The whole stack start/stop is huge. It was my biggest issue. Looking forward to giving this a spin.
Spaceman_Splff
joined 1 year ago
Securityonion is a great ids system. I used their distributed system, so I have 1 mini pc as a sensor and another as a manager/search. Works wonderful.
Graylog. Super easy to set up. Getting the grok and regex patterns sorted kind of sucks for getting fields to be pulled out unless you are good with that already.
You can run it on a docker container on your main pc. It will only be accessible when your pc is on of course, but look up docker for windows. You could also run a Linux vm in virtual box and have the docker container run on it.