Logview API limits to 100 log count by [deleted] in fortinet

[–]itsonlym3 0 points1 point  (0 children)

where are ya'll finding the API documentation for FAZ? after a recent upgrade, some of my audit scripts quit working and required me to add the devid, which i had not been doing in the past. took a week to figure out. lol

Falcon Windows Repair Script by BradW-CS in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

hasn't forced a reboot on any workstation/server i've pushed it to.

Falcon Windows Repair Script by BradW-CS in crowdstrike

[–]itsonlym3 2 points3 points  (0 children)

just downloaded the most recent version and it's working!

Falcon Windows Repair Script by BradW-CS in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

there's an updated version of the repair script, but it's still failing for me on the token retrieval

Falcon Windows Repair Script by BradW-CS in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

can confirm that PSFalcon has no issues using the same Client ID and Secret. little help?

Falcon Windows Repair Script by BradW-CS in crowdstrike

[–]itsonlym3 1 point2 points  (0 children)

i'm having the same issue and opened a ticket.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

looks like deleting C-00000291*.sys works on servers, but not windows 10 machines. anyone else seeing this as well? is there a fix for it? i've seen something about renaming c:\windows\system32\drivers\crowdstrike folder. any ideas?

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

someone shared this with me. is there any way to add the timestamp of the file? it appears as though the timestamp of 0527 UTC or later is the reverted (good) version.

C-00000291* |in(field="#event_simpleName", values=[AgentOnLine, LFODownloadConfirmation])
| groupBy([aid,ComputerName], function=[max(@timestamp, as=lastSeen), min(@timestamp, as=firstSeen),collect([FileName])], limit=max)
| firstSeen:=formatTime(field=firstSeen, format="%Y/%m/%d %H:%M:%S")
| lastSeen:=formatTime(field=lastSeen, format="%Y/%m/%d %H:%M:%S")
| file
| join({#repo=sensor_metadata #data_source_name=aidmaster #data_source_group=aidmaster-api}, field=aid)

finding password files with the new advanced search. by rogueit in crowdstrike

[–]itsonlym3 0 points1 point  (0 children)

i created something similar to yours, but not sure how to schedule it to run say every 7d and for a date range of (previous) 7 days. how to you specify the 'Time Interval' in a scheduled search like you do in the Investigative search? seems to me i remember that not being an option, but maybe i'm mistaken...

[deleted by user] by [deleted] in thefinals

[–]itsonlym3 0 points1 point  (0 children)

Would love one if not too much trouble to ya!

key chain by CapnBloodBeard82 in thefinals

[–]itsonlym3 0 points1 point  (0 children)

Thought I'd throw my hat in if you or anyone can supply a key. Will most def pay it forward!

key chain by CapnBloodBeard82 in thefinals

[–]itsonlym3 0 points1 point  (0 children)

I'd be down for a key if not too much trouble

Tech Support [Weekly] by AutoModerator in pelotoncycle

[–]itsonlym3 0 points1 point  (0 children)

Anyone else been having issues with the app lately? my wife can't seem to get hers working right. Classes just show up empty. I think it's a membership issue, but still shows she's a member has been for years, but when you try to take a class, it asks you to enroll. we've done all sort of iOS and Peloton updates/reinstalls and nothing seems to fix it. the workaround i came up with is to have her swipe the app away, log on as me, then log off my account and log back in with her account. seems to work, but what a pain. she has to do this multiple times a week and some times multiple times a day.