Skip to content

2: Installation

Muted Mouse edited this page Apr 1, 2019 · 4 revisions

Complete OS installation

Boot from the SecurityOnion ISO or installation disk Upon boot completion, run the installation link on the Desktop.

This installation guide begins after first boot following installation of the Operating System.

First Stage: Security Onion Setup

Follow the prompts in the screens below ensuring you select you listed interfaces Configure Interfaces

Select Management Interface

Select Static

Enter Management Interface IP Address

Enter Management Interface Subnet Mask

Enter Management Interface Gateway Address

Enter Management Interface DNS Server IP Address

Enter Management Interface Domain Name

Choose "No, only configure a management interface." This choice is critical. Choose No only configure management interface

Select Yes Make Changes

Select Yes Reboot

Second Stage: Security Onion Setup

Select Yes Continue

Select Yes skip network configuration

Select Production Mode

Select Existing

Enter Master Server IP Address or Hostname

Enter a user who can execute as sudo on the master server

Select Heavy

Select Custom

Default values are acceptable as the functionality will be disabled in subsequent prompts Select OK with no changes

Check the non management interface from the list Select remaining NON MANAGEMENT Interfaces

Select Disable the IDS Engine

Select Disable Bro

Select Disable full packet capture

Leave default disk usage and select OK

Select Disable Salt

Leave Elastic logs default and Select OK

Visually confirm entries and select Proceed with changes

Type "yes" at the prompt, then enter password for master server user Type yes and enter master server user password at prompt

Reboot the system upon completion of the Second Stage

Third Stage: Host Configuration from Project

Download HELK4SO project and unzip in any directory of your choosing cd or Change Directory into the HELK4SO folder

Execute host-setup.sh script

Follow prompts to identify interfaces and settings for monitored interface Follow prompts to identify interfaces and addresses

Allow beats from monitored subnet or address with [b] option This command accepts cidr notation as well (10.0.0.0/24) for example Enter Management Interface IP Address

Once complete, the script will prompt for username to connect to master server. This user must be allowed to execute as sudo on master server. Follow prompts to execute as sudo on master server

Use [e] option and the IP address of the management interface of this sensor in the so-allow prompts Allow management ip address of sensor in so-allow

Reboot and enjoy. Please add index pattern "logs-*" on the master server to start displaying logs.

Home

Prerequisites

Post Installation

Usage

Resources