All Apps and Add-ons

Security Onion App for Splunk software: How to get data from a Security Onion stand alone server into a stand alone Splunk server?

dt2525
New Member

Greetings,

I have set up a stand alone Security Onion server and stand alone Splunk server. I have followed the instructions on setting up the Security Onion App on Splunk. I have set up Security Onion to send events via SYSLOG to the Splunk server. I see the data coming in, but the Security Onion app is not parsing and not seeing the data via the dashboards.

What am I missing in the setup?

Can I do this using separate servers, or do they both have to be installed on the same box?

Do I use the standard SYSLOG data source, or do I need to use something like SNORT or other for the context of the data source?

Thanks....

0 Karma

ozirus
Path Finder
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...