Madiana A. Argon :verified: · @madargon
1017 followers · 579 posts · Server is-a.cat

Funny thing...

For many weeks I couldn't power off my work laptop. For some reasons system (it's Ubuntu there) didn't shut down and I always had to use power button. I blamed snap nonsense (which frequently generates other problems) or keeping Yubikeys inserted too much time.

Today I tried to check memory usage and ran . I was surprised when I found many background processes from services I tested long time ago, mostly related to . It reminded me I experimented with data transfer between remote systems and set my computer to send data to development server. Later I disabled services on that server and forgot about these tests. And my computer tried to send data for more than 3 months and didn't let turn system off unless it will be successfully sent :blobcatjoy:​
Of course I disabled all remained services.

Today I could turn off my laptop without using power button first time since December :blobcatjoy:​

#htop #logstash #it #SysAdmin #linux

Last updated 1 year ago

Ingest data from to @AzDataExplorer
Day60

() Logstash plugin enables you to process events from Logstash into an Azure Data Explorer database for later analysis.

Learn More
[1] learn.microsoft.com/en-us/azur
[2] learn.microsoft.com/en-us/azur

#logstash #365daysofadx #azuredataexplorer #adx

Last updated 1 year ago

Philipp Krenn · @xeraa
424 followers · 226 posts · Server mastodon.social

we're currently also working on re-using the same ingest pipelines on logstash. because that is a common transition. also bringing logstash to the operator
so is very much alive. but probably not what you want for starters

#kubernetes #logstash

Last updated 1 year ago

Philipp Krenn · @xeraa
424 followers · 225 posts · Server mastodon.social

worth repeating, since this is such a common question: is "going to be dropped/replaced"?

yes and no :)
I'd only start using logstash when you need it (JDBC input, multiple outputs, DNS lookups,...). otherwise agent / beats + ingest should be simpler to get started and potentially slimmer
but for large users, many use logstash. both for features and scale

#logstash #elasticsearch

Last updated 1 year ago

MrRoubos · @MrRoubos
127 followers · 925 posts · Server mastodon.nl

I think it is amazing when I try to configure to accept via via with on a server. Then when I configure a rsyslog client without any certs configuration, I see this loglines on the rsyslog with certs passing. Weird. Next attempt is to deliver from rsyslog with certs to with certs. As last option switch to

#filebeat #logstash #ubuntu #certs #imtcp #gtls #tls #rsyslog

Last updated 2 years ago

Philipp Krenn · @xeraa
395 followers · 179 posts · Server mastodon.social

wrote a quick blog post on: "did a (hub) pull request / commit make the release?"
example from where it got trickier than normal: xeraa.net/blog/2023_pull-reque

#git #logstash

Last updated 2 years ago

Nitin · @redknitin
11 followers · 62 posts · Server ruby.social

I just deployed the stack to demonstrate log analysis to an audience of IT Ops engineers 👨‍💻. It was easy to ingest ‘s logs and process them through ‘s JSON filter and to get to show a count of connections from each client node. Before the demo, I looked at using which RedHat uses in as the stack.

#elk #mongodb #logstash #kibana #fluentd #openshift #efk

Last updated 2 years ago

Beth Pariseau · @BPariseau
248 followers · 39 posts · Server hachyderm.io
Beth Pariseau · @BPariseau
257 followers · 43 posts · Server hachyderm.io
F0rm4t · @F0rm4t
18 followers · 19 posts · Server infosec.exchange
⥫ Lee ⥭ :yorkshire: · @lee
130 followers · 512 posts · Server yorkshire.social

@mhamzahkhan ELK is heavy weight. If all you want is centralised logging, you might be able to just leverage the L in . will consolidate your logs, but without the bells and whistles provided by and .

#elk #logstash #elasticsearch #kibana

Last updated 2 years ago

rishi (/r/n) :verifiedpurple: · @rishi
87 followers · 134 posts · Server infosec.exchange

Alright fellas, folks and friends - I am revamping my SIEM setup - moving to next month; also evaluating in last couple of years how is holding up against

Would you recommend to update ELK & continue with improving it, or it’s a good time to dip my toe in the world of Wazuh?

Expected log sources/ purpose:
Few HTTP (Nginx, nix), 1 vulnerable server (nix) , may be pi-hole (not yet setup), home IOT and daily drivers (max and windows)

Tags:
%toot_23%

#soc #threathunting #blueteam #cloud #elk #wazuh #honeypot #siem #logstash #kibana #ioc #threatintel

Last updated 2 years ago

Kamyar Kojouri · @etcshad0w
80 followers · 32 posts · Server infosec.exchange

Does anyone here use and have you found a way to do proper load balancing across a large fleet of Logstash servers? We’ve tried DNS, HAProxy, and Netscalers, the clienrs continue to stick to the servers they initially connected to and will not let go until to force kill those connections, so the load doesn’t get evenly distributed.

#logstash #elastic #elasticsearch

Last updated 2 years ago

Kadin · @kadin
178 followers · 1356 posts · Server mastodon.sdf.org

Spent more time than I'd care to admit today playing around with the and components of the "ELK" stack. Because I'd heard that Logstash was the toughest to get running, I started there. And it really wasn't bad to get installed and set up (just some weird permissions issues on ).

However, I didn't realize that there's just no way to run Elasticsearch on a 32b kernel. Fail.

Anyone know any drop-in alternatives to ELK's Elasticsearch that are lighter-weight?

#elasticsearch #logstash #debian

Last updated 2 years ago

fgntfg :ablobcatrainbow: · @fgntfg
125 followers · 4096 posts · Server lor.sh


Если DLQ очень резво забивается, куда тыкать? Очистка помогает, но не панацея совсем.

#logstash

Last updated 3 years ago

HCS ▋ · @superruserr
1273 followers · 2875 posts · Server infosec.exchange

Just added: YAML Config with Event IDs of Active Directory Domain Service Events with Criticality Info hannahsuarez.github.io/2021/Ac

#logging #logstash #yml #elasticsearch #elk

Last updated 4 years ago

Want to parse out domain tld info in and can't get logstash-filter-tld installed
blog.infosecworrier.dk/2019/08

#logstash #elastic #logging #domain #dns #fqdn

Last updated 5 years ago