-
Notifications
You must be signed in to change notification settings - Fork 522
Installation
To install Security Onion, you're going to either install our Security Onion ISO image or install a standard Ubuntu 12.04 ISO image and then add our Security Onion PPA and packages. Please keep in mind that our PPA and packages are only compatible with Ubuntu 12.04.
Regardless of whether you're downloading our Security Onion ISO image or whether you're starting with an Ubuntu 12.04 ISO image, you should ALWAYS verify the checksum of the downloaded ISO image.
- If downloading our Security Onion ISO image, you can download the accompanying .md5 file or you can use the MD5/SHA1 checksums that Sourceforge displays when clicking the Information (view details) button to the right of the ISO image (it's a circle with an "i").
- If downloading an Ubuntu 12.04 ISO image, use the accompanying .md5 file. Here are some Ubuntu instructions for verifying checksums: https://help.ubuntu.com/community/HowToMD5SUM
If you haven't already, please review the Hardware page.
If you have a new machine with UEFI, please see:
https://help.ubuntu.com/community/UEFI
We have different Installation Guides to cover various use cases. Please choose the appropriate Installation Guide for your use case.
If you just want to quickly evaluate Security Onion, choose one of the following. If you're a first time user, please choose the first option.
OR
If you're deploying Security Onion in production, please see:
- Introduction
- Use Cases
- Hardware Requirements
- Release Notes
- Download/Install
- Booting Issues
- After Installation
- UTC and Time Zones
- Services
- VirtualBox Walkthrough
- VMWare Walkthrough
- Videos
- Architecture
- Cheat Sheet
- Conference
- Elastic Stack
- Elastic Architecture
- Elasticsearch
- Logstash
- Kibana
- ElastAlert
- Curator
- FreqServer
- DomainStats
- Docker
- Redis
- Data Fields
- Beats
- Pre-Releases
- ELSA to Elastic
- Network Configuration
- Proxy Configuration
- Firewall/Hardening
- Email Configuration
- Integrating with other systems
- Changing IP Addresses
- NTP
- Managing Alerts
- Managing Rules
- Adding Local Rules
- Disabling Processes
- Filtering with BPF
- Adjusting PF_RING for traffic
- MySQL Tuning
- Adding a new disk
- High Performance Tuning
- Trimming PCAPs