Spaceman_Splff

joined 1 year ago
[โ€“] [email protected] 1 points 11 months ago

You can run it on a docker container on your main pc. It will only be accessible when your pc is on of course, but look up docker for windows. You could also run a Linux vm in virtual box and have the docker container run on it.

[โ€“] [email protected] 1 points 11 months ago (1 children)

The whole stack start/stop is huge. It was my biggest issue. Looking forward to giving this a spin.

[โ€“] [email protected] 1 points 11 months ago

Securityonion is a great ids system. I used their distributed system, so I have 1 mini pc as a sensor and another as a manager/search. Works wonderful.

[โ€“] [email protected] 1 points 11 months ago

Graylog. Super easy to set up. Getting the grok and regex patterns sorted kind of sucks for getting fields to be pulled out unless you are good with that already.