Help with Forward Node and SO-Elastic Agent Installation in Distributed Security Onion Setup #14081
Replies: 2 comments 2 replies
-
Answers below. Can I send Elastic Agent logs to the forward node? According to the documentation, Elastic Agent logs cannot be sent directly to a forward node. However, how can we configure it so that logs from one office can still be sent to Security Onion?
When I send logs to the forward node, will they automatically be forwarded to the manager/search node? Or is there an additional configuration needed?
Where are the logs saved in Security Onion? Can I change the log storage location to keep logs from different sources stored separately? If yes, how can I configure this? How can I connect my client devices to the forward node? My understanding is that if I use separate forward nodes, I can collect logs from different clients separately. Could you please guide me on how to achieve this connection? |
Beta Was this translation helpful? Give feedback.
-
How do forward nodes get logs? If I install a forward node in the client’s environment (same network), do I need to do any additional configurations? How can I change the log storage location when using two forward nodes separately? How can I collect logs separately from two clients in different locations? As you mentioned, if I send syslogs to forward nodes, what are the main drawbacks of this approach? |
Beta Was this translation helpful? Give feedback.
-
Hi everyone,
I am currently working with a distributed Security Onion setup, where I have a manager/search node (a combined manager and search node) hosted on a server. I can access the web view using the server's IP address through a VPN. My goal is to collect logs from a separate office, using a forward node to send them to Security Onion.
I have some questions regarding this setup:
Can I send Elastic Agent logs to the forward node? According to the documentation, Elastic Agent logs cannot be sent directly to a forward node. However, how can we configure it so that logs from one office can still be sent to Security Onion?
I have installed a forward node at the client end, which is successfully connected to the manager/search node.
Are there other methods to send logs from the client end to the forward node? Can we use an agent or any alternative method to achieve this while keeping logs separated for Security Onion?
Where are the logs saved in Security Onion?
Any guidance or suggestions on how to proceed with setting up and troubleshooting this process would be greatly appreciated.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions