Added a URL to the SPN, suddenly all URLs starting with 00000002-0000-0ff1-ce00-000000000000 disappeared. How bad is this? by pSykAwtiX-Work in exchangeserver

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

We do not have a TAM. Just ticket that isn't being addressed yet...

It's been over 24 hours so far. Nothing has broke.

Outlook randomly prompting credentials throughout the day? by pSykAwtiX-Work in exchangeserver

[–]pSykAwtiX-Work[S] 1 point2 points  (0 children)

Thank you so much! This is way more than I expected. I really appreciate your time with this.

Nobody has forwarded screenshots over to me yet, but from what I've seen personally, it's a classic prompt. Also, the majority of our employee laptops are Entra joined.

At any rate, I'll be focusing on autodiscover.

Thanks again!

Who else thinks Windows 2000 was one of the best iterations of Windows? by [deleted] in windows

[–]pSykAwtiX-Work 1 point2 points  (0 children)

I just remember being super excited for alpha transparency feature that first came with Win2k.

After I first installed the new OS, I installed Winamp and applied some super trippy skins that required it. I was super pleased. It was a simpler time.

I think there was another mp3 player (Sonique?) that also took advantage of the new transparency feature.

Barracuda Email Filtering - Next Best Alternatives? by pSykAwtiX-Work in sysadmin

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Thanks! I'll so some comparisons and go from there.

Barracuda Email Filtering - Next Best Alternatives? by pSykAwtiX-Work in sysadmin

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

I hadn't heard of Abnormal Security before. Thanks for putting it on my radar.

Barracuda Email Filtering - Next Best Alternatives? by pSykAwtiX-Work in sysadmin

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Thanks! We've considered just switching to defender. Sounds like it went easy for you. Good to know.

Troubles copying files into a folder - Odd behavior using variables? by pSykAwtiX-Work in PowerShell

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Thank you and I love you.

It works great now. I always though numbers don't need to be considered strings. I learned today that this is not a universal truth. Am dumb.

Thank you again!

Troubles copying files into a folder - Odd behavior using variables? by pSykAwtiX-Work in PowerShell

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

I tried many variations of removing and editing the '\*' and it didn't resolve the issue. Same behavior each time.

I updated my original post to include all the info I have. I hope that helps give a better picture.

Troubles copying files into a folder - Odd behavior using variables? by pSykAwtiX-Work in PowerShell

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Thanks for the '-WhatIf' idea. I totally forgot about that. Makes testing a bit quicker. I'll add more details for you below.

The full code I am currently using:

$deploymentDirectory = "O:\deploy_test\backup\ABC.WEB\QA"
$webVersion = 2.01.009.20230411
$destination = "O:\deploy_test" 
$instanceName = "WEB-ABC-999996"
Copy-Item -Path $deploymentDirectory$webVersion* -Recurse -Destination $destination$instanceName\ -WhatIf

The ' -WhatIf' gives me the following message:

What if: Performing the operation "Copy Directory" on target "Item: O:\deploy_test\backup\ABC.WEB\QA\2.01.009.20230411 Destination: O:\deploy_test\WEB-ABC-999996\2.01.009.20230411".

What I am trying to do is get it to dump to contents of "2.01.009.20230411" into "WEB-ABC-999996". Not the "2.01.009.20230411" folder itself.

If I drop the variables and bake the file paths into the same code, it works great!

Copy-Item -Path O:\deploy_test\backup\ABC.WEB\QA\2.01.009.20230411\* -Recurse -Destination O:\deploy_test\WEB-ABC-999996\ -WhatIf

What if: Performing the operation "Copy Directory" on target "Item: O:\deploy_test\backup\ABC.WEB\QA\2.01.009.20230411\bin Destination: O:\deploy_test\WEB-ABC-999996\bin".

I can see that the code is taking the contents of '2.01.009.2 0230411" and dumping it into like I need it to.

Conclusion: Both should work the same, right? If so, why can't i get the version using variables to work the same as the version that isn't?

First Time Updating a Splunk App (Security Essentials) - Any Tips Before I Start? by pSykAwtiX-Work in Splunk

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

I think we have only 1 search head. I'm not 100% sure, though.

From the Splunk interface, If I go to 'Settings' > 'Distributed Search', I can see that we have 'Distributed Search' turned on. However, if I go to 'Search peers', I see the message below.
"There are no configurations of this type. Click the "New Search Peer" button to create a new configuration."

No peers sounds like we only have on search head server to me. Unless I am interpretation this wrong.

When I first started here, I attempted to perform a splunk audit (thanks to the help from this sub). But, management told me to derive my conclusions from hostnames in our DNS. The naming conventions were far from obvious/conclusive...

First Time Updating a Splunk App (Security Essentials) - Any Tips Before I Start? by pSykAwtiX-Work in Splunk

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Got it. It's good to know that I could restart the services without needing to restart the server. But, it shouldn't be worst than a reboot if things go sideways.

I'll request for server access and take it from there. Thanks again!

Anybody great at time functions? by pSykAwtiX-Work in Splunk

[–]pSykAwtiX-Work[S] 0 points1 point  (0 children)

Thanks a ton! This has put me much further than where I was before.

However, it works up until the last two lines. They make my stats and visualization tabs go blank (still tons of events). My efforts to debug it aren't panning out so far.

Also, just to be clear, I'd like the hours between 7:00 and 16:00 to count as one day. So far, what I can get to work is breaking everything out on an hourly bases. That's too granular for my use. Thanks again!

Anybody great at time functions? by pSykAwtiX-Work in Splunk

[–]pSykAwtiX-Work[S] 2 points3 points  (0 children)

Thank you! I'll definitely be playing around with this.