This document applies to Classic/Legacy Integrations. You may continue to use these integration configurations. While no active development is happening for these integrations, we continue to provide Classic/Legacy Integrations in the product. You do not have to move to MSI Integrations. If your support engineer or TSC recommends or you choose to move to MSI Integrations, you can take advantage of the latest features and functionality. For more information, see the MSI Integration documentation in the Integrations Overview.
Update Security Onion - ELSA
to update Security Onion - ELSA
- Create a username.
- If using API authentication, identify the token to be used.
Update the Validation Platform
Prerequisites
Information to gather before you start:
- Host and port used for Security Onion - ELSA (defaults are auto-populated).
- Identify whether the protocol is HTTP or HTTPS for connections.
- Identify or create the credentials to access Security Onion.
Configuration
To add the Security Onion - ELSA integration
Go to Settings > Integrations.
- Click Add Integration > Security Onion - ELSA.
- If necessary, change the Host and Port.
- Choose the Protocol and Credential type.
- Enter the credentials. Expand Advanced options.

Security Onion ELSA Integration
- (Optional) Update Query time and Delay time.
(Optional) Select Enable query for Malicious DNS Actions and configure the Query. This query will only be used when you run Malicious DNS Actions or Captive DNS Actions.
(Optional) Select Discover network devices automatically.
Modify the Query Interval and Event Time Adjustment, if necessary.
(Optional) Assign a Name.
(Optional) Choose Yes to save suspicious events.
Click Submit.
Verify connectivity
To verify connectivity to Security Onion - ELSA
Click Test to verify that:
- The Director can communicate with Security Onion - ELSA with the host, port, and credentials provided.
Run a Malicious or Captive DNS Action and then review the last run query to verify:
- The custom DNS query works as expected (if configured).