Install/Enable ELSA Post Installation/Configuration

145 views
Skip to first unread message

Martin Bishop

unread,
Jul 11, 2016, 4:13:32 PM7/11/16
to security-onion
Hi All,

Havent seem to find the answer in the group, so asking here.

I have SO 14.04 (standalone) installed on Ubuntu 14.04 LTS server. I have already went through the process of configuring everything for the current services and sensors. However, I would like to enable/install ELSA to play around with its functionality. During the initial sosetup, I declined to enable ELSA and so at this point I would like to enable it. I would however like to complete this without having sosetup overwrite any of my current configurations.

Is there an ELSA setup script in SO that would be used for this process? If so, please advise. If not, would going thru the sosetup again write-over my current configurations? Any other advice that would be helpful in this situation would be appreciated.

Please advise.

Thanks in advance!

Martin Bishop

unread,
Jul 11, 2016, 4:16:15 PM7/11/16
to security-onion
Currently reading this post to see if this will work...

https://groups.google.com/forum/#!searchin/security-onion/ELSA$20enable/security-onion/og50nOWKgAM/K4N1hE1HXbUJ

Any additional information is appreciated.

Martin Bishop

unread,
Jul 11, 2016, 4:38:05 PM7/11/16
to security-onion
From Dougs post on this matter:

- run "sudo /usr/bin/securityonion-elsa-config.sh -t WEB" on your
master server (the box that hosts sguild, Squert, Snorby, etc.)
- run "sudo /usr/bin/securityonion-elsa-config.sh -t LOG" on any boxes
that are sniffing live network interfaces
- once the previous step is completed and all sensors are running ELSA
log nodes, then return to the master server and run "sudo
/usr/bin/securityonion_elsa_register.rb -f && sudo service apache2
restart"

Already ran, will be testing and troubleshooting next. If I find any issues, I will post them here. If all else fails, I get to re-run sosetup and will have to reconfigure everything.

Reply all
Reply to author
Forward
0 new messages