Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

Use Cases

Doug Burks edited this page Mar 3, 2017 · 10 revisions

Security Onion is designed for many different use cases! Here are just a few examples.

Classroom

Install Security Onion. Run Setup and configure network interfaces. Reboot, run Setup, and then choose Evaluation Mode.

Production Server - Standalone

Install Security Onion. Run Setup and configure network interfaces. Reboot, run Setup, choose Production Mode, and then choose Standalone.

Production Server - Distributed Deployment

Install Security Onion on the master server box. Run Setup and configure network interfaces. Reboot, run Setup, choose Production Mode, and then choose Master. Install Security Onion on one or more sensor boxes and then on each one: run Setup, configure network interfaces, reboot, run Setup choose Production Mode, and then choose Sensor.

Analyst VM

Install Security Onion in a VM on your local desktop or laptop. Do NOT run Setup. Launch the Sguil client and connect to sguild on your Production Master Server. Launch the web browser and connect to Squert or ELSA on your Production Master Server.

Sensor sending logs to SIEM

Sending logs to SIEM

Clone this wiki locally