk server. I have followed the instructions on setting up the Security Onion App on Splunk. I have set up Security Onion to send events via SYSLOG to the Splunk server. I see the data coming in, but the Security Onion app is not parsing and not seeing the data via the dashboards.

What am I missing in the setup?

Can I do this using separate servers, or do they both have to be installed on the same box?

Do I use the standard SYSLOG data source, or do I need to use something like SNORT or other for the context of the data source?

Thanks....

0 Karma

ozirus
Path Finder
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.