Help with Monitoring Alerts and Logs in Security Onion (Distributed Setup) #14666
Replies: 1 comment
-
From https://docs.securityonion.net/en/2.4/pcap.html:
Click the alert, click Actions, click Correlate. From https://docs.securityonion.net/en/2.4/alerts.html#actions:
Most of our users do not use Kibana Observability. If you really need to use this feature, then you may need to enable it as shown in the Kibana Features section of our documentation. From https://docs.securityonion.net/en/2.4/kibana.html#features:
From https://docs.securityonion.net/en/2.4/introduction.html#workflow:
From https://docs.securityonion.net/en/2.4/kibana.html#kibana-dashboards:
We recommend our SOC Alerts interface: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone,
I'm new to Security Onion and recently set up a distributed deployment with receiver, manager, search, and sensor nodes. I’ve been trying to understand how to effectively monitor alerts and troubleshoot some issues. I have a few questions I hope someone can help with:
Where can I view the raw packet/message related to a triggered alert?
I want to dig into the raw data that triggered an alert. Where can I find that in Security Onion?
How do I verify if an alert is a false positive or true positive by using logs?
Is there a recommended way to correlate alerts with log data to validate them?
Kibana Error: "Application not found" when clicking "Show Logs Explorer"

In the Kibana "Observability" section, I see a "Show logs explorer" option, but clicking it gives an "Application not found" error.
Has anyone else faced this? How do I fix it?
Can someone explain a simple workflow for monitoring alerts in Security Onion?
Like, what tabs/tools should I regularly use to keep an eye on alerts?
Can we customize dashboards in Kibana or other parts of Security Onion?
I’d like to tailor dashboards to show exactly what I need—are customizations supported?
Which interface is best to use for monitoring alerts?
Should I focus on the “Alerts” tab, “Dashboards,” “Hunt,” or “Kibana”? Which one gives the most useful view for ongoing monitoring?
Thanks in advance for any help or suggestions! I’m eager to learn and get this setup working effectively.
Beta Was this translation helpful? Give feedback.
All reactions