<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Security Onion for threat hunting, network security monitoring, and log management.]]></title><description><![CDATA[<p dir="auto">Security Onion, is a free and open platform for threat hunting, network security monitoring, and log management. Security Onion includes free and open tools including Suricata, Zeek, Wazuh, the Elastic Stack and many others.</p>
<p dir="auto"><a href="https://github.com/Security-Onion-Solutions/securityonion/blob/master/VERIFY_ISO.md" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/Security-Onion-Solutions/securityonion/blob/master/VERIFY_ISO.md</a></p>
]]></description><link>https://forum.cloudron.io/topic/6213/security-onion-for-threat-hunting-network-security-monitoring-and-log-management</link><generator>RSS for Node</generator><lastBuildDate>Sun, 10 May 2026 23:42:14 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6213.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 22 Dec 2021 22:26:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Security Onion for threat hunting, network security monitoring, and log management. on Thu, 23 Dec 2021 20:51:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: mastadamus">@<bdi>mastadamus</bdi></a> good convo to have with the Sysbox folks.</p>
]]></description><link>https://forum.cloudron.io/post/40875</link><guid isPermaLink="true">https://forum.cloudron.io/post/40875</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Thu, 23 Dec 2021 20:51:26 GMT</pubDate></item><item><title><![CDATA[Reply to Security Onion for threat hunting, network security monitoring, and log management. on Thu, 23 Dec 2021 15:11:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a>  yeah I should have said "can't be easily containerized"<br />
Security onion relies on a span port/mirror traffic getting to its analysis engines and is a pretty complicated beast. If cloudron can containerized the whole thing awesome but this is no small task lol.</p>
]]></description><link>https://forum.cloudron.io/post/40858</link><guid isPermaLink="true">https://forum.cloudron.io/post/40858</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Thu, 23 Dec 2021 15:11:34 GMT</pubDate></item><item><title><![CDATA[Reply to Security Onion for threat hunting, network security monitoring, and log management. on Thu, 23 Dec 2021 05:17:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: mastadamus">@<bdi>mastadamus</bdi></a> This is possible because of a few innovations:</p>
<ol>
<li>Sysbox by Nestybox, find the thread in this forum.</li>
<li>This allows for Docker-in-Docker nesting, even running VMs.</li>
<li>With affordable VPS providers like <a href="https://trimurl.co/ssd" target="_blank" rel="noopener noreferrer nofollow ugc">SSDnodes</a> and Contabo, CPU and RAM are not an issue.</li>
<li>With multi-cloudron coming soon, it's going to be an ecosystem of hosts managed by a central Cloudron UI, so why not have a host dedicated to security or similar functions.</li>
</ol>
]]></description><link>https://forum.cloudron.io/post/40846</link><guid isPermaLink="true">https://forum.cloudron.io/post/40846</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Thu, 23 Dec 2021 05:17:54 GMT</pubDate></item><item><title><![CDATA[Reply to Security Onion for threat hunting, network security monitoring, and log management. on Thu, 23 Dec 2021 00:41:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dark-shadow" aria-label="Profile: dark-shadow">@<bdi>dark-shadow</bdi></a> I run security onion on a separate machine. I don't think its applicable for cloudron. 1. it can't be containerized. its a stack of docker containers controlled by SALT. 2. It requires immense CPU/RAM/HD. For a small network you are looking at 4 cores min and at least 20gb ram.  Additionally, You don't really want to put your security tools on the same subnet as your internet facing stuff.</p>
]]></description><link>https://forum.cloudron.io/post/40842</link><guid isPermaLink="true">https://forum.cloudron.io/post/40842</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Thu, 23 Dec 2021 00:41:22 GMT</pubDate></item></channel></rss>