background
tools & workflows
1 sources
So you need a SIEM or IDS? Check out Security Onion.
What happened
TL;DR if I spent some time writing up and documenting how to configure Security Onion as an IDS and SIEM logging solution, would the community be interested? Hey y'all. I'm that guy who loved Graylog for a long time, and while Graylog is great for general alerting, it is not ready for prime time as a SIEM, and it has no ability to do intrusion detection. Over the weekend in my homelab, I started trying out SecurityOnion, and I have to say I'm quite impressed. Here is a quick overview of some of
Business impact
Reported by r/sysadmin. Monitor for further developments.
Sources
Related stories