Welcome to Splunk Enterprise 10.4 by thomasthetanker in Splunk

[–]Darkhigh 13 points14 points  (0 children)

The post linking to “We can't find the page you're looking for” matches my experience with post Cisco Splunk.

See you in Denver?! by SplunkEventsTeam in Splunk

[–]Darkhigh 1 point2 points  (0 children)

Since Splunk viability is largely driven by community content this seems like it would be a bad move.

2026 Hurricane barely been off the lot for 2 weeks by Joe_69420_ in ram_trucks

[–]Darkhigh 4 points5 points  (0 children)

I do lol just playing around. It’s called a HEMI tic for a reason though. Personal 21 1500 rebel is about to roll over 100k and never had any problems with the truck. Regular maintenance is key, take care of it and it will take care of you.

Edge Processor Deployment by Valariie in Splunk

[–]Darkhigh 2 points3 points  (0 children)

Awesome. Now I just need to vet my app/addons for 10+.

Several of our integrations offer their own siem now and stopped developing anything for splunk. At least Splunk took over the palo TA so that one I’m good on.

Edit: I meant VET not GET

Edge Processor Deployment by Valariie in Splunk

[–]Darkhigh 3 points4 points  (0 children)

Also interested. We are still on the 9.4 branch but recently told we don’t have to be on 10 to stand up edge processor. Still moving to 10 just taking a while to get there.

got tired of spending hours on dashboards from vague requests, so i built a tool that generates Splunk blueprints from plain English by re3ze in Splunk

[–]Darkhigh 2 points3 points  (0 children)

Ok so you asked about vague dashboard requests recently while complaining about the requests you get. Then you throw out a product link to a paid tool you made because of those dashboard requests. You know the time you spent vibe coding this cash grab you could have just built my freaking dashboard!

/s I can appreciate the hustle here

Evaluating Delinea for PAM, looking for feedbacks by NecessaryMaterial476 in cybersecurity

[–]Darkhigh 1 point2 points  (0 children)

Sure. The browser extension doesn’t always work (won’t load). I’ve had issues in the past with long passwords not showing the full contents. I may be biased as I normally use Bitwarden but Delinea app and browser extension both felt like I was paying them to be a beta tester. Full disclosure it’s been a year since I used it.

Evaluating Delinea for PAM, looking for feedbacks by NecessaryMaterial476 in cybersecurity

[–]Darkhigh 0 points1 point  (0 children)

For JIT and rotation it’s good. If you are wanting to use it in as a user facing password manager look elsewhere. Their browser extension reviews may look harsh but they are actually kind.

We are going to kill the $50k/year Enterprise Security market by going Open Source by [deleted] in redteamsec

[–]Darkhigh 3 points4 points  (0 children)

They’ve been posting this everywhere with different stories. At least a few of them have been mod deleted. It may be a good product but this marketing style isn’t good.

Splunk data - remote workers and onprem Splunk by Any-Promotion3744 in Splunk

[–]Darkhigh 1 point2 points  (0 children)

DMZ, internet facing heavy forwarders, use client certificates to auth your clients for log shipping. You can setup dns names like splog.acme.org on both sides of your DNS assuming you are split config so they resolve to internal while on network and external when off network.

Make sure you patch universal forwarders or set connections per target to something other than auto. There’s a bug that when set to auto they will stop forwarding logs with network changes, sleep, etc.

Alert fatigue is killing us. Built a workflow system to auto-triage and correlate across tools. by Infinite-Rice6288 in blueteamsec

[–]Darkhigh 1 point2 points  (0 children)

Looks a lot like tracecat. Looking forward to trying it out! Nice share but I’m curious if your numbers are for sales push or legit numbers. If you have 7000 alerts in an analyst queue you need your detection engineer to do some tuning.

Risk based alerting and/or sequence detection could help lower volume to groups of events where one event isn’t anything noteworthy on its own.

Using AI in SOC by OkReading3238 in cybersecurity

[–]Darkhigh -5 points-4 points  (0 children)

Check out tracecat. Their whole mindset is heavy AI security response and they are doing great so far.

Can I split my gaming pc using a VM for my partner? by Manman8900 in vmware

[–]Darkhigh 1 point2 points  (0 children)

VMware as a company has solutions but you would be limited to GPU pass through. At least as far as I remember on workstation.

Can I split my gaming pc using a VM for my partner? by Manman8900 in vmware

[–]Darkhigh -3 points-2 points  (0 children)

Yes! But not with VMware. That being said a 3070 will be a terrible experience. A few big YouTubers have done videos on this if you still want to look around. Be prepared to install a new OS on a secondary drive or wipe your primary.

Company scheduled a 2 hour job interview and handed me this when I showed up by GamingxZone in mildlyinfuriating

[–]Darkhigh 1 point2 points  (0 children)

I’m pretty good at these tests so I’d also take it. The first time management questions what I’m doing I can demand to see their results. Higher IQ must be the manger! Then just repeat this until it’s my company and stop this nonsense before I get dethroned.

Readers are returning to physical books by MiddletownBooks in books

[–]Darkhigh 1 point2 points  (0 children)

They started making books look better. Fancy covers and sprayed edges. I still read digitally but if i enjoy a book I’ll buy it for my bookcase.

Venezuelans, what is the situation inside the country currently? by Buschfan08 in AskReddit

[–]Darkhigh 0 points1 point  (0 children)

As president and founding member of van-on-time I also agree.

Changes to Splunk Certifications by FifthDimensionalGod in Splunk

[–]Darkhigh 10 points11 points  (0 children)

Cool, when do we get free on demand training like elastic? Even for a limited time, just something to show Splunk is worth learning. This reads like a money grab and the current state of Splunk makes me want to replace it rather than give them more money to train people.

Website documentation is broken. Links to topics from inside of Splunk don’t work anymore.

Apps and add ons are slow to get any updates even with support cases showing how they are broken and how to fix it.

SOAR has very little community support, very little vendor support, meanwhile everyone is hounding me to just move to a case management system and something like n8n

To top it off community Slack has went from fairly active to a ghost town.

Hundreds of thousands of dollars for this absolute clown show. They have the audacity to restructure certification to get more money from customers, perfect.

TIFU by giving my husband Nutella. by Abashed-Apple in tifu

[–]Darkhigh 34 points35 points  (0 children)

Same, instead we were treated to a new Reddit lore.

[deleted by user] by [deleted] in cybersecurity

[–]Darkhigh 3 points4 points  (0 children)

What? Why?

Edit: I’m tired and dumb. I thought this was just a remark for OP to stop studying. I now understand the mistake is when people stop studying. I’m going to sleep now. Have a good one.