-
Notifications
You must be signed in to change notification settings - Fork 522
Installation
Please note! This wiki is no longer maintained. Our documentation has moved to https://securityonion.net/docs/. Please update your bookmarks. You can find the latest version of this page at: https://securityonion.net/docs/Installation.
To install Security Onion, you're going to either install our Security Onion ISO image or install a standard Ubuntu 16.04 ISO image and then add our Security Onion PPA and packages. Please keep in mind that our PPA and packages are only compatible with Ubuntu 16.04.
Regardless of whether you're downloading our Security Onion ISO image or whether you're starting with an Ubuntu 16.04 ISO image, you should ALWAYS verify the downloaded ISO image.
- If downloading our Security Onion 16.04 ISO image, please verify using these instructions:
https://github.com/Security-Onion-Solutions/security-onion/blob/master/Verify_ISO.md - If downloading an Ubuntu 16.04 ISO image, please verify using these instructions:
https://help.ubuntu.com/community/VerifyIsoHowto
If you haven't already, please review the Hardware page.
If you have a new machine with UEFI, please see: https://help.ubuntu.com/community/UEFI
If your hardware has UEFI Secure Boot enabled, please see Secure Boot.
Please note that we only support the English language at this time.
We have different Installation Guides to cover various use cases. Please choose the appropriate Installation Guide for your use case.
If you just want to quickly evaluate Security Onion, choose one of the following. If you're a first time user, please choose the first option.
OR
If you're deploying Security Onion in production, please see:
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs