Skip to content

Questions Regarding Log Storage and Node Management in Security Onion #14056

Answered by dougburks
SankaGamage asked this question in Q&A
Discussion options

You must be logged in to vote

How long are logs typically stored in Security Onion by default?

This depends on how much disk space you have:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Is it possible to change the log retention period? If so, how can this be configured?

Yes:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Where are logs normally stored in Security Onion?

/nsm:
https://docs.securityonion.net/en/2.4/directory.html

If logs are overwritten, how many days of logs are retained before they are overwritten?

This depends on how much disk space you have:
https://docs.securityonion.net/en/2.4/elasticsearch.html#index-management

Is it possible to st…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@SankaGamage
Comment options

@dougburks
Comment options

Answer selected by SankaGamage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants