About This File
The EveBox Remote Node Agent — OpenSearch Edition extends an existing WinSuricata Headless sensor into a managed Remote Node within the centralized WinSuricata deployment framework. The Remote Node continues to operate as a local Suricata detection sensor, capturing network traffic, applying detection rules, and generating its local eve.json event stream. The EveBox Remote Agent operates alongside Suricata and securely forwards applicable alert telemetry to the designated WinSuricata Host, allowing the local sensor to retain its detection capabilities while participating in a centralized security monitoring environment.
Each Remote Node is individually registered with the WinSuricata Host and receives a unique Host-generated authentication and configuration package that establishes its authorized communication relationship with the Host. Once deployed, the Remote Node becomes an identified sensor within the centralized EveBox/OpenSearch environment, where its alert telemetry can be stored, searched, visualized, and managed alongside other registered sensors. The Remote Node Edition therefore adds centralized connectivity and sensor integration to an existing WinSuricata Headless installation without replacing the local Suricata detection engine or requiring OpenSearch to be installed on the Remote Node itself.
Complete installation instructions, deployment requirements, verification procedures, troubleshooting information, architecture details, and the final deployment checklist are included in the `README-INSTALL.txt` file contained within this package. Please review the included documentation before beginning the installation and retain it for future administration and troubleshooting.
PACKAGE SECURITY & INTEGRITY
Before extracting or installing the package, verify the downloaded ZIP file against the published SHA-1 hash to confirm that the archive has not been corrupted or altered.
Archive Password : w1nsn03t.c0m SHA-1 Hash : 5B9032569517CF8C28264E6E94D8A420D1B176D4
To verify the package in Windows, run the following command from Command Prompt or PowerShell, replacing the filename if necessary:
certutil -hashfile "EveBox-OpenSearch-Node-Installer.zip" SHA1
The calculated SHA-1 value must match the published value exactly. If the hash does not match, do not extract or install the package. Obtain a new copy from the authorized distribution source and perform the verification again.
