Skip to content

Newbie help? #12960

Answered by reyesj2
Prometheus8282 asked this question in 2.4
May 7, 2024 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

For the proxmox you likely need some additional configuration of the bridge or pass-thru network interface https://docs.securityonion.net/en/2.4/proxmox.html#nic
While you're testing to see if the traffic is reaching your bond0 interface you can run tcpdump -i bond0 that will show you what traffic is getting to the bond0 (monitor) interface for Security Onion.

With the cisco device you can setup the integration and use the existing elastic agent on your standalone deployment and add your integration https://docs.securityonion.net/en/2.4/elastic-fleet.html#adding-an-integration

You can also setup your cisco device to send logs over syslog and point it at your Security Onion box. https://do…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@Prometheus8282
Comment options

Answer selected by Prometheus8282
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants