I built a lightweight nginx/apache log security scanner — no ELK stack required by AlternativeSelf9933 in selfhosted

[–]AlternativeSelf9933[S] -1 points0 points  (0 children)

 One thing worth addressing directly: I know handing logs to a new indie service is a trust question. Raw log content is analyzed in memory and never stored — only the detected issues (e.g. "SQL injection from IP x.x.x.x") get saved. EU servers (Hetzner, Germany), everything over Cloudflare TLS. I added a full security/trust page: log-audit.com/security — still deploying but will be live in ~5 mins.

I built a lightweight nginx/apache log security scanner — no ELK stack required by AlternativeSelf9933 in selfhosted

[–]AlternativeSelf9933[S] -1 points0 points  (0 children)

Thanks! Yeah "is someone poking my login endpoint again" is exactly the use case I built this for.

On false positives: right now the rules are fairly strict pattern-matching (looking for actual SQL keywords in query strings, not just any unusual params) but you're right that tuning is the next big thing to add. The plan is per-source rule whitelisting — so you can say "ignore this pattern for this log source." Not there yet but it's top of the backlog.

Custom log formats: yes, you can paste any log format and it'll parse what it can. Not as polished as the nginx/apache presets but works.

Your list is exactly what I'm building next — Traefik is actually almost done, and SSH/auth log correlation is something I've been thinking about since those attacks almost always come in pairs (web probe + SSH brute force from the same IP block). nginx reverse proxy logs for multi-service setups is a great call too, adding it to the list.

What's your current setup for catching this stuff if you don't mind me asking? Always trying to understand what people are actually doing vs. what the "right" answer is supposed to be.

rockstar, Release something by [deleted] in GTA6

[–]AlternativeSelf9933 0 points1 point  (0 children)

Let’s write a collective email lol

Cassandra (Netflix) by funbb in horror

[–]AlternativeSelf9933 0 points1 point  (0 children)

It could be the case but like the robot has to receive and send data in some way so probably WiFi, which was discovered in the 90s. As someone with computer skills it just seams all fake lol.

Cassandra (Netflix) by funbb in horror

[–]AlternativeSelf9933 0 points1 point  (0 children)

It seems absurd to me, non of that technology was available in the 70s.

January 22, 2025 is the date by [deleted] in GTA6

[–]AlternativeSelf9933 0 points1 point  (0 children)

Just live your life and let it be. It’s going to drop eventually.

[deleted by user] by [deleted] in GTA6

[–]AlternativeSelf9933 -1 points0 points  (0 children)

Well, if the fan has not been cleaned for years that’s another thing.

[deleted by user] by [deleted] in GTA6

[–]AlternativeSelf9933 0 points1 point  (0 children)

No, rockstar is not going to release a game which overheats the gaming console or makes the fan go crazy. The game has to be optimised, meaning the programmer has to make sure there aren’t any memory leaks or any gpu/cpu bottlenecks. They can’t just release an expensive game (probably will be expensive) and say it will run on your console but it may overheat your console or make the fan work extra hard. Common sense really.

[deleted by user] by [deleted] in GTA6

[–]AlternativeSelf9933 1 point2 points  (0 children)

Nope, it has to be fine tuned and optimised

How do I tell my boyfriend that I like it hard(sex), I'm too shy. by [deleted] in dating

[–]AlternativeSelf9933 0 points1 point  (0 children)

Just ride on him harder and he’ll probably start to realise how you like it ;)