Not the answer I was hoping for! :-D I need to do this myself on an existing machine.
Here is what I'm thinking: ( I peeked in sosetup, nsm_sensor_add and nsm_server_sensor-add )
The questions I ask below I'll try and answer as I go through it for myself but if anyone knows fell free to shout it out. I'll try and develop a script to perform these functions as I might have to repeat again down the road.
sosetup:
----------
run through nsm_sensor_add items ( most are checking things and then making directories and copying files )
Q: Do I need a new port for barnyard? (thinking yes) is that the normal 8100 in sensortab?
Now that I looked more just calling nsm_sensor_add with the proper port might work just fine.
Will need to investigate sensortab_names_get_on_port & sensortab_entry_add calls and see what they do.
--- under # NIDS sensor(s) ---
run through the remainder of the setup after nsm_sensor_add call
-- under # Bro
add those to the config.
Is there anything to add on the server or sguil database?
Thanks,
-B
Today I had success adding another interface... not all scripted yet but I know what needs to happen. Most is simple as missed preparing the variables in sensor.conf.
I'm cobbling together a nsm_sensor_add_interface script from mostly sosetup that I'd like to possibly shoot you a copy next week if you like.
Monday, I'm going to restore snapshots on both sever and sensor add the missing pieces to the script and keep running it over until I get it right.
Answering my own questions:
A1 - yes to barnyard. I'm going with the let BY2PORT=$BY2PORT+100
A2 - nope everything happens on sensor. Once it's all running sguil client sees the new interfaces.
Cheers,
-B
-Bob
Thanks Doug. I'll check that out. I did see that piece in the script but looks to be no related call or ssh back to the server to run those commands. I'll be sure to exercise all functionality in sguil once I think I'm there and post back.
-Bob
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.
Thanks
Hi, any changes in v16? I'd like to add a 3rd NIC to a sensor VM.
Thanks
--
Follow Security Onion on Twitter!
https://twitter.com/securityonion
---
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at https://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.