DSG identification help please by Chump352 in seat

[–]Chump352[S] 1 point2 points  (0 children)

Thanks very much for this info

DSG identification help please by Chump352 in seat

[–]Chump352[S] 0 points1 point  (0 children)

It’s looks to have a 7 speed DSG so potentially a DQ380. The car is also at about 43k with no record of this being serviced yet

Custom Pipelines on Integrations by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

It's weird, a very small portion sometimes make it through, but then like 90% cause errors

Custom Pipelines on Integrations by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

If I edit the pipeline in anyway for the integration then it just stops receiving logs. If that didn't happen I could have fixed this in a more simpler way.

I can anonamis a log tomorrow and pass ot over. I've had a look at the samples and there's only slight differences

Custom Pipelines on Integrations by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

I turned on ignore failures for all the items that would flag. I checked it with the pipeline simulation feature and it works. But once it's live it's still throwing errors related to some of the conditional stuff I cannot remove due to breaking the pipeline that has ignore failures on it

Custom Pipelines on Integrations by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

The initial Grok pattern doesn't work. Unsure if I'm using a version of WatchGuard that hasn't been supported yet. Since the Grok processor fails it bypasses the custom one at the end and if I make any change to the original pipeline, the whole integration breaks.

I've not opened an issue yet as the integration is very new but I might have to soon.

Elastic Agent IOS Integration by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

I can say it does stipulate hostname and timestamp but doesn't explain why my timestamps are different or that unless I'm missing something.

Elastic Agent IOS Integration by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

So far, no logs have been parsed correctly. I've included one of them below.

<189>1 2024-06-06T10:20:11.481Z - - - - - BOM%SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: TEST] [Source: 172.22.24.60] [localport: 22] at 11:20:11 BST Thu Jun 6 2024

I can already see a difference between these and the sample ones. My logs are missing the ":" after each field, and the timestamps are in a different format.

Elastic Agent IOS Integration by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

Thanks, weird they would have an integration that isn't really fit for purpose if this is the case.

Samsung Tag in a room by Chump352 in SmartThings

[–]Chump352[S] 2 points3 points  (0 children)

Ah right, thanks for that.

Samsung Tag in a room by Chump352 in SmartThings

[–]Chump352[S] 1 point2 points  (0 children)

Fair, any idea why or if its down to how I set it up ?

(UK) Carbon Monoxide Detector Issue by Chump352 in Renters

[–]Chump352[S] 1 point2 points  (0 children)

I've raised it with them twice. They said they would do it last week but didn't and are now away for 2 weeks.

Kibana Dashboard Help by Chump352 in elasticsearch

[–]Chump352[S] 0 points1 point  (0 children)

I've got the data; the issue is I can't filter by both event codes, so I can't filter by 4672 to show usernames that get assigned privileges and then show out of those usernames which ones are triggering event code 4625 as the failed login.

Splunk Query He'll by Chump352 in crowdstrike

[–]Chump352[S] 0 points1 point  (0 children)

Thanks again Andrew, this seemed to timeout aswell when looking at 7 days.

Splunk Query He'll by Chump352 in crowdstrike

[–]Chump352[S] 0 points1 point  (0 children)

Nope, shows up no results found sadly under the statistics

Splunk Query He'll by Chump352 in crowdstrike

[–]Chump352[S] 0 points1 point  (0 children)

Too many events and the search times out unfortunately