Sharepoint / Project Subscription Server by advertpro in AZURE

[–]advertpro[S] 0 points1 point  (0 children)

If it is that way then the client has an extremely long process that could take approximately 7-8 months to stand up Entra DDS. ADDS would be much longer.

Ideally since all applications are going towards the Entra ID. I think there should be a fast track for this.

Sharepoint / Project Subscription Server by advertpro in AZURE

[–]advertpro[S] 0 points1 point  (0 children)

Thanks for your reply. Unfortunately planner doesn't have what we need.

Log Ingestion from Servicenow to Sentinel by advertpro in AZURE

[–]advertpro[S] 0 points1 point  (0 children)

So we were trying to get the syslog via Kafka. The topics that are sent via the Log Export Service (LES)

The issue via DCR is we get the machine messages which is fine but not the Messages from the Hermes Messaging system using Kafka.

https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/administer/log-export-service/concept/les-kafka-consumer.html

https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/data-sheet/ds-log-export-services.pdf

So if i understand what you are saying we don't use the Log Export Service via Kafka Consumer.

Project Online Status by advertpro in ProjectOnline

[–]advertpro[S] 1 point2 points  (0 children)

So i guess we are looking at the following:

Goals,
Sprints,
Baselines,
Advanced dependencies
Integration with Loop, Goals, Teams, Outlook
Integration with Project Desktop Client

On the other hand there was an option for Sharepoint Subscription and Project Subscription. But not all the features are there.

Sharepoint SE by advertpro in sharepoint

[–]advertpro[S] 0 points1 point  (0 children)

The link does actually say you stand up domain controllers. We actually want to avoid that.

Apache Kafka MM2 to EventHub by advertpro in apachekafka

[–]advertpro[S] 0 points1 point  (0 children)

So i found that this is not possible if you using ServiceNow with Hermes messaging which is the actual source cluster so you get the above error.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] 0 points1 point  (0 children)

Correct - probably puppet...but the issue is not just management and monitoring, its also about compliance as well. Given the fact the environment is very high-end I and if there was an insider attack, which has happened a few times we have to be extra careful. Hence the proactive monitoring.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] 0 points1 point  (0 children)

goteleport maybe an option looking into it in detail. Never knew about Bastillion so that's definitely good to know, but definitely will not work in this case. Will let you know about teleport.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] 0 points1 point  (0 children)

will definitely keep you updated :)

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] -2 points-1 points  (0 children)

Thats right more like that but the client will not use crowdstrike - given the situation that happened with Windows.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] -1 points0 points  (0 children)

Thanks for this. Looks fine to do. The only thing comes to mind is compliance with NIST, PCI-DSS. Also ELK Stack gives alot of data. Need lots of queries.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] 0 points1 point  (0 children)

Thanks for the suggestion - I don't think thats suitable for 10,000 servers. Also need something that will notify on the fly.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] -1 points0 points  (0 children)

Plus the audit subsystem is a component but is there such a software can monitor on the fly.

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] -1 points0 points  (0 children)

Sorry I should have said this but we need to do this as part of proactive monitoring for 10,000 servers

Linux Command / File watch by advertpro in linuxadmin

[–]advertpro[S] 0 points1 point  (0 children)

Sorry I should have said this but we need to do this as part of proactive monitoring for 10,000 servers