This document applies to Classic/Legacy Integrations. You may continue to use these integration configurations. While no active development is happening for these integrations, we continue to provide Classic/Legacy Integrations in the product. You do not have to move to MSI Integrations. If your support engineer or TSC recommends or you choose to move to MSI Integrations, you can take advantage of the latest features and functionality. For more information, see the MSI Integration documentation in the Integrations Overview.
Update Security Onion - ELK
Do the following to allow access to the API port via Security Onion's built-in Firewall.
To allow access to the API port
- Run the
so-allowcommand. - Choose option e.
- Enter the
director's ip address.
Update the Validation Platform
Prerequisites
Information to gather before you start:
- Host and port used for Security Onion - ELK.
- Identify whether the protocol is HTTP or HTTPS for connections .
- Identify or create the credentials to access Security Onion.
Configuration
To add the Security Onion - ELK integration
Go to Settings > Integrations.
Click Add Integration > Security Onion - ELK.
Enter information for the Host, Port, Username, and Password.
Expand Advanced options.
Review the field name mappings and update as necessary. Default mappings exist for Snort and Bro.
You can use standard UNIX wildcards in the Index name, allowing you to match several index files (for example,
snort-*matchessnort-123andsnort-abc).- Inputs are enclosed by square brackets
[]. - Inputs point to the path location (
["_id"]). - Nested locations should be enclosed in one set of brackets, encompassed in quotes, and separated by commas (
["_source","src_ip"]).
- Add a new Index and configure those fields, if necessary.
Modify the Query Interval and Event Time Adjustment, if necessary.
(Optional) Select Discover network devices automatically.
(Optional) Assign a Name.
(Optional) Choose Yes to save suspicious events.
Click Submit.
Verify connectivity
To verify connectivity to Security Onion - ELK
Click Test to verify that:
- The Director can communicate with Security Onion - ELK with the host, port, and credentials provided.