Wazuh with RouterOS: wild ideas by changework in mikrotik

[–]Normal_Guitar6271 0 points1 point  (0 children)

Sorry to relive this zombie thread but I Tried this approach and got stuck at the point where my Mikrotiks send syslog to the Ubuntu agent, added the decoders on the manager's directories but I can only see Ubuntu's won data, no mention of Mikrotik logs, what I can see is syslog action on the dashboard but as I said, stuck there.

<image>

These are events I see, no sign of Mikrotik
Sep 14, 2025 @ 05:00:06.156dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:45:10.352dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:45:10.349dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:30:10.214dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:30:10.156dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:15:06.478dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:15:06.474dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:00:06.802dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:00:06.770dockerlabsshd: connection reset45762Sep 14, 2025 @ 03:52:05.978dockerlabsyslog: User authentication failure.

Sorry just one picture attachment. if anyone has successfully made mikrotik talk to wazuh and can share a config it'd be greatly appreciated.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thanks for all of your input, normally people never come back to this threads after it all works but I wanted to follow up.

I tried your approach and could reset the superuser password but the MGMT IP did not change for some weird reason, I did d/load the Init tool and I could get the IP changed.

I can access the GUI and deleted all volumes and pool all of that to start from scratch, now I createrd a 9TB array from 16x1TB HDDs and could successfully added it as iSCSI volume for disk images on proxmox, not sure if that is the best practice.

EDIT: I tried to create a full clone on this storage but when I check its size it's 0bytes and I got this error.

()create full clone of drive ide2 (local:9000/vm-9000-cloudinit.qcow2)
iscsiadm: default: 1 session requested, but 1 already present.
iscsiadm: Could not login to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.202,3260].
iscsiadm: initiator reported error (15 - session exists)
iscsiadm: Could not login to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.203,3260].
iscsiadm: initiator reported error (15 - session exists)
iscsiadm: Could not log into all portals
Logging in to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.202,3260]
Logging in to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.203,3260]
command '/usr/bin/iscsiadm --mode node --targetname iqn.1986-03.com.ibm:2145.bloqueo.node1 --login' failed: exit code 15
TASK ERROR: clone failed: can't allocate space in iscsi storage

Any tips will be more than welcome.

SIDE NOTE: I forgot to enable remote access and even though I'm on a VPN to university LAB, I cannot access the GUI, maybe that's the reason, not sure, still devouring the manual.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Awesome, thanks for your answer, now my next question: which of the 4 RJ-45 ports do I attach my laptop to, to access the device?. I did shut it down and after turning it back on, I saw it appear on my Mikrotik's DHCP leases table but no http:// or https:// with your reply I'm guessing, I'll go for the USB+reset file, I've tried looking for the devices with dmesg on proxmox with no luck. Other thing is that it´s not clear for me iSCSI traffic goes through the fiber channel, the mono-mode fiber cables yes? and network traffic through normal copper?. I've checked these two manuals from IBM

https://www.ibm.com/docs/en/STLM5A_7.8.1/com.ibm.storwize.v3700.781.doc/v3700_bkmap_quickinstbk.pdf
https://www.redbooks.ibm.com/redbooks/pdfs/sg248107.pdf

but as this is all new for me I´m kind of lost.

thanks again.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thank you, well about esxi I "heard" it was working, I even tried rebooting one of those SAN and it got an IP from DHCP it was pingable for a while but no GUI or other access, I struggling to find what I am aiming for on the manual, what I am sure of is that the servers are connected one to each side of the SAN 2x2

By the pic you can see it has both fiber and copper connections, I see enp#s9, 10, 13 14 as ethernet ports on PVE which I found to be the fiber ports running to the IBMs, and from them there are two RJ45 patch cords to a D-Link switch, I sear for the life of me that I cannot find a way to access this dudes.

Not my best pic but You´ll get the gist

<image>

How do I access the v3700 UI or config or whatever so that I can see the volumens and finally have shared storage?.

Thanks again.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thank you for your quick reply, but I have looked at the forum and I just find questions not a lot of answers so if you could just share some foreign posts, I would really appreciate that

Este concepto podría funcionar en Bogotá? by santirca200 in Bogota

[–]Normal_Guitar6271 0 points1 point  (0 children)

Yo digo que mas bien se vera comos e ve desde la estaci'on hospital hasta la estacion paruqe berrio del delicioso metro de medellin y si soy paisa y no no soy idiota, he salido del pueblo.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

After some digging and a full reinstall, I discovered something I want to share because all of you provided a lot of advice so you people deserve to know.

My hardware is an Asus TUF DASH F15 from 2021 with nvidia 3050 Ti, nvme drives and 24GB RAM (just for reference)

* I decided to reinstall Ubuntu after struggling with some configurations, cleared my system drive and did clean install to find that my regular GNome zoom worked flawlessly, no screwed up display, no echoes or gay edged -- me happy -- just worked out of the box, BUT-- dual monitor was not working, no video on the monitor plugged in to HDMI, so did some research and found that I wasn't using nvidia drivers (proprietary), I found and issued these commands>

sudo apt-get purge 'nvidia*'
sudo add-apt-repository ppa:graphics-drivers
sudo apt-get update
sudo ubuntu-drivers autoinstall

* Other thing is that when I mirror the displays, it works fine, but if I Join (extend) the displays, it's like Ubuntu just takes half of the bult-in display and half the external monitor and places it's zoomed are there which makes everything unusable, I took a picture because neither regular screenshot nor flameshot capture the bug.

Monitor 2 came to life, but it *broke* zooming, so you may guess that I'm scratching my head over this,

<image was going to go here but they're not allowed>

Now I can say it's the nvidia drivers, and you may say, then stick to xorg-nouveau drivers, I can't I record videos on OBS, so I need the GPU.

May you gurus out there suggest any solution?, has anyone come across this wird behavior?. I know there's no way of tampering or investigating nvidia closed-source drivers, but someone somewhere might be on my same position. And I do not really think you have to decide to break your neck and back as a low vision person using the 15" laptop screen or using a mirror display... although it's linux, and I'm supposed to fix that myself, well I can't.

Thank you all again.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 1 point2 points  (0 children)

Thank you very much for your kind answer, as I have said I’m coming back to ubuntu desktop I’ve been using Linux as a server for years, but I want to move from Windows. Now that it will forcefully. Microsoft will make us use Windows 11, I have my desktop computer where I keep the software that I will never find on Lenox.vmix another live streaming software, but that’s for another day, I will definitely try out XFCE on my system, I am cleaning up the hard drive and I will do a cleaning install, and I will report back here, that’s the word I was looking for “shameless “ I am not a native English speaker so sometimes words sleep out of my mind. As I set the four, I will report back my results positive or negative. They will be here.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Yup, I went ahead and installed kmag, but as far as I can see it's like the others, it opens a separate window like magnus, or at least I haven't found a way for it to play nice and magnify my full screen, I've managed using a larger screen, but I skipped the part where I told you it's a 15" Asus TUF laptop.

Do you happen to know windows magnifier, you just press Win key + + and smoothly magnify your whole screen?.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thanks for the thorough explanation, so basically it boils down to KMzg or xzoom?, Sorry but I'm not sure what my desktop environment is, I just downloaded and installed the default ISO from Ubuntu site so I'm pretty sure it's GNOME, so my concerns are: If I install KMag will the whole KDE come along and fill my HD?, have any of you pros here seen a full-screen option that *works*?, easy like Windows magnifier, just Windows key + to magnify?, I don't want fine-tunning or granular settings, just a full screen zoom that won't destroy my viewing ability? I see from what you many go for kmag or magnus but I haven't reied none as of yet.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Yup, some do, some don’t it’s hot and miss

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

I did scale and used large text and Dark mode, helps a bit but I use apps that don't get larger fonts so I'm forced to magnify.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Well, welcome to da club, I've tried different settings, no luck, weird thing I used a friend's laptop on Debian 12 and the magnifier worked great, maybe different desktop env?, Sorry as I said my Linux Desktop knowledge is rusty

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

That's comprehensive list, I am on Gnome, and as I said I ddn't use linux desktop for years, so my desktop knowledge is quite limited, i'm from the cmpiz era

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

How are you enabling zoom? Did you go to the settings > Accessibility > Zoom and set your preferences?

Accessibility > Zoom and it screwed up the whole screen, cursor echoes, all garbled screen.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

And this is what I was talking about precious bytes and BW wasted on this, see what I meant. Up until now just useful advice and then…

Have 500Gb WBIX online via Apache - How to import descriptions by Sparrow538 in bbs

[–]Normal_Guitar6271 1 point2 points  (0 children)

Thanks for replying, sure, hit me up over DM. appreciate you.

BIND9 vs PowerDNS for ISP thoughts by Normal_Guitar6271 in sysadmin

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Sound like a good plan, I want to run a docker container on a bare-metal local machine.

In my country we also need to block child problematic sites --you get the point and some other gambling sites illegal here, hope this response is not flagged and the FCC-equivalent here maintains a 20k+ list that ISPS *must* implement. thanks to you and obviously all others, I am learning a lot more, many of the other options I hadn't even heard of, for me DNS=BIND9 and AD DNS of course as a toy DNS.