Splunk rant
Splunk rant
ICYMI: on the latest #TechstrongTV I join the Gang to go deep on #Google #acquisition of #CNAP (#cloud #cybersecurity) with #Wiz, esp. how it hits #AWS, #Azure, #Cisco, #Splunk, #Crowdstrike, #PANW, ++. Just don't call it #DevSecOps!
Plus, #AI is failing, even for religion!
https://techstrong.tv/videos/videos/techstrong-gang-march-19-2025
ICYMI, on the latest #TechstrongTV I join the Gang to go deep on #Google #acquisition of #CNAP (#cloud #cybersecurity) with #Wiz, esp. how it hits #AWS, #Azure, #Cisco, #Splunk, #Crowdstrike, #PANW, ++. Just don't call it #DevSecOps!
Plus, #AI is failing, even for religion!
https://techstrong.tv/videos/videos/techstrong-gang-march-19-2025
ICYMI, on the latest #TechstrongTV I join the Gang to go deep on #Google #acquisition of #CNAP (#cloud #cybersecurity) with #Wiz, esp. how it hits #AWS, #Azure, #Cisco, #Splunk, #Crowdstrike, #PANW, ++. Just don't call it #DevSecOps!
Plus, #AI is failing, even for religion!
https://techstrong.tv/videos/videos/techstrong-gang-march-19-2025
Super new drop from #TechstrongTV! I join the Gang to go deep on #Google #acquisition of #CNAP (#cloud #cybersecurity) with #Wiz, esp. how it hits #AWS, #Azure, #Cisco, #Splunk, #Crowdstrike, #PANW, ++. Just don't call it #DevSecOps!
Plus, #AI is failing, even for religion!
https://techstrong.tv/videos/videos/techstrong-gang-march-19-2025
"#Alphabet to buy #Wiz for $32bn in its biggest deal to boost #cloud #security"
Smart for #Google - #cybersecurity still #1 factor for #CIO & #CTO, esp. #enterprise. Takes fight to $AMZN $MSFT $CRWD $PANW but esp $CSCO (#Splunk, #Epsagon).
Just don't call it #DevSecOps!
Hey Software company PR peeps. You might want to at least register your handle on #Bluesky; ideally with your verified domain.
Today alone I have seen name-squatters for #ServiceNow, #SolarWinds, #Splunk, #Cisco, #Squadcast, and #Atlassian.
And anyone else who wants to protect their name/brand.
"#Solarwinds Acquires #Squadcast, Unifying #Observability & #IncidentResponse"
Not exactly a blockbuster. Useful for customers, and I get this is a tempting adjacency (ask me how I know ) but I don't see this hurting #PagerDuty, let alone #Cisco, #Splunk, or #ServiceNow.
@fistfulofdave that was my follow up argument. When I’m using #Splunk to report on stuff I can eyeball the results from a first pass at writing a query, then debug and finesse it. With an #AI / #LLM you’re putting complete trust in its output, you can’t ask to “see it’s working”, as it were.
Nächste Woche dann endlich die #Splunk Schulung. Gestern videocall mit den Kollegen der Abteilung, die Splunk betreiben…
Die Idee für ne splunk Schulung fanden sie cool. Zumal der zuständige Kollege, diesen Sommer extern gewechselt hat. Interne Ausschreibung der Stelle kommt bald, ob ich Interessiert wäre
Hello Mastodon!
I'm Steven Butterworth, aka UKITGURU. I specialise in InfoSec and SIEM technologies (Splunk, Sentinel, Elastic). As a freelancer, I create and deliver SIEM content, working with gov departments and private sectors. Passionate about Data Science, Data Engineering, and data literacy. Avid triathlon enthusiast—never enough bikes!
Looking forward to connecting!
#InfoSec
#SIEM
#Splunk
#Sentinel
#DataScience
#Triathlon
#Cycling
There are hundred of lava tube caves in southern Washington. Some are a tight squeeze, others offer vast open rooms with 50’ tall ceilings.
Today I learnt MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 encapsulates LDAP Authentication on Windows Domain controllers where a request is made by LDAP(S).
This is after I have spent years following trusting most of the advice online that it’s an artifact of NTLM authentication and the local security authority (LSA). For the better part of a decade I had assumed these were being generated by legacy windows devices using NTLM, but never working out why there were so many of them.
It all makes sense now! And now at least I have a better understanding of some of the events I am looking at!
Today is DBA Appreciation Day!
If you have a DBA in your company who relentlessly takes care that your databases are humming along and delivering query results, today is the day to say Thank You!
#PostgreSQL #MySQL #MariaDB #Oracle #Greenplum #SQLite #SQLServer #MongoDB #Redis #Snowflake #DB2 #Elasticsearch #Teradata #InfluxDB #Firebird #Informix #Couchbase #CouchDB #Vertica #DuckDB #CockroachDB #SAPHana #Splunk #DynamoDB #BigQuery #Hive #Neo4j ...
Since morning I am searching for a nice free log analyzer, I used #splunk around 12 years just wanted to search quickly on some application logs, most probably log4j or log4net logs. I tried
- #ELK<-too hard to install configure
- #graylog<-too complex or non working docs
- #jaeger<-wanted json format
- #openobserve<-does not have simple log upload or file path provider, needs fluentd or kubectl
I did not know splunk is this good, now I am convinced it is super product. Feel free to tell if you have a good suggestion and boost please for reach.
Thank you, #Splunk, for the recurrence of leaning toothpick syndrome…
…
| rex mode=sed field=URI "s/\/\d+(\/|$)/\/42\1/g"
| stats count by URI
So I set up #Splunk again at home on a dev license and started to ingest firewall logs again.
PSA: #QNAP Consumer NAS devices have apps (Hello myQNAPCloud Link) that talk UDP on UNDOCUMENTED ports back to the Akamai cloud.
Have now added some restrictive firewall rules to allow that traffic through, but a little annoyed that its taken me as long as it has to find the source of the issue due to lack of documentation.
I'm probably an outlier in being a person who reviews home firewall deny logs though :)