Skip to content

Wazuh, Suricata integration #9143

Locked Answered by dougburks
OlexTratisky asked this question in Q&A
Discussion options

You must be logged in to vote

Our Alerts, Dashboards, and Hunt interfaces have a Correlate option on the Actions menu that allows you to find related logs based on Community ID, uid, fuid, etc.:
https://docs.securityonion.net/en/2.3/alerts.html#actions
https://docs.securityonion.net/en/2.3/dashboards.html#actions
https://docs.securityonion.net/en/2.3/community-id.html

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by OlexTratisky
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants