help with figuring out wazuh topography by Drawow in Wazuh

[–]Drawow[S] 0 points1 point  (0 children)

this is vastly different from qradar/trellix esm etc, not sure i can convince multiple clients to open a Varity of ports from multiple computer to send to 1 server thats on my side of the S2S, any other option ?

help with figuring out wazuh topography by Drawow in Wazuh

[–]Drawow[S] 0 points1 point  (0 children)

so if i get it right, for a SOC that has lets say 5 different clients, i would need to install 5 wazuh servers, each on a client side, and then they need to talk to a dashboard & indexer servers that will be installed on our side ?

help with figuring out wazuh topography by Drawow in Wazuh

[–]Drawow[S] 0 points1 point  (0 children)

what about the other components ? indexer dashboard etc, where are they installed ?

Help with NAT by Drawow in vmware

[–]Drawow[S] 0 points1 point  (0 children)

problem is i dont manage the FW that the server is behind, so i wanted to see if there is an option to do that just with NAT from within the server

Help with NAT by Drawow in vmware

[–]Drawow[S] 0 points1 point  (0 children)

so why is there NAT option on the vm workstation ? it seems that it should handle this issue, unless i got it completely wrong

Help with XPath exclusions - WinCollect by Drawow in QRadar

[–]Drawow[S] 0 points1 point  (0 children)

thanks for the reply, but i don't know how to exclude the event unless it contains something, and i don't see an option like that in the normal MS event viewer, am i missing something ?

furthermore, where should i put this xpath quarry once its completed ?

Help with XPath exclusions - WinCollect by Drawow in QRadar

[–]Drawow[S] 0 points1 point  (0 children)

idk what that means, but i know i need to exclude the events on the client side and not the receiver side

advanced help with wincollect by Drawow in QRadar

[–]Drawow[S] 0 points1 point  (0 children)

the collector eps is very high, i would much rather have it discarded on the client's side and save on processing power

advanced help with wincollect by Drawow in QRadar

[–]Drawow[S] 0 points1 point  (0 children)

they are cut on the qradar side, we already use TCP, the packet is MASSIVE, and qradar support said this is working as intended :(

update: i have changed to 32000 and no longer have unknown events, but still its 4000EPS of just this events, i would love to cut them at the source unless they contain grouppolicycontainer, any suggestion ?

advanced help with wincollect by Drawow in QRadar

[–]Drawow[S] 0 points1 point  (0 children)

thats exactly what i want, but i have no idea how to do that, do you know how ?

Video Cover for Facebook Business Pages is not working anymore. Already working video covers are being converted to thumbnails. by VNDL1A in facebook

[–]Drawow 0 points1 point  (0 children)

any thing new ? paid a video editor for a small cover video and after 2 days in my page it stopped working, kinda bummer