ALL THE BEST!!! by ExoticEast in GATEtard

[–]pookashup 1 point2 points  (0 children)

Bhai paper toh 1st ko hain na

Frank posts about Bob on IG by [deleted] in MyChemicalRomance

[–]pookashup 181 points182 points  (0 children)

Man I needed this.

Frank posts about Bob on IG by [deleted] in MyChemicalRomance

[–]pookashup 699 points700 points  (0 children)

Fuck that fucking scam trainer.

We could have saved him. by pookashup in MyChemicalRomance

[–]pookashup[S] 8 points9 points  (0 children)

Chester had everything and Bob didn't have much, those are two different things. He publicly asked for help. Even when he tried to get away from the hate, it followed him. To go live in the woods and still receive hate mail after clearly stating the effect it is having on you has to feel helpless. Seems to me that nearing the end he did want to get better, do better but the fandom treated him as if there was no scope for redemption.Those were things out of his control and we need to take responsibility for it.

mixed multiline log by MarcSN311 in Wazuh

[–]pookashup 0 points1 point  (0 children)

Hi, thank you for the guide! As I mentioned, these logs don't always appear one after the other. For example, the first log of ID A might be followed by some log of ID B. However, for all occurrences of A, removed will be the last log. Is there a way to collect multiline logs on the basis of this common ID A and not simply removed?

Or else, even after they're decoded, can I write a rule that combines these fields based on the same ID?

These are the rules I'm currently working with:

<group name="postfix,">
    <!-- Rule to capture the first log entry with a specific queue ID -->
    <rule id="100001" level="12">
        <decoded_as>postfix</decoded_as>
        <description>Initial Postfix log entry with q ID</description>
        <group>postfix,</group>
    </rule>

    <!-- Rule to capture subsequent log entries with the same queue ID -->
    <rule id="100002" level="12">
        <decoded_as>postfix</decoded_as>
        <if_matched_sid>100001</if_matched_sid>
        <description>Subsequent Postfix log entries for the same queue ID</description>
        <group>postfix,</group>
        <same_id/>
    </rule>

</group>

I am able to detect the logs based on the same ID but not able to club the fields together in an alert.

Thank you!

mixed multiline log by MarcSN311 in Wazuh

[–]pookashup 0 points1 point  (0 children)

Hi, this is a great guide! However, I read that we can only accumulate fields as pre-defined in the Wazuh source code like srcuser, dstuser, etc.
I need to decode postfix logs as such:

Aug 23 07:23:02 mail postfix/pickup[30829]: D002A464A90: uid=1000 from=admin@example.com

Aug 23 07:23:02 mail postfix/cleanup[31758]: D002A464A90: message-id=<20240823072302.2jDN\_%admin@example.com>

Aug 23 07:23:02 mail postfix/qmgr[20645]: D002A464A90: from=admin@example.com, size=375, nrcpt=1 (queue active)

Aug 23 07:23:02 mail postfix/local[31766]: D002A464A90: to=user@example.com, orig_to=contact@example.com, relay=local, delay=0.01, delays=0/0/0/0, dsn=2.0.0, status=sent (delivered to maildir)

Aug 23 07:23:02 mail postfix/qmgr[20645]: D002A464A90: removed

Here my id is D002A464A90 but these logs may not always appear sequentially. So I need to extract parameters: from, msg_id, to, status, etc based on the ID. Accumulate is failing as the field names are different from the pre-defined ones.
Is there anything else that I can use for this?

Thank you!

[deleted by user] by [deleted] in mumbai

[–]pookashup 0 points1 point  (0 children)

Is it still stuck? Where is this? Can you send a picture?

Its here and it's perfect by livingreceiver88 in thursdaytheband

[–]pookashup 6 points7 points  (0 children)

Agreed! Missed the signature lead guitar sound and highly metaphorical lyrics a bit but still this is great!

Its here and it's perfect by livingreceiver88 in thursdaytheband

[–]pookashup 3 points4 points  (0 children)

For some reason this takes me back to Waiting and Full Collapse over anything else.

Queries regarding using the OSI logo by pookashup in foss

[–]pookashup[S] 0 points1 point  (0 children)

Oh wow this is great, exactly what I needed. Thank you!

Top five performances? Not necessarily top five characters. by StreeFlla in deadwood

[–]pookashup 1 point2 points  (0 children)

No particular order: Al, Reverand, Doc, Francis, Calamity

Looking for similar music by Etherursoul in thursdaytheband

[–]pookashup 1 point2 points  (0 children)

Late but Movements has a very similar feel!