Security Engineer making his way through the world.
Learning and working.

Security Engineer making his way through the world.
Learning and working.
So I've had a poke around Security onion, and obviously, I'm setting this all up from scratch with ZERO existing knowledge of how to do any of this.
I'm a little lost if I'm honest, I know I can ingest device alerts through the Wazuh Agent. but I want to ingest data from existing services.. ESET for a start.
I think i can do this through SYSLOG but that requires knowledge of ElasticSearch it seems, is anyone any good with ElasticSearch and can give me a rundown?
Took me two hours to work out why it wouldn't lold the WebUI. But finally..
I'm In.
Also, I've set up a monthly subscription to donate to @jerry to support the infosec instance.
I'm a strong believer in "Pay for the product, don't be the product".
Lets keeps this train going :)