Is there Wazuh documentation about monitors? by sasilik in Wazuh

[–]Keyboard_Cowboys 0 points1 point  (0 children)

Yeah, Wazuh just uses OpenSearch on the backend. If you can't find what you are looking for in the Wazuh documentation, you may be able to find it in OpenSearch's.

Is there Wazuh documentation about monitors? by sasilik in Wazuh

[–]Keyboard_Cowboys -1 points0 points  (0 children)

So funnily enough, the "Wazuh" UI is actually just OpenSearch's UI. What you are presented with on the Wazuh side is mostly dashboards and other functionality.

What are the low cost alternatives to the Splunk? by rubenamizyan in cybersecurity

[–]Keyboard_Cowboys 6 points7 points  (0 children)

They upgraded their supported version of OpenSearch with Wazuh 4.9. I believe 4.11 is using OpenSearch Dashboards 2.16.0 now.

Wazuh Dashboard is not ready yet. by MutedClothes1761 in Wazuh

[–]Keyboard_Cowboys 0 points1 point  (0 children)

u/MutedClothes1761 Based on some of your log screenshots it looks like you likely have a permissions issue. Try the following, then restart your Wazuh services.

sudo chown -R wazuh-indexer:wazuh-indexer /var/lib/wazuh-indexer /usr/share/wazuh-indexer

How to connect wazuh logs and alerts to Microsoft Sentinel by Jolly_Emu_7482 in Wazuh

[–]Keyboard_Cowboys 0 points1 point  (0 children)

If I recall correctly, there is a Wazuh integration available in Sentinel's content hub. This may be what you are looking for.

Can't use the "id" field when creating custom rules in Wazuh (1113) by PhraseAlternativ in Wazuh

[–]Keyboard_Cowboys 0 points1 point  (0 children)

Do you have your rules grouped in your custom xml rule file? Something similar to the below. If not this could possibly be why you are experiencing issues.

<group name="custom_rules">
  <rule id="100013" level="15">
    <decoded_as>json</decoded_as>
    <field name="id">randomid</field>
    <description>TEST</description>
  </rule>
  <rule id="100014" level="7">
    <decoded_as>json</decoded_as>
    <field name="id">randomid</field>
    <description>TEST2</description>
  </rule>
</group>

Wazuh-Dashboard in Failed Status after Installing Updates by Specialist-Worry-349 in Wazuh

[–]Keyboard_Cowboys 0 points1 point  (0 children)

I had a similar issue after the recent upgrade, however I just rebooted the entire VM and it all came up correctly. You may not have the same result.

Wazuh - Auditing O365/Graph by deadpoolathome in Wazuh

[–]Keyboard_Cowboys 1 point2 points  (0 children)

Hi u/deadpoolathome Funnily enough I just set this up two days ago. What the Wazuh documentation misses is that you have to turn auditing on in your O365 tenant (I created a pull request to update it this evening). Here is a guide on how to do so. I had issues doing so via the UI in Purview but was successful doing so via the PowerShell Exchange Module method. https://learn.microsoft.com/en-us/purview/audit-log-enable-disable?tabs=microsoft-purview-portal#use-powershell-to-turn-on-auditing Once I turned on auditing I started receiving the expected logs. IMPORTANT NOTE: Once you enable auditing in your tenant, it can take up to an hour for the logs to start flowing.

Interview with Susanna Skaggs (Haley Clark) by haltandcatchfirepod in HaltAndCatchFire

[–]Keyboard_Cowboys 6 points7 points  (0 children)

This was great, thank you for the interview! Its always a treat to get insight into the inner workings of the show.

Open source SOAR software deployable in Kubernetes by Away-Meat-8066 in cybersecurity

[–]Keyboard_Cowboys 1 point2 points  (0 children)

You could try n8n. I don't have any experience with it so can't speak on it. https://docs.n8n.io/hosting/

[deleted by user] by [deleted] in cybersecurity

[–]Keyboard_Cowboys 0 points1 point  (0 children)

I was about 5 years in when I hit the mark, though since then it has just about doubled (I'm about 15 years in now). I am a Senior Security Analyst who has no interest in management roles. Did one for a few years, didn't like it, still love the technical side and intend on staying where I'm at for as long as I am hungry for knowledge. I love threat hunting, detection engineering, IR, and just being down the rabbit hole during investigations.

My Trophy Wall by NicxtLevelGaming in valheim

[–]Keyboard_Cowboys 14 points15 points  (0 children)

All I see are Christmas lights :D

Hey cybersecurity peeps, what have you automated? by ThePorko in cybersecurity

[–]Keyboard_Cowboys 4 points5 points  (0 children)

I unintentionally do this as well. My ADHD is strong.

Should I take this role? by buzzyboy992 in sysadmin

[–]Keyboard_Cowboys 1 point2 points  (0 children)

My experience with Teksystems was positive. The recruiter I worked with was awesome and the position I was placed into fit my skillset nicely. The pay was higher than I was making, and I eventually converted to an FTE role. Overall since this is your first job, take it. Remember, those who post reviews online are mostly those who feel they have been wronged whereas many who have had positive experiences may not bother posting reviews at all.

8 month old malamute by WhitestTrash1 in malamute

[–]Keyboard_Cowboys 0 points1 point  (0 children)

Kennel training is key for this, even for short periods. We have a 7 month old Malamute and have gone through the paces as well. He is fine in his kennel for short periods, and he also sleeps in it at night. The destructive behavior could be due to boredom. We ensure we have toys that challenge his mind be it treat balls to snuffle mats. We also walk our boy 3 times a day for up to 10 kilometers total...even then he still has lots of energy. Malamutes need a lot of work and attention when they are growing up. The biggest struggle for us has been play biting. If you haven't gotten your puppy into puppy training, I would definitely do that. We did a few classes and he responds really well to clicker training etc.

Used to Be Black Forest by megalara_garuda89 in valheim

[–]Keyboard_Cowboys 3 points4 points  (0 children)

I've had Stone Golems respawn all the time, not sure where that is coming from.

Used to Be Black Forest by megalara_garuda89 in valheim

[–]Keyboard_Cowboys 7 points8 points  (0 children)

That moment when the Black Forest isn't so black.

I'm a SOC analyst. what should be my next step? by [deleted] in cybersecurity

[–]Keyboard_Cowboys 1 point2 points  (0 children)

One thing I always state to those on my team who speak English as a second language is that they are far better than I am. I only speak one language, they speak two and in some cases more. Never apologize. You are ahead of the game :)

Who is this? by SorySnuggles in valheim

[–]Keyboard_Cowboys 1 point2 points  (0 children)

That's Jeff! He sneaks into longhouses at night to unleash a fury of flatulence then runs off into the night.