security-onion

Docs live on Discourse — this repo is the executable source of truth. Topic: https://community.turnsys.com/t/332 Redmine: https://projects.knownelement.com/issues/772 · Split from KNEL/PFVCluster@041d311 per #769

Repo home for Security Onion ops integration (syslog→Wazuh, netflow from OPNsense, coverage matrix). DEPLOYMENT is owned by the security lane, not this repo's lane. [#772]

Layout

  • scripts/ — rule engine + hooks (see bash scripts/check-rules.sh --fast)
  • (imported content at repo root, mirroring its PFVCluster path layout)

Provenance

Code imported from KNEL/PFVCluster (041d311); full git history retained in PFVCluster. Enforcement layer copied per ADOPTING.md. IaC consumers: KNEL/KNELIAC references this repo.

S
Description
Security Onion: repo home; deployment owned by the security lane [#772]
Readme AGPL-3.0
56 KiB
Languages
Shell 93.2%
Makefile 6.8%