This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 521
QuickISOImage
doug edited this page Aug 27, 2019
·
27 revisions
Please note! This wiki is no longer maintained. Our documentation has moved to https://securityonion.net/docs/. Please update your bookmarks. You can find the latest version of this page at: https://securityonion.net/docs/QuickISOImage.
- First, review the Hardware Requirements page.
- Review the Release Notes page.
- Download and verify our Security Onion ISO image.
- Boot the ISO image.
- At the ISO boot menu, choose the default option.
- Once the live desktop appears, double-click the "Install SecurityOnion" icon.
- Follow the prompts in the installer. If prompted with an
encrypt home folder
orencrypt partition
option, DO NOT enable this feature. If asked about automatic updates, DO NOT enable automatic updates. Reboot into your new installation. Login using the username/password you specified during installation. - Verify that you have Internet connectivity. If necessary, configure your proxy settings.
- Install updates and reboot. If you get any errors relating to MySQL, please see MySQL-Upgrade-Errors.
- Double-click the Setup icon. The Setup wizard will walk you through configuring
/etc/network/interfaces
and will then reboot. - After rebooting, log back in and start the Setup wizard again. It will detect that you have already configured
/etc/network/interfaces
and will walk you through the rest of the configuration. When prompted for Evaluation Mode or Production Mode, choose Evaluation Mode. - Once you've completed the Setup wizard, use the Desktop icons to login to
Sguil
,Squert
, orKibana
. - Finally, review the Post Installation page.
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs