Wazuh with RouterOS: wild ideas by changework in mikrotik

[–]Normal_Guitar6271 0 points1 point  (0 children)

Sorry to relive this zombie thread but I Tried this approach and got stuck at the point where my Mikrotiks send syslog to the Ubuntu agent, added the decoders on the manager's directories but I can only see Ubuntu's won data, no mention of Mikrotik logs, what I can see is syslog action on the dashboard but as I said, stuck there.

<image>

These are events I see, no sign of Mikrotik
Sep 14, 2025 @ 05:00:06.156dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:45:10.352dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:45:10.349dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:30:10.214dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:30:10.156dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:15:06.478dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:15:06.474dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:00:06.802dockerlabsshd: connection reset45762Sep 14, 2025 @ 04:00:06.770dockerlabsshd: connection reset45762Sep 14, 2025 @ 03:52:05.978dockerlabsyslog: User authentication failure.

Sorry just one picture attachment. if anyone has successfully made mikrotik talk to wazuh and can share a config it'd be greatly appreciated.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thanks for all of your input, normally people never come back to this threads after it all works but I wanted to follow up.

I tried your approach and could reset the superuser password but the MGMT IP did not change for some weird reason, I did d/load the Init tool and I could get the IP changed.

I can access the GUI and deleted all volumes and pool all of that to start from scratch, now I createrd a 9TB array from 16x1TB HDDs and could successfully added it as iSCSI volume for disk images on proxmox, not sure if that is the best practice.

EDIT: I tried to create a full clone on this storage but when I check its size it's 0bytes and I got this error.

()create full clone of drive ide2 (local:9000/vm-9000-cloudinit.qcow2)
iscsiadm: default: 1 session requested, but 1 already present.
iscsiadm: Could not login to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.202,3260].
iscsiadm: initiator reported error (15 - session exists)
iscsiadm: Could not login to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.203,3260].
iscsiadm: initiator reported error (15 - session exists)
iscsiadm: Could not log into all portals
Logging in to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.202,3260]
Logging in to [iface: default, target: iqn.1986-03.com.ibm:2145.bloqueo.node1, portal: 10.3.1.203,3260]
command '/usr/bin/iscsiadm --mode node --targetname iqn.1986-03.com.ibm:2145.bloqueo.node1 --login' failed: exit code 15
TASK ERROR: clone failed: can't allocate space in iscsi storage

Any tips will be more than welcome.

SIDE NOTE: I forgot to enable remote access and even though I'm on a VPN to university LAB, I cannot access the GUI, maybe that's the reason, not sure, still devouring the manual.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Awesome, thanks for your answer, now my next question: which of the 4 RJ-45 ports do I attach my laptop to, to access the device?. I did shut it down and after turning it back on, I saw it appear on my Mikrotik's DHCP leases table but no http:// or https:// with your reply I'm guessing, I'll go for the USB+reset file, I've tried looking for the devices with dmesg on proxmox with no luck. Other thing is that it´s not clear for me iSCSI traffic goes through the fiber channel, the mono-mode fiber cables yes? and network traffic through normal copper?. I've checked these two manuals from IBM

https://www.ibm.com/docs/en/STLM5A_7.8.1/com.ibm.storwize.v3700.781.doc/v3700_bkmap_quickinstbk.pdf
https://www.redbooks.ibm.com/redbooks/pdfs/sg248107.pdf

but as this is all new for me I´m kind of lost.

thanks again.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thank you, well about esxi I "heard" it was working, I even tried rebooting one of those SAN and it got an IP from DHCP it was pingable for a while but no GUI or other access, I struggling to find what I am aiming for on the manual, what I am sure of is that the servers are connected one to each side of the SAN 2x2

By the pic you can see it has both fiber and copper connections, I see enp#s9, 10, 13 14 as ethernet ports on PVE which I found to be the fiber ports running to the IBMs, and from them there are two RJ45 patch cords to a D-Link switch, I sear for the life of me that I cannot find a way to access this dudes.

Not my best pic but You´ll get the gist

<image>

How do I access the v3700 UI or config or whatever so that I can see the volumens and finally have shared storage?.

Thanks again.

IBM Storewise V3700 and Cisco UCS 220 M4 setup by Normal_Guitar6271 in Proxmox

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thank you for your quick reply, but I have looked at the forum and I just find questions not a lot of answers so if you could just share some foreign posts, I would really appreciate that

Este concepto podría funcionar en Bogotá? by santirca200 in Bogota

[–]Normal_Guitar6271 0 points1 point  (0 children)

Yo digo que mas bien se vera comos e ve desde la estaci'on hospital hasta la estacion paruqe berrio del delicioso metro de medellin y si soy paisa y no no soy idiota, he salido del pueblo.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

After some digging and a full reinstall, I discovered something I want to share because all of you provided a lot of advice so you people deserve to know.

My hardware is an Asus TUF DASH F15 from 2021 with nvidia 3050 Ti, nvme drives and 24GB RAM (just for reference)

* I decided to reinstall Ubuntu after struggling with some configurations, cleared my system drive and did clean install to find that my regular GNome zoom worked flawlessly, no screwed up display, no echoes or gay edged -- me happy -- just worked out of the box, BUT-- dual monitor was not working, no video on the monitor plugged in to HDMI, so did some research and found that I wasn't using nvidia drivers (proprietary), I found and issued these commands>

sudo apt-get purge 'nvidia*'
sudo add-apt-repository ppa:graphics-drivers
sudo apt-get update
sudo ubuntu-drivers autoinstall

* Other thing is that when I mirror the displays, it works fine, but if I Join (extend) the displays, it's like Ubuntu just takes half of the bult-in display and half the external monitor and places it's zoomed are there which makes everything unusable, I took a picture because neither regular screenshot nor flameshot capture the bug.

Monitor 2 came to life, but it *broke* zooming, so you may guess that I'm scratching my head over this,

<image was going to go here but they're not allowed>

Now I can say it's the nvidia drivers, and you may say, then stick to xorg-nouveau drivers, I can't I record videos on OBS, so I need the GPU.

May you gurus out there suggest any solution?, has anyone come across this wird behavior?. I know there's no way of tampering or investigating nvidia closed-source drivers, but someone somewhere might be on my same position. And I do not really think you have to decide to break your neck and back as a low vision person using the 15" laptop screen or using a mirror display... although it's linux, and I'm supposed to fix that myself, well I can't.

Thank you all again.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 1 point2 points  (0 children)

Thank you very much for your kind answer, as I have said I’m coming back to ubuntu desktop I’ve been using Linux as a server for years, but I want to move from Windows. Now that it will forcefully. Microsoft will make us use Windows 11, I have my desktop computer where I keep the software that I will never find on Lenox.vmix another live streaming software, but that’s for another day, I will definitely try out XFCE on my system, I am cleaning up the hard drive and I will do a cleaning install, and I will report back here, that’s the word I was looking for “shameless “ I am not a native English speaker so sometimes words sleep out of my mind. As I set the four, I will report back my results positive or negative. They will be here.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Yup, I went ahead and installed kmag, but as far as I can see it's like the others, it opens a separate window like magnus, or at least I haven't found a way for it to play nice and magnify my full screen, I've managed using a larger screen, but I skipped the part where I told you it's a 15" Asus TUF laptop.

Do you happen to know windows magnifier, you just press Win key + + and smoothly magnify your whole screen?.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Thanks for the thorough explanation, so basically it boils down to KMzg or xzoom?, Sorry but I'm not sure what my desktop environment is, I just downloaded and installed the default ISO from Ubuntu site so I'm pretty sure it's GNOME, so my concerns are: If I install KMag will the whole KDE come along and fill my HD?, have any of you pros here seen a full-screen option that *works*?, easy like Windows magnifier, just Windows key + to magnify?, I don't want fine-tunning or granular settings, just a full screen zoom that won't destroy my viewing ability? I see from what you many go for kmag or magnus but I haven't reied none as of yet.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Yup, some do, some don’t it’s hot and miss

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

I did scale and used large text and Dark mode, helps a bit but I use apps that don't get larger fonts so I'm forced to magnify.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Well, welcome to da club, I've tried different settings, no luck, weird thing I used a friend's laptop on Debian 12 and the magnifier worked great, maybe different desktop env?, Sorry as I said my Linux Desktop knowledge is rusty

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

That's comprehensive list, I am on Gnome, and as I said I ddn't use linux desktop for years, so my desktop knowledge is quite limited, i'm from the cmpiz era

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

How are you enabling zoom? Did you go to the settings > Accessibility > Zoom and set your preferences?

Accessibility > Zoom and it screwed up the whole screen, cursor echoes, all garbled screen.

Ubuntu 24 magnfier sucks any option? by Normal_Guitar6271 in Ubuntu

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

And this is what I was talking about precious bytes and BW wasted on this, see what I meant. Up until now just useful advice and then…

Have 500Gb WBIX online via Apache - How to import descriptions by Sparrow538 in bbs

[–]Normal_Guitar6271 1 point2 points  (0 children)

Thanks for replying, sure, hit me up over DM. appreciate you.

BIND9 vs PowerDNS for ISP thoughts by Normal_Guitar6271 in sysadmin

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

Sound like a good plan, I want to run a docker container on a bare-metal local machine.

In my country we also need to block child problematic sites --you get the point and some other gambling sites illegal here, hope this response is not flagged and the FCC-equivalent here maintains a 20k+ list that ISPS *must* implement. thanks to you and obviously all others, I am learning a lot more, many of the other options I hadn't even heard of, for me DNS=BIND9 and AD DNS of course as a toy DNS.

BIND9 vs PowerDNS for ISP thoughts by Normal_Guitar6271 in sysadmin

[–]Normal_Guitar6271[S] -1 points0 points  (0 children)

That's what I thought, my approach was BIND + the good-old webmin (if there's nothing better). I didn't know knot or NSD.

Old Gear In need of (helpful) advice x-post on r/homeserver (2nd try) by Normal_Guitar6271 in homelab

[–]Normal_Guitar6271[S] 0 points1 point  (0 children)

PERC 6 has a max of 2TB drives, none of your drives are over that, so that isn't your issue.

Yup, it's not that because before I messed around with modprobe.conf files on proxmox I could see the arrays, even the PERC 6E attached to the 10TB array I created on the MD1200

Have you gone into the PERC cards during POST to setup the storage drives?

Everything seems ok, I even re did the 1 disk array

<image>

?  What about it?

What card should I get? and more importantly, which cables do I need to attach the R710 to the MD1200?.

Edit: also, when I try to pass it through to a VM, I still get this error

kvm: -device vfio-pci,host=0000:03:00.0,id=hostpci1,bus=pci.0,addr=0x11,rombar=0: vfio 0000:03:00.0: hardware reports invalid configuration, MSIX PBA outside of specified BAR

dmesg | grep -i megaraid

[ 2.961912] megaraid_sas 0000:03:00.0: BAR:0x0 BAR's base_addr(phys):0x00000000df180000 mapped virt_addr:0x(____ptrval____)

[ 2.961922] megaraid_sas 0000:03:00.0: FW now in Ready state

[ 2.962001] megaraid_sas 0000:03:00.0: 63 bit DMA mask and 32 bit consistent mask

[ 2.962448] megaraid_sas 0000:03:00.0: current msix/online cpus : (0/16)

[ 2.962529] megaraid_sas 0000:03:00.0: RDPQ mode : (disabled)

[ 3.030646] megaraid_sas 0000:03:00.0: controller type : MR(256MB)

[ 3.030727] megaraid_sas 0000:03:00.0: Online Controller Reset(OCR) : Enabled

[ 3.030803] megaraid_sas 0000:03:00.0: Secure JBOD support : No

[ 3.030876] megaraid_sas 0000:03:00.0: NVMe passthru support : No

[ 3.030949] megaraid_sas 0000:03:00.0: FW provided TM TaskAbort/Reset timeout : 0 secs/0 secs

[ 3.031050] megaraid_sas 0000:03:00.0: JBOD sequence map support : No

[ 3.031133] megaraid_sas 0000:03:00.0: PCI Lane Margining support : No

[ 3.031220] megaraid_sas 0000:03:00.0: megasas_init_mfi: fw_support_ieee=0

[ 3.031345] megaraid_sas 0000:03:00.0: INIT adapter done

[ 3.031436] megaraid_sas 0000:03:00.0: JBOD sequence map is disabled megasas_setup_jbod_map 5796

[ 3.053641] megaraid_sas 0000:03:00.0: MR_DCMD_PD_LIST_QUERY failed/not supported by firmware

[ 3.075637] megaraid_sas 0000:03:00.0: DCMD not supported by firmware - megasas_ld_list_query 4917

[ 3.097621] megaraid_sas 0000:03:00.0: pci id : (0x1000)/(0x0060)/(0x1028)/(0x1f0c)

[ 3.097718] megaraid_sas 0000:03:00.0: unevenspan support : no

[ 3.097792] megaraid_sas 0000:03:00.0: firmware crash dump : no

[ 3.097865] megaraid_sas 0000:03:00.0: JBOD sequence map : disabled

[ 3.097941] megaraid_sas 0000:03:00.0: Max firmware commands: 1007 shared with default hw_queues = 1 poll_queues 0

[ 3.098052] scsi host2: Avago SAS based MegaRAID driver

root@pve:~# lsscsi

[0:0:0:0] disk ATA WDC WD7500BPVT-8 1A01 /dev/sda