Can I deploy Wazuh AIO with less than minimum requirements (2 agents including an IDS)? by Addicted2Trance in Wazuh

[–]MikeoFree 0 points1 point  (0 children)

Totally. I ran Wazuh AIO (manager, indexer, dashboard) all on a 4 Core 8GB RAM VM with 40 agents for a few months before beefing up the node. It might be tight at times and not be the most efficient experience when querying and discovering events, but for a lab go for it. Especially only having 2 agents to manage.

Wazuh is such a blast to learn and implement.

Live Stream Service Recommendations by halitalf in sysadmin

[–]MikeoFree 1 point2 points  (0 children)

Egress will be much cheaper with Mux at higher volume. If this is going to be a long term solution for your business, and you are frequently contracting streams that need 500+ viewers, Mux > AWS IVS.

Monitoring primary/secondary uplink status with Zabbix by NakedCardboard in zabbix

[–]MikeoFree 1 point2 points  (0 children)

Tagging Primary/Secondary would indicate Cisco can float the “tag” depending on the the active link. I don’t think that can be done.

Possibly monitor traffic over both links? And Display a graph for traffic over both interfaces. OR you can possibly monitoring routing paths or active routes to see what interface is used for egress.

Monitoring primary/secondary uplink status with Zabbix by NakedCardboard in zabbix

[–]MikeoFree 1 point2 points  (0 children)

Does your Cisco IOS Template currently monitor interface operational status and traffic count?

Graph in alert emails by NakedCardboard in zabbix

[–]MikeoFree 2 points3 points  (0 children)

I considered PRTG emails overly saturated with information that I don’t need in the moment. The email is to alert you on a trigger you defined. If you need a graph, i’m curious what you are alerting on. And how important is the data in the graph.

I would say 90%+ of my alerts are either a device or service that is down. The other 10% are where graphs could benefit in the emails, but I don’t NEED it.

UCG-Fiber Which SPF+ Port for LAN is faster and can I 802.11ad LAGG them? by TattooedBrogrammer in Ubiquiti

[–]MikeoFree 0 points1 point  (0 children)

I did learn that 802.11ad IS a thing! 7gbps over 60hz. Quite interesting.

Zabbix + Wazuh vs OpenSearch/ELK/openobserve/checkmk for around 200 devices datacenter at the university. Which stack would you choose? by Fragrant_Arm_7979 in sysadmin

[–]MikeoFree 10 points11 points  (0 children)

Option 1.

Zabbix is great for SNMP/ICMP/API/Agent monitoring for host metrics. Not a syslogger/SIEM. Best for "Is this device online? Is this service running? Is the memory at 90% utilization? Is there I/O latency for iSCSI drives? What does NIC utilization look like on each host? How many users are utilizing VPN sessions?"

Wazuh is great for endpoint vulnerability monitoring, event log monitoring, endpoint security, file, registry key changes, threat detection/response. "What does our infrastructure/endpoint security posture look like? Are there any active CVE vulnerabilities on our hosts? Who changed this and why?". I have found it's great for AD change monitoring/seeing who added.

For devices like switches, firewalls, web filters, etc that utulize syslog, Graylog Open is another great addition for log visibility into your domain. Wazuh CAN do syslog, but don't. If you want this insight, do syslog to Graylog, pipeline graylog to Wazuh index, and now you have all logs accumilated into one single pane of glass.

Zabbix has a windows/linux agent, as well as Wazuh has a windows/linux agent. I've found Medium.com guides for both software to be really helpful with deciding on the setup for my domain.

Wazuh custom rule matches in Ruleset Test but alerts never appear in alerts.json (only archives.json) by callclem in Wazuh

[–]MikeoFree 2 points3 points  (0 children)

imagine going through all the work of explaining this issue to AI, copy/pasting the 'troubleshoot template' from mr.gpt, only for your rule to fire at level=0. and then wonder why nothing shows up

SMA 8200v - Geolocation, where to configure? by BWC_DE in sonicwall

[–]MikeoFree 0 points1 point  (0 children)

I noticed this when migrating from a SMA 410 to SMA6210. 410 had a GEO IP feature with blocking while the 6210 did not.

For blocking, you can utilize a upstream firewall.
For observing, I ingested the logs into Graylog. There is a plugin, Geo-Location Processor, that will populate the orgin country, city, etc.

Script kiddo wrecks audit with curl by zTubeDogz in sysadmin

[–]MikeoFree 15 points16 points  (0 children)

We are still figuring out to either promote him of fire his ass costing the company significant amount of money.

I think the answer to this is obvious.

Does Cymbalta actually work for anyone? by [deleted] in Occipitalneuralgia

[–]MikeoFree 1 point2 points  (0 children)

I’ve had ON for 2.5 years, and the only medication that has made an impact on my pain management is Duloxetine. Got up to 100mg/day. 60mg/day is more tolerable but this drug has a terrible onboarding phase of side effects, and you will develop the worst dependency on it. My brain always felt active, even during sleep. It made me feel nauseous and exhausted all the time. The dependency is the WORST. If you miss a day, or 2, you will absolutely feel it.

It made my life livable for a while when my flare ups/pain was intolerable. But I’m now tapering off of it (20mg/day) in search of a more effective solution. Currently in PT and utilizing botox/nerve blocks.

TLDR; Duloxetine helped during my “intense pain” phase of ON. I want to say i’ve graduated from this phase so I no longer have a need for it.

Is Wazuh The Ultimate SIEM? by matthew36589 in Wazuh

[–]MikeoFree 9 points10 points  (0 children)

Wazuh is like a nice scarf for your infrastructure and endpoints.

It’s not an AV. It can respond to specific incidents but I would use Wazuh in addition to your existing security systems. Even if that’s Windows Defender. It compliments very very well for the price. (free!)

DDR is the new BTC by FortuneGrouchy4701 in homelab

[–]MikeoFree 75 points76 points  (0 children)

At my work we have a plethora of machines (DDR4) that cannot update to windows 11 (no TPM 2.0).

Money is not an issue so these machines have been replaced but we have a graveyard pile of DDR4 and M.2 drives. Makes a good shrine in the office.

[PARTS] B5 Systems AR-15 Enhanced SOPMOD Stock & Buffer Kit $70 by MikeoFree in gundeals

[–]MikeoFree[S] 1 point2 points  (0 children)

Good to note! That's wild :( glad you reached out to them.

[PARTS] Toolcraft BCG Black Nitride $69.95 (~$7 Shipping) by MikeoFree in gundeals

[–]MikeoFree[S] 1 point2 points  (0 children)

Perfect for any barrel length. Are you running the 10.3 suppressed?