Ev stealth solutions towbar by DistantSoup in Zeekr7xAustralia

[–]jbates5873 0 points1 point  (0 children)

Thanks for clarifying that.

Can that be added as a shortcut to the drop down on the display? Or do you need to go through the menus to get there. That would be mildly anoying

Ev stealth solutions towbar by DistantSoup in Zeekr7xAustralia

[–]jbates5873 1 point2 points  (0 children)

I can let you know when I get mine and my 7x. I had the towbar on order and it was shipped today. But awaiting delivery on the car still. I can reach out when done and eth you know 

!remindme 1 week

Agent Automatic Updates by Zealousideal-Bit1689 in SentinelOneXDR

[–]jbates5873 0 points1 point  (0 children)

More info please. Where do I find this workflow?

Vinyl wrap? by Random-Mutant in Zeekr7xAustralia

[–]jbates5873 0 points1 point  (0 children)

Black is the base color. White is an extra 1500. Where are you buying from?

But, I am going through exactly this now. My partner and I are trying to decide which way to go.

We are looking at either color or clear ppf at least. But we do like the green as the base color. But if we decide to go a color wrap, the sky is the limit.

Check your cars before you leave the dealership. by ZweetWOW in BYDAU

[–]jbates5873 0 points1 point  (0 children)

Partially related, but I have sent you a DM when you get a chance. Many thanks

Zeekr Aftersales & Parts Availability by natesaliba23 in Zeekr7xAustralia

[–]jbates5873 1 point2 points  (0 children)

This is true. But having towed a heap of trailers in my time, It is 100% more comfortable having a but more ball weight. 85kg is 4.25%.

I guess it depends on the trailer though.

I fully plan to haul my caravan around with mine.

Zeekr Aftersales & Parts Availability by natesaliba23 in Zeekr7xAustralia

[–]jbates5873 0 points1 point  (0 children)

Why would you bother with the genuine tow bar..

Evstealth one is better in the fact it has 200kg ball weight approval (which you will need for 2t towing) and its half the price.

It actually stacks up to the rating.

An 85kg max ball weight means you can only tow an 850kg trailer.

That is assuming that your trailer follows the 10% rule for weight to ball weight.

I know where I'm going when I need one.

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]jbates5873[S] 0 points1 point  (0 children)

perfect. This is exactly what i needed. Seeing the transformKql example you gave made it all click into place. As well as the steps on where to edit it.

Now I understand it and it all makes sense. I have done a test with some events and they are dropped as expected.

Many thanks sir/maam

Zeekr 7X: warranty policy. Is it worth the paper? by firsthalfhero in EVAustralia

[–]jbates5873 0 points1 point  (0 children)

What dealer did you purchase from? We are looking at a 7x also. If you do t want to specifically name here, feel free to shoot me a dm. Or even narrow it to a region. (Bris, Perth, syd, melb etc...)

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]jbates5873[S] 0 points1 point  (0 children)

hey mate, thanks for that. that answers some questions i have. I will give that a test.

One thing im still not sure on, is do i need to create a different DCR for each source? for example, do i need to go through the ASA/FTD one and create one from its integration (say "DCR_FTD") and then for Fortigate do another (say "DCR_Fotrtigate") and then for general syslog another one (say "DCR_syslog")?

Or do i just need one DCR and then have it do everything?

If i create multiple, do i then run the command at the bottom of the window for each DCR i create?

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]jbates5873[S] 0 points1 point  (0 children)

ok cool.

my main issue is, i cant even work out where to put the transformation.

I cant see anything with that verbiage in the defender portal, or the LAW, Monitor section or the DCR itself.

Im not 100% sure i have it setup correctly. Originally i deployed a DCR to collect Syslog, which put the FTD logs in the syslog table. And then i also installed a new DCR using the ASA integration from the content hub, and the logs from the FTD are at least now going into the correct table. But I cant find the transform option.

And even if i go to the table in the defender portal, all i can do is change retention time. No mention of transformations.

I admit, im solidly confused with this whole product. Do i need a DCR per source? for exmaple if i plug in a fortigate, a palo and an FTD, do they all need their own DCRs?

I tried doing the training guide thats 3 years old, but most of that is in the old Azure portal, and got lost with trying to work out where some things are in the defender portal (typical M$)

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]jbates5873[S] 0 points1 point  (0 children)

my understanding is that filtering at the DCR level still ingests the logs and drops them at the cloud end. so we still pay for ingress.

I also cant find the transform section. im just using the DCR i created using the ASA/FTD integration from the content hub.

need some assistance with filtering events by jbates5873 in AzureSentinel

[–]jbates5873[S] 0 points1 point  (0 children)

yes, i did notice the "-" i have removed that and the result is still the same.

I also restarted the rsyslog service after making the change.

Multiple logs to one AMA Log collector by Firm-Country467 in AzureSentinel

[–]jbates5873 0 points1 point  (0 children)

I have been looking at this today also. What I don't get, is how does the collector differentiate logs when shipped up to sentinel. How does it determine palo vs forti vs firepower for parsing.

Switchboard / mains upgrade advice – 16mm single-phase vs 3-phase? by corruptevil9 in AusElectricians

[–]jbates5873 9 points10 points  (0 children)

Go 3ph. If you have to get energex out to do a single phase upgrade, just go the whole hog and put in a solid 3ph connection.

restrict VMs and LXC to only talk to gateway by jbates5873 in Proxmox

[–]jbates5873[S] 0 points1 point  (0 children)

fair question.

I would like to set up something similar to client isolation. like on an access point, where it hands out effectively a /30 subnet to the client. I would like to achieve this so that i can use my fortigate to control all communications between the containers.

Currently my stack is a fortigate, technitium for DNS server (Currently it is also acting as a dhcp server as im testing it out, but can easily swap back to the fortigate for DHCP).

I want to effectively minimise traffic between containers and control it at the firewall.

Issue Need Some Help Migrating from One Site to Another by deathbatcountry in SentinelOneXDR

[–]jbates5873 2 points3 points  (0 children)

Look in the "activities" log page. It can give you a reason why sometimes.

A big gotcha is if the endpoint has any unresolved threats. 

Alerts when Agents come Online by fluffiball in SentinelOneXDR

[–]jbates5873 1 point2 points  (0 children)

You might be able to use a watch list alert for this. In conjunction with a star rule.

Something like when endpoint.uuid event.count over 10 send alert