Peel back the layers of your network and make your adversaries cry!
Free platform for threat hunting, enterprise security monitoring, and log management.
Questions: http://securityonion.net/discuss
Peel back the layers of your network and make your adversaries cry!
Free platform for threat hunting, enterprise security monitoring, and log management.
Questions: http://securityonion.net/discuss
Security Onion 3.1.0 Hotfix 20260528 Now Available!
We've released a hotfix to Security Onion 3.1.0 to address issues for deployments with Heavy Nodes or custom Logstash pipelines - please check out this blog post for more information.
https://blog.securityonion.net/2026/05/security-onion-310-hotfix-20260528-now.html
Our printed documentation book has been updated for Security Onion 3.1 and is available from Amazon now!
For those who don't know, we offer a softcover copy of our documentation for the current version of Security Onion via Amazon. All proceeds go to the Rural Technology Fund, and the book comes with a 20% off discount code for our on-demand training and the Security Onion Certified Professsional (SOCP) certification exam.
https://blog.securityonion.net/2026/05/security-onion-documentation-printed.html
IT'S TIME FOR SOUP!
Security Onion 3.1.0 is now available and includes new features, updated components, and many quality-of-life improvements!
Get all the details on our blog:
https://blog.securityonion.net/2026/05/security-onion-310-now-available-with.html
DID YOU KNOW?
Starting in version 2.4.170, Security Onion Pro users have access to a new type of Security Onion node, the Hypervisor Node. The Hypervisor node uses Linux-native virtualization libraries to run multiple independent SO nodes on a single piece of hardware -- if you have a powerful server that's being underutilized, this allows you to spin up additional nodes on it from inside the Security Onion Console, with no reliance on other virtualization platforms.
More information here: https://docs.securityonion.net/en/2.4/hypervisor.html
SAVE THE DATE!
We will once again be hosting the Security Onion Conference in beautiful Augusta, GA on October 23rd. Registration will open on August 7.
Today, we are opening our Call For Presenters (CFP) for the conference. Have you developed a unique use case for Security Onion? Integrated it with other tools? Deployed it in an exciting new environment? We want to hear all about it!
https://blog.securityonion.net/2026/05/security-onion-conference-2026-save.html
ICYMI: Last week we had a webinar with our friends from Garland Technology on using their TAPs and packet brokers along with Security Onion for a holistic view of what's happening on your network. Check it out!

THURSDAY: Join our Senior Engineer Matthew Gracie, along with Chris Bihary and our friends from Garland Technology, for the webinar "See Everything, Miss Nothing: Enhancing Threat Detection with Complete Packet Visibility and Full Packet Capture". Come learn how Garland TAPs and packet brokers can feed Security Onion to give you full visibility into your network traffic.
Register below!
DID YOU KNOW?
Security Onion can be configured to automatically perform reverse DNS lookups to provide hostname information in the SOC interface. Just turn on the "enableReverseLookup" function in Configuration and enjoy!