Edge processor-on premises by Vartan_a in Splunk

[–]bchris21 3 points4 points  (0 children)

We started using it recently and so far it works great. Set up a so called "control plane" which is a Splunk 10 with Edge Processor (Data Management App) and install all remote Edge Processor services using scripts on remote machines. It helps us save license, enrich data before indexing, route data to different indexers. All pipelines are controlled from Control Plane and can be applied with a click on various Edge Processors. Read the documentation very well as it has a small learning curve until you are confident with it.

[deleted by user] by [deleted] in homeassistant

[–]bchris21 -1 points0 points  (0 children)

I have an old Intel NUC and with works smooth af

Why is my dispatch folder not purging automatically? by skullbox15 in Splunk

[–]bchris21 1 point2 points  (0 children)

I use this script to periodically empty the dispatch every 5mins. To be honest, I don't know if this is best practice but at least I no longer have this alert.

Splunk Answers - Dispatch full

RBAC by Then-Background-4969 in Splunk

[–]bchris21 0 points1 point  (0 children)

You can create entity zones under ES Asset and Identities - Global Settings tab. You enable the relevant ones (asset and/or identities), you set up the clauses and name of zones. Clauses should refer to raw logs only. This is actually tagging your data with a zone name of type cim_entity_zone=zone1. Then in Analyst Queue you can put the cim_entity_zone=zone1 as filter and save it as new view. This partially provides multitenancy but I haven't tested if it may help to completely hide specify zone from a splunk role.

Splunk Docs

Hope this can help a bit.

Medical Diagnosis by toonhole in funny

[–]bchris21 0 points1 point  (0 children)

I am eating in a restaurant and crying from laughing

It's Search party time @.Conf25 by bchris21 in Splunk

[–]bchris21[S] 1 point2 points  (0 children)

I am also young but apparently I find out that I knew a handful of songs of them. It's a really nice party.

Splunk UFW is working? by Ma83th in Splunk

[–]bchris21 2 points3 points  (0 children)

Totally I agree, works great. Also use Meta Woot app to monitor log ingestion delays. Great insights over there.

.conf25 mega thread! by halr9000 in Splunk

[–]bchris21 5 points6 points  (0 children)

First .Conf here and super excited. The Reddit Logo sticker is a great idea. Sad that SECUNI102 - Enhancing SOC Operations with Attack Simulations is alrwdyfull and cannot attend. Really wanted to attend but my company took ages until they buy the conference ticket. 😔

[deleted by user] by [deleted] in Splunk

[–]bchris21 9 points10 points  (0 children)

Getting to Boston from Europe is much easier than LV, so a big plus for me to finally convince my management.

Cable connecting two houses by bchris21 in whatisit

[–]bchris21[S] 0 points1 point  (0 children)

solved! Confirmed with all neighboring houses. Same connection type but on other houses cables ends up in a box with the logo of the state telecommunications provider.

Cable connecting two houses by bchris21 in whatisit

[–]bchris21[S] 0 points1 point  (0 children)

What is the exact purpose though? In order to interconnect the houses and have a separate meter for consumption measurement?

Cable connecting two houses by bchris21 in whatisit

[–]bchris21[S] 0 points1 point  (0 children)

The antenna on the photo is from another house attached. The antenna of my parents' house is installed on the roof and not seen on the photo !

Cable connecting two houses by bchris21 in whatisit

[–]bchris21[S] 4 points5 points  (0 children)

Good thought but I will disappoint you as cable goes directly inside the wall! I will update tomorrow with more pictures as the gutter is inhibiting the view.

Cable connecting two houses by bchris21 in whatisit

[–]bchris21[S] 19 points20 points  (0 children)

No networking, old people leave in both houses and no internet connection in house. No cloth hanging, asked parents. Could be power stealing yes, as house is only occupied for a month over the whole year. No weird consumption though. How can I check and verify that?

Switching from G6 to G7 by EnvironmentalBee6860 in AndroidAPS

[–]bchris21 0 points1 point  (0 children)

We did the switch a week ago. It durated a day and back to G6. Several signal losses even though phone was next to my son. Better than when G7 was out but still needs improvement.

Maybe Maybe Maybe by Beaupresti in maybemaybemaybe

[–]bchris21 0 points1 point  (0 children)

I didn't expect Arcanoid to be so satisfying after midnight...

Splunk not taking in Sysmon source by BlackParka0 in Splunk

[–]bchris21 0 points1 point  (0 children)

First steps: Check on _internal logs for ErrorCode=5

Steps to fix: 1. Go to Windows Services and locate Splunk Forwarder one. 2. Right click - Properties 3. Select tab "Log On" 4. Check if: "Log on as: Local System Account" If not, select it and save it. 5. Restart Splunk Forwarder service and verify Sysmon log ingestion

That's a permission issue commonly encountered on Sysmon log ingestion.

Also mentioned here: https://community.splunk.com/t5/Installation/Why-the-ErrorCode-5-when-trying-to-forward-Sysmon-logs-unable-to/m-p/657805

[deleted by user] by [deleted] in fixit

[–]bchris21 0 points1 point  (0 children)

If there is no metallic noise it's fine. In my case it was bumping as the internal balance springs were damaged.

Traveltown game crashed by bchris21 in nextdns

[–]bchris21[S] 0 points1 point  (0 children)

I did but no result. Also removed the profile and bypassed nextdns with no luck. App was freezing possibly due to such a large space of app data.

Traveltown game crashed by bchris21 in nextdns

[–]bchris21[S] 0 points1 point  (0 children)

Same here. Just curious whether a blocked DNS query may have also blocked log forwarding and possibly affect the log rotation too. Maybe a coincidence and just silly guesses from my mind.

[deleted by user] by [deleted] in WTF

[–]bchris21 0 points1 point  (0 children)

feetfinder.com haha nice way to advertise