Two refinements to the --salt-upgraded path, surfaced testing a salt downgrade+soup on a manager+heavynode grid: - The post-upgrade settle loop settled on any stable reachable count >0, so when a target was briefly down for its salt-minion restart it could settle on the not-yet-restarted subset (observed: 'settled at 1' with 2 accepted) and release the tiered pass before nodes reconnected. Capture the reachable count just before the pass and wait for it to recover to that count (up >= pre-upgrade target) and hold steady, with an initial grace so the delayed restart dip is observed rather than skipped. Still compares against the pre-upgrade reachable set, not accepted keys, so an intentionally powered-off node never stalls past the backstop. - The salt-upgrade pass returns non-zero by design (targets restart salt-minion mid-run), but it logged the generic 'nodes it missed will converge on the scheduled highstate' warning, which reads like a real failure. Mark that dispatch as expect_restart so it logs a benign, explanatory line instead. Verified live: with the heavynode's salt-minion bounced during the settle window, the loop logged 'fleet recovered to 2 minions up (>= pre-upgrade 2)' and only then ran the tiered pass (heavynode highstate 427 succeeded, 0 failed).
Security Onion
Security Onion is a free and open Linux distribution for threat hunting, enterprise security monitoring, and log management. It includes a comprehensive suite of tools designed to work together to provide visibility into your network and host activity.
✨ Features
Security Onion includes everything you need to monitor your network and host systems:
- Security Onion Console (SOC): A unified web interface for analyzing security events and managing your grid.
- Elastic Stack: Powerful search backed by Elasticsearch.
- Intrusion Detection: Network-based IDS with Suricata and host-based monitoring with Elastic Fleet.
- Network Metadata: Detailed network metadata generated by Zeek or Suricata.
- Full Packet Capture: Retain and analyze raw network traffic with Suricata PCAP.
⭐ Security Onion Pro
For organizations and enterprises requiring advanced capabilities, Security Onion Pro offers additional features designed for scale and efficiency:
- Onion AI: Leverage powerful AI-driven insights to accelerate your analysis and investigations.
- Enterprise Features: Enhanced tools and integrations tailored for enterprise-grade security operations.
For more information, visit the Security Onion Pro page.
☁️ Cloud Deployment
Security Onion is available and ready to deploy in the AWS, Azure, and Google Cloud (GCP) marketplaces.
🚀 Getting Started
| Goal | Resource |
|---|---|
| Download | Security Onion ISO |
| Requirements | Hardware Guide |
| Install | Installation Instructions |
| What's New | Release Notes |
📖 Documentation & Support
For more detailed information, please visit our Documentation.
- FAQ: Frequently Asked Questions
- Community: Discussions & Support
- Training: Official Training
🤝 Contributing
We welcome contributions! Please see our CONTRIBUTING.md for guidelines on how to get involved.
🛡️ License
Security Onion is licensed under the terms of the license found in the LICENSE file.
Built with 🧅 by Security Onion Solutions.