This lab introduces students to the Security Onion Security Information and Event Management (SIEM) system.  It is a widely used SIEM that integrates multiple tools into one platform.  Tools include: Log analysis tools such as Elasticsearch, Logstash, and Kibana;  intrusion detection systems such as Suricata, Zeek and Snort; and threat detection systems such as Wazuh.

Students will learn to configure Security Onion and to use Squil, a graphical analyst console; Squert, a web application that is used to query and view event data stored in a Sguil database; and Kibana, the data visualization and exploration user interface for the Elasticsearch log analysis system.

Prerequisites

Basic understanding of the TCP/IP protocol stack and the Linux command line.

Expected Duration

0.5 hours, self-paced. Pause and continue at any time.
0.5 CPEs awarded on successful completion.

Availability

Included if you are a subscriber to any of the following training packages:

  • Level 1: CYRIN Enterprise Instructional Labs
  • Level 2: Attack/Defense/IR Exercises and Instructional Labs
  • Level 3: Attack Scenarios, Attack/Defense/IR Exercises, and Instructional Labs
Live Exercise