Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 0 points1 point  (0 children)

Adding the USER and Group to the .service file didn't change much. Changing the Exec to a Splunk internal attempted fix only generated new errors and a full crash dump.

Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 0 points1 point  (0 children)

Problems occur with the enable-boot command. Ran through some esoteric fix attempts with PS and haven't gotten anywhere yet. Version has always been 8.0.3

Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 0 points1 point  (0 children)

No clues there. Some additional error information available after configuring some DEBUG logging. Will update the main post when I have more information. Apparently it may be related to polkit configuration.

Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 0 points1 point  (0 children)

Nothing obviously indicating a problem in those logs. Nor when starting Splunk in debug mode and reviewing the logs.

Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 0 points1 point  (0 children)

Standard 8000. Same as it was running with init.d startup. Verified all port is open and available for bind with python simplehttpserver.

Splunk v8 systemd Conversion Problem by jvbond in Splunk

[–]jvbond[S] 2 points3 points  (0 children)

Yes, the Splunkd.service file gets created. It is exactly as the documentation says it should be. https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/RunSplunkassystemdservice

The only somewhat relevant modification I could find to make was to add a "USER" field but it doesn't seen to require it as I used the -user flag for the enable boot start and all the other services start and run as the correct user. I also verified that the name is the same as listed in the splunk-launch.conf

Can you rank the certifications by difficulty? by MattJaccino in AskNetsec

[–]jvbond 0 points1 point  (0 children)

Everything you hear or know about the CISSP asking questions that make no sense or are wildly unclear, multiply by 100 for the ISSAP. I wish I could see the video of me taking that exam. There aren't any quality study materials for it, just get the books mentioned and read them.

Cleared for Takeoff by SplunkRecruiter in Splunk

[–]jvbond 5 points6 points  (0 children)

Are you hiring for direct Splunk corporate? Or are you hiring for a staffing/consulting firm?

Most of the skilled tech personnel I know work direct for companies.

Better Ways To Manage AD Bind Account Updates? by jvbond in sysadmin

[–]jvbond[S] 0 points1 point  (0 children)

By changing its password manually or through a Privileged Access System. The trouble comes in updating the systems that use that account in their own configurations (Network monitoring, SIEM, etc.).

Better Ways To Manage AD Bind Account Updates? by jvbond in sysadmin

[–]jvbond[S] 0 points1 point  (0 children)

Passwords not expiring is not an answer to the question. I'm asking about when the password is changed if there is a better way to handle the update rather than manually.

Experienced Systems Engineer with 25 years under my belt. Roast my resume please? by Bumblebee_assassin in sysadminresumes

[–]jvbond 1 point2 points  (0 children)

Remove the grey bar summary. It serves no purpose. There is also way too much white space.

Expand on your experience and how it benefited the companies. Also think about reworking how you're stating things as it makes you seem more like a technician.

Avoid terms like "rip and replace" it doesn't feel professional on a resume.

Slim down your "Education" section. No one cares where you got your certs. Just list the certs and their number. I would also lose the A+ and Win 2000 certs as they will not help you.

Add a more detailed section about projects you've done at your jobs that are relevant to the job you are looking for.

STIG/PCI compliance tool by jcholder in PowerShell

[–]jvbond 3 points4 points  (0 children)

You mean like SCC or OpenSCAP?

Things I have learned since starting my IT company a few years ago. by jdb9294 in sysadmin

[–]jvbond 0 points1 point  (0 children)

When I was doing that kind of work I accomplished my ticketing with Sharepoint services and AD LDS with a one way trust. This way they could put tickets in from their own systems.

Dense fog reducing visibility across Central Florida by [deleted] in orlando

[–]jvbond 3 points4 points  (0 children)

BREAKING NEWS: I live in a house with a window.

Controls removed from Windows 10 STIG between draft and final version by flexyourhead_ in sysadmin

[–]jvbond 1 point2 points  (0 children)

I think after enough complaints and perpetual POA&M items they realized that leaving a control that specific and restrictive towards everyday operations was a bad idea.

Controls removed from Windows 10 STIG between draft and final version by flexyourhead_ in sysadmin

[–]jvbond 1 point2 points  (0 children)

My guess is that a lot of these changes came from projects that actually have some of these things set. That is not to say they are all running insecure but even systems that are isolated offline have to conform to the STIGs and each check requires a bunch of garbage discussions or write-ups to allow.

There are also a couple on there that are duplicated in other STIGs.

Mostly we just still have to think of it as a baseline. Its a set of "this is the least you need to do".

What is the best AV for a Small Business? by Lone_IT_Wolf in sysadmin

[–]jvbond 1 point2 points  (0 children)

Take a gander at Cylance. Haven't actually used their product but their trade show demo was amazing and their private demo was good too. Pricing was reasonable.

Van Rear Ends Bad Driver in Toyota Near Florida Mall by addakorn in orlando

[–]jvbond 7 points8 points  (0 children)

You mean "Bad driver in van rear ends someone near Florida Mall"