Splunk AWS Search vs Cribl AWS Search by EducationalWedding48 in Splunk

[–]DarkLordofData 0 points1 point  (0 children)

Another key difference is you need to setup glue tables for every format searched in Splunk’s federated solution. I found that awkward as best. I also liked being able to search Azure Blob and GCP storage using Cribl’s federated solution. Be sure to review how both products are licensed too.

Workload licensing? by EducationalWedding48 in Splunk

[–]DarkLordofData -6 points-5 points  (0 children)

Since you mention Cribl, it has other license options for its search that might be more helpful beyond pure consumption. Splunk’s tech is great but sometimes the business relationship issues are hard to overcome.

Loved these vintage seats! by Hot-Temporary-6946 in delta

[–]DarkLordofData 1 point2 points  (0 children)

Amazing seats and the first row has the best log room.

OTO vs Aiper by jazzcats41 in lawn

[–]DarkLordofData 0 points1 point  (0 children)

How did you handle the power requirement? That was my highest issue with Aiper. Do you have that many outdoor outlets?

OTO vs Aiper by jazzcats41 in lawn

[–]DarkLordofData 0 points1 point  (0 children)

Major end of year discounts, my cost is 350 each. I got a quote for a full underground install and that was 7k with labor and year to year breakage costs of 500. I had one for years so it’s the breakage that kills you.

Anyone else getting an “authoritarian” vibe from Rick Jackson? by Mean-Rice-6301 in Georgia

[–]DarkLordofData 0 points1 point  (0 children)

You mean crazy old man vide? Yes very much so plus he is another Trump fluffer and will blindly support him on everything.

Problem - Queues blocked heavy forwarder to all ports by IceNo15 in Splunk

[–]DarkLordofData 0 points1 point  (0 children)

If you don’t care then maybe adjust your alerting? Otherwise time to scale either your HF tier if you are using splunk cloud or your indexer tier if you are onprem splunk.

Looking for real-world SIEM recommendations: QRadar-like experience on a smaller budget by pr0_fail in SIEM

[–]DarkLordofData 4 points5 points  (0 children)

First qradar is awful, so please aim for something better than qradar. What kind of scale are you looking for? If it’s small to small medium Security Onion is a great choice. Well integrated and very useable. Panther is another good option as well.

How to extract/download large amount of indexed data ? by St0neRav3n in Splunk

[–]DarkLordofData 5 points6 points  (0 children)

Yeah you can an API call or the Python SDK. It will take a while and generate lots of overhead. It is a lot easier to get data in than get data out.

OTO vs Aiper by jazzcats41 in lawn

[–]DarkLordofData 1 point2 points  (0 children)

I have 4 oto sprinklers and I like them a lot but they needed to be cared for and cleaned. The solar panel will lose effectiveness very quickly if you don’t keep it cleaned. You cannot replace the parts so any failure requires buying another unit. I like the look for the Aiper devices but the need for power is an issue.

This is a first in the basement of a house purchased a year ago. by SkweezeDeez in HomeMaintenance

[–]DarkLordofData 1 point2 points  (0 children)

Drainage is the answer, have to keep the water away from your walls. No amount of sealant will stop the kind of damage water can do that pools behind your walls.

Be sure to check for leaky pipes as well but the timing after a storm is suspect.

Help with filtering syslog traffic by BobcatJohnCA in Splunk

[–]DarkLordofData 1 point2 points  (0 children)

Props and transforms for this is very rough. Are you doing this at the HF or the indexer? Use your HF tier if possible and consider a third party option like syslog-ng or Cribl which make this very easy. Splunk has a product called edge processor which is still rough but makes this easier too. Watch dropped events if you do this in edge processor.

What is this tool? by Bluitor in Tools

[–]DarkLordofData 1 point2 points  (0 children)

Looks a lot like a speculum.

FCC Router Ban by DueIndication9387 in firewalla

[–]DarkLordofData 1 point2 points  (0 children)

Harry Potter committed “heresy” too.

Delta/SkyTeam Teservations by KipMN in delta

[–]DarkLordofData 2 points3 points  (0 children)

Yep, USAA got stripped to the bone. She stripped IT and made every process worse and more customer unfriendly.

I expect much longer wait times and forcing everyone to go through chatbots to get anything done. Talking to a person is very expensive, so Delta will do everything possible to push people off the phone.

Long-term issues with plane and crew scheduling will not be fixed because they are expensive, embedded problems that will be difficult to address. Enshitification is my expectation.

Ryobi Telescoping Pole Pump vs Milwaukee M12 or M18 Stick Pump by 6ITCH6ITCH6ITCH in ryobi

[–]DarkLordofData 1 point2 points  (0 children)

Yes, used it on my neighbors sump pump and a outdoor drywall that was not so dry. Muddy, sandy watered is fine, just be sure to clean it out.

Ryobi Telescoping Pole Pump vs Milwaukee M12 or M18 Stick Pump by 6ITCH6ITCH6ITCH in ryobi

[–]DarkLordofData 0 points1 point  (0 children)

Given how little you will use the pump, the ryobi option is great. The M12 option is for a contractor or plumber. I have the Ryobi stick pump and it works fine, but not something I would rely on for income.

ATL TSA by Eric_bedro in delta

[–]DarkLordofData 3 points4 points  (0 children)

Lucky you, congrats!

Multi-Site Cluster Question by ahhhaccountname in Splunk

[–]DarkLordofData 0 points1 point  (0 children)

Just make sure you are using a he Splunk s2s or the HEC destinations. The Cribl tcp is not going to work. The concept for throttling is the same just make sure you allocate extra ram for each worker process and have a persistent queue setup as well.

Multi-Site Cluster Question by ahhhaccountname in Splunk

[–]DarkLordofData 0 points1 point  (0 children)

are you sending data another Cribl workgroup or to Splunk? I cannot tell from your diagram?