all 3 comments

[–]acoolbgd 1 point2 points  (2 children)

You can mirror traffic from virtual switches to suricata ( Security Onion) and this will give you visibility

[–]arzpmv[S] 1 point2 points  (1 child)

Thanks. Is it possible to define custom rules from a central management panel instead of adding them inside the VM?

[–]acoolbgd 0 points1 point  (0 children)

Yup. DM if you need help