This lab introduces students to the Security Onion Security Information and Event Management (SIEM) system. It is a widely used SIEM that integrates multiple tools into one platform. Tools include: Log analysis tools such as Elasticsearch, Logstash, and Kibana; intrusion detection systems such as Suricata, Zeek and Snort; and threat detection systems such as Wazuh.
Students will learn to configure Security Onion and to use Squil, a graphical analyst console; Squert, a web application that is used to query and view event data stored in a Sguil database; and Kibana, the data visualization and exploration user interface for the Elasticsearch log analysis system.
Prerequisites
Basic understanding of the TCP/IP protocol stack and the Linux command line.
Expected Duration
0.5 hours, self-paced. Pause and continue at any time.
0.5 CPEs awarded on successful completion.
Availability
Included if you are a subscriber to any of the following training packages:
- Level 1: CYRIN Enterprise Instructional Labs
- Level 2: Attack/Defense/IR Exercises and Instructional Labs
- Level 3: Attack Scenarios, Attack/Defense/IR Exercises, and Instructional Labs
