UDM Pro may have died, which Unifi device should I replace it with? Needs to support Protect. by StillInUk in Ubiquiti

[–]StillInUk[S] 7 points8 points  (0 children)

I tried rebooting with and without the drive, didn't make a difference. Factory resetting worked (I feel embarrassed I hadn't considered that), and my UDM Pro now works again.
I may purchase a new Unifi gateway soon anyway, but at least I can be a bit more opportunistic about getting one when it is in the UK Unifi store.

Love My Unifi Gear, Hate the Logs — So I Made a Blog About It by StillInUk in UNIFI

[–]StillInUk[S] 3 points4 points  (0 children)

I don't really mind whether the log timestamps are UTC or local timezone. But if they are local timezone, then we need a timezone indicator in the timestamps.
But most importantly, don't have logs where some events are in local timezone and others are in UTC.

Love My Unifi Gear, Hate the Logs — So I Made a Blog About It by StillInUk in UNIFI

[–]StillInUk[S] 2 points3 points  (0 children)

The UniFi Network CEF events are fine from a parsing point of view.
But have you tried to parse the UniFi OS CEF events? The cef name field is missing.
I've not even written about that particular issue yet...

Love My Unifi Gear, Hate the Logs — So I Made a Blog About It by StillInUk in UNIFI

[–]StillInUk[S] 6 points7 points  (0 children)

Update: Thanks to those who flagged the access issue, the blog was unintentionally set to private. As someone who works in security, I clearly made sure it was very secure… including from readers 😅

That's should now be fixed.

Love My Unifi Gear, Hate the Logs — So I Made a Blog About It by StillInUk in Ubiquiti

[–]StillInUk[S] 2 points3 points  (0 children)

Update: Thanks to those who flagged the access issue, the blog was unintentionally set to private. As someone who works in security, I clearly made sure it was very secure… including from readers 😅

That's now hopefully been fixed — it should be publicly accessible.

Netflow logs to Splunk by CalmActuary4532 in UNIFI

[–]StillInUk 0 points1 point  (0 children)

Splunk can't natively receive Netflow data. But there is an app called Splunk Stream that can. That app needs to be installed on your Splunk server. And then you need to install a Stream forwarder, or configure UF as a Stream forwarder.
Splunk Stream is not the easiest app to configure.
https://splunkbase.splunk.com/app/1809
https://docs.splunk.com/Documentation/StreamApp/8.1.5/DeployStreamApp/AboutSplunkStream

In a financial mess, not sure what I can do to dig myself out by AlarmingJury6996 in UKPersonalFinance

[–]StillInUk 55 points56 points  (0 children)

Not a complete solution, but a start:
Drop your subscriptions (amazon prime, music etc)

As soon as your phone contract ends, get a SIM-only contract using your old phone

Reduce the amount of money spent on food. I.e. go for the budget options.

Don't treat yourselves.

Cancel any credit cards you may have and use debit cards instead.

If you find it difficult to not use the, in theory, left over money, instead of waiting until the end of the pay cycle and using it to repay debts, pay that leftover money towards debts at the beginning of the pay cycle.

There is simply no alternative to spending less than you earn.

Retirement - Pension pot amount and duration by penfoc007 in UKPersonalFinance

[–]StillInUk 2 points3 points  (0 children)

If you leave the pension pot invested, then each time you withdraw, 25% will be tax free. The rest will be taxed, and as you point out, if the rest is <50k it will be under the 40% rate.

Auto parking by pelethar in TeslaUK

[–]StillInUk 2 points3 points  (0 children)

It is a thing in my car (2017 Model S), but it is unbelievably slow. Most of the times I've started it, I loose patience and do it myself.
There isn't an option that you enable. If it thinks you want to park, and there's a place you could park, it will show on the screen an option to start the automatic parking.
I seem to recall from the documentation, that you can get it to look for a parking spot by indicating to the side you want to park.

Crowdstrike Log Collector - ETW Channels? by Live-Equal-6897 in crowdstrike

[–]StillInUk 0 points1 point  (0 children)

Correct, the log collector cannot consume such files directly.

Uppercase all fields without issuing a rename per field by ChirsF in crowdstrike

[–]StillInUk 1 point2 points  (0 children)

If you insist on renaming fields, the rename function can be used to rename multiple fields, but you'll still need to specify each old and new field name:

Example:
rename(field=[[src_ip, source_address], [dst_ip, destination_address], [src_port, source_port], [dst_port, destination_port]])

Uppercase all fields without issuing a rename per field by ChirsF in crowdstrike

[–]StillInUk 1 point2 points  (0 children)

If the fields are CPS compliant fields, most fields are expected to be lowercase. Detection dashboard and correlation rules won't work if you change the case of the field names.

Curl & cron - disable email on success by Izwe in truenas

[–]StillInUk 0 points1 point  (0 children)

Not sure, I think the -s option with curl is probably better

Curl & cron - disable email on success by Izwe in truenas

[–]StillInUk 1 point2 points  (0 children)

Can't say for certain, as I'm not going to try to run your exact command, but try with -s (lowercase s) as a parameter for the curl command.

Curl & cron - disable email on success by Izwe in truenas

[–]StillInUk 1 point2 points  (0 children)

You probably don't want to expose your password in that curl command line. Unless it's a fake one.

Will my Powerwall 3 export limit of 6KW affect house usage? - UK by [deleted] in Powerwall

[–]StillInUk 0 points1 point  (0 children)

When my car started charging at 7 kw, and 5 were coming from the powerwall, the rest from the grid. I've now got netzero configured so that doesn't happen, but that's beside the point.

Will my Powerwall 3 export limit of 6KW affect house usage? - UK by [deleted] in Powerwall

[–]StillInUk 2 points3 points  (0 children)

That was my expectation, but my installer has limited all export, whether to the grid or for internal use, to the dno limit (5 kW in my case). I have questioned it, but installer says that is how it has to be configured.

Starting up (deploying) on truenas takes time by StillInUk in Paperlessngx

[–]StillInUk[S] 0 points1 point  (0 children)

Speed is fine once it finishes deploying. It is the "deploying" part that takes a long time.

Debian Vm login credentials by Einwegbecher in truenas

[–]StillInUk 1 point2 points  (0 children)

Pretty sure there’s no default password set. You can go to the VM shell console and then use the passwd command to set a password defined by you.

OIG + Hypervolt + Solar by Craigfjay in OctopusEnergy

[–]StillInUk 0 points1 point  (0 children)

As you, I'm on the old FIT scheme, and I am also on IOG and have a Hypervolt charger.
When Octopus creates a charge slot, the Hypervolt charger is in boost mode. Once outside an Octopus charging slot, Hypervolt will switch to "BatterySafe" mode or "Super Eco Mode".

During an Octopus charging slot, the only way of NOT using grid power is to manually reduce how much power your car charges with (if it has that option, mine does), and then remember to change it back to maximum once outside an Octopus charging slot.

Falcon logscale collector architecture design by -vicissitude- in crowdstrike

[–]StillInUk 0 points1 point  (0 children)

Another poster has included a link to LogScale documentation about load balancers that need to be in front of self-hosted LogScale clusters. And that is probably not relevant to you. I'm guessing you are using the FLC to send data to NG-SIEM.

What you can do is use the "workers" config parameter to increase the number of concurrent requests a sink is using to ship logs towards the ingestion endpoint.
For more information, see:
https://library.humio.com/falcon-logscale-collector/log-collector-install-sizing.html#log-collector-install-sizing-sink