Latest upstream stable for el9. All four NVRs are already carried by the SO prod repo, so no repo change is needed -- a so-repo-sync refresh is enough. Tested on a managersearch and a heavynode (OL 9.8, 3.4.0), upgrading from 29.2.1/2.2.1 both by hand and through the state itself: - The 29.8.1 RPM ships a byte-identical docker.service, so the full ExecStart override in files/iptables-disabled.conf still resolves correctly and the hand-written DOCKER/DOCKER-ISOLATION/DOCKER-USER chains came back byte-identical on both nodes across upgrade, restart and reboot. - update_holds re-pinned the versionlock from the old NVRs to the new ones without intervention, so soup's path needs no change. - docker-py 7.1.0 still creates sobridge and soauth (forced by removing both); bridges keep their configured kernel names rather than br-<hash>. - 29.6 changed how dynamic port allocation treats net.ipv4.ip_local_reserved_ports; Strelka's 57314 is both published and reserved, and docker-proxy still owns it with no bind errors. - docker ps --format json gained a HealthStatus key. Additive, so so-status, so-log-check and so-docker-prune all still parse it. - containerd 2.3.6 ships the same config.toml, and it is %config(noreplace) and unmodified on disk, so no .rpmnew and disabled_plugins=["cri"] survives. - Zeek/Suricata/Strelka pipeline verified end-to-end with so-test: 111k packets replayed, 0 capture loss, file extraction and ES ingest all landed. The manifest unknown exclusion in so-log-check still fires on 29.8.1 -- it comes from a tag lookup during the registry-to-registry image copy, not from the 29.2.1 upgrade the old comment blamed -- so only the comment changes.
Security Onion
Security Onion is a free and open Linux distribution for threat hunting, enterprise security monitoring, and log management. It includes a comprehensive suite of tools designed to work together to provide visibility into your network and host activity.
✨ Features
Security Onion includes everything you need to monitor your network and host systems:
- Security Onion Console (SOC): A unified web interface for analyzing security events and managing your grid.
- Elastic Stack: Powerful search backed by Elasticsearch.
- Intrusion Detection: Network-based IDS with Suricata and host-based monitoring with Elastic Fleet.
- Network Metadata: Detailed network metadata generated by Zeek or Suricata.
- Full Packet Capture: Retain and analyze raw network traffic with Suricata PCAP.
⭐ Security Onion Pro
For organizations and enterprises requiring advanced capabilities, Security Onion Pro offers additional features designed for scale and efficiency:
- Onion AI: Leverage powerful AI-driven insights to accelerate your analysis and investigations.
- Enterprise Features: Enhanced tools and integrations tailored for enterprise-grade security operations.
For more information, visit the Security Onion Pro page.
☁️ Cloud Deployment
Security Onion is available and ready to deploy in the AWS, Azure, and Google Cloud (GCP) marketplaces.
🚀 Getting Started
| Goal | Resource |
|---|---|
| Download | Security Onion ISO |
| Requirements | Hardware Guide |
| Install | Installation Instructions |
| What's New | Release Notes |
📖 Documentation & Support
For more detailed information, please visit our Documentation.
- FAQ: Frequently Asked Questions
- Community: Discussions & Support
- Training: Official Training
🤝 Contributing
We welcome contributions! Please see our CONTRIBUTING.md for guidelines on how to get involved.
🛡️ License
Security Onion is licensed under the terms of the license found in the LICENSE file.
Built with 🧅 by Security Onion Solutions.