photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

242
active users

#splunk

1 post1 participant0 posts today

Nächste Woche dann endlich die #Splunk Schulung. Gestern videocall mit den Kollegen der Abteilung, die Splunk betreiben…
Die Idee für ne splunk Schulung fanden sie cool. Zumal der zuständige Kollege, diesen Sommer extern gewechselt hat. Interne Ausschreibung der Stelle kommt bald, ob ich Interessiert wäre 😳🤔😬

👋 Hello Mastodon!

I'm Steven Butterworth, aka UKITGURU. I specialise in InfoSec and SIEM technologies (Splunk, Sentinel, Elastic). As a freelancer, I create and deliver SIEM content, working with gov departments and private sectors. Passionate about Data Science, Data Engineering, and data literacy. Avid triathlon enthusiast—never enough bikes! 🚴‍♂️

Looking forward to connecting!

#InfoSec
#SIEM
#Splunk
#Sentinel
#DataScience
#Triathlon
#Cycling

Today I learnt MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 encapsulates LDAP Authentication on Windows Domain controllers where a request is made by LDAP(S).

This is after I have spent years following trusting most of the advice online that it’s an artifact of NTLM authentication and the local security authority (LSA). For the better part of a decade I had assumed these were being generated by legacy windows devices using NTLM, but never working out why there were so many of them.

It all makes sense now! And now at least I have a better understanding of some of the events I am looking at!

Since morning I am searching for a nice free log analyzer, I used #splunk around 12 years just wanted to search quickly on some application logs, most probably log4j or log4net logs. I tried
- #ELK<-too hard to install configure
- #graylog<-too complex or non working docs
- #jaeger<-wanted json format
- #openobserve<-does not have simple log upload or file path provider, needs fluentd or kubectl

I did not know splunk is this good, now I am convinced it is super product. Feel free to tell if you have a good suggestion and boost please for reach.

So I set up #Splunk again at home on a dev license and started to ingest firewall logs again.

PSA: #QNAP Consumer NAS devices have apps (Hello myQNAPCloud Link) that talk UDP on UNDOCUMENTED ports back to the Akamai cloud.

Have now added some restrictive firewall rules to allow that traffic through, but a little annoyed that its taken me as long as it has to find the source of the issue due to lack of documentation.

I'm probably an outlier in being a person who reviews home firewall deny logs though :)