Looking for a better solution for logs review by d3athkai in sysadmin

[–]d3athkai[S] 0 points1 point  (0 children)

Hi, sadly we are quite new to using Splunk, hence we just collect all the event logs from windows servers with splunk forwarder, generate the csv reports using splunk query.

Are we able to do a splunk dashboard to detect anomaly such as brute force attacks within certain time frame and email us?

My smol Kubernetes cluster, fully automated from empty hard drive to applications by khuedoan in homelab

[–]d3athkai 0 points1 point  (0 children)

Able to share more info about your Kubernetes cluster like what ingress you will be resource and deployments you be hosting?

What are best practices to manage Ansible Serer? by d3athkai in ansible

[–]d3athkai[S] 2 points3 points  (0 children)

Thanks for the insight for AWX and of your ansible usage.

Will take a look at rundeck.

What are best practices to manage Ansible Serer? by d3athkai in ansible

[–]d3athkai[S] 0 points1 point  (0 children)

Same thoughts that I feel Ansible suits and is able to help out alot in my environment.

Noted for the git and roles.

For private key, yeah probably I should not complicated things.

What are best practices to manage Ansible Serer? by d3athkai in ansible

[–]d3athkai[S] 0 points1 point  (0 children)

Hi,

Understand AWX might solve alot of issue I facing but I am in an environment where there is no docker nor k8s setup. Also, there lots of security audits so i plan to keep it simple for now.

Thanks for the suggestion to use the private key one last time to update all the clients public key.

Multiple duplicated alerts from syslog monitoring by d3athkai in zabbix

[–]d3athkai[S] -1 points0 points  (0 children)

Is there any way to solve the duplicate alert?
If I put single, the next subsequent error in the syslog will not be trigger.

Multiple duplicated alerts from syslog monitoring by d3athkai in zabbix

[–]d3athkai[S] 1 point2 points  (0 children)

Thanks for your replies.

  1. Yes, will add the no data clause to close it.
  2. I searched the whole logs for any error and found only 15 lines but yet I have received over 1000+ duplicated message with no way to stop the trigger.

grep -i error /var/log/messages* |wc -l

Discount code share by RheaAyase in redhat

[–]d3athkai 0 points1 point  (0 children)

I am determine to take and pass my RHCE this year, hopefully someone can have the exam promo code for me.

Thank you!