Comment on Internal network monitoring

<- View Parent
irmadlad@lemmy.world ⁨4⁩ ⁨days⁩ ago

but suricata will not automatically correlate primitives into actual alerts from different vlans without transforms, which are cpu-intensive for what they do.

It is possible to offload the correlation to a downstream SIEM or log aggregator like Wazuh or ELK. Again, it’s something I’m currently trying to spool up on. I know it can be done, I’m just trying different things until I do get it right. I appreciate any input.

source
Sort:hotnewtop