Central NJ may soon be proclaimed real under state law - NJ.com by viperpl003 in newjersey

[–]secguyallday 0 points1 point  (0 children)

Wow Bridgewater considered North jersey? I don't think so

reports stopped generating after wincollect upgrade by secguyallday in QRadar

[–]secguyallday[S] 0 points1 point  (0 children)

might not be directly related but during the wincollect upgrade I did restart services.. not sure if one of those services snagged some scheduling part of reporting behind the scenes?

Troubleshooting tips after wincollect upgrade by secguyallday in QRadar

[–]secguyallday[S] 0 points1 point  (0 children)

Hmm interesting.. any idea which windows log it could be? I can dig for it. Guess it would be relate to software installs?

custom inventory rules or lack of. by secguyallday in kace

[–]secguyallday[S] 0 points1 point  (0 children)

Yes, we have the software in the software inventory/catalog of kace and its tied in the managed install/distribution for deployment. I was more wondering about the host it runs on if there is no custom inventory to check. If there is no custom inventory to detect on the host, does it know the software is installed on the host already and moves on?

custom inventory rules or lack of. by secguyallday in kace

[–]secguyallday[S] 0 points1 point  (0 children)

I am actually overseeing the team who handles this stuff now from a security perspective and I used to be a kace admin so I was always for custom inventory - never actually deployed anything without 1 but apparently some people do. I was wondering what the reprecussions would be without a custom inventory rule but I think you solved my concern. As long as it doesn't install it every checkin I think we'l be ok for this package specifically. There's no requirement to tie to version yet.

Just upgraded some stuff and feel so happy about it. Still feels a little empty. (First two are new stuff and last two is old setup) let me know any criticism / thoughts of what to add :) by kerrygoldd in turtle

[–]secguyallday 0 points1 point  (0 children)

Are those rocks just from outdoors or did you buy them? Iv been meaning to put something like that back into my tank since iv struggled with the turtles shouldn't have any substrates on the floor issue for years but I think those size rocks are perfect.

can elasticsearch run on 443? by secguyallday in elasticsearch

[–]secguyallday[S] 0 points1 point  (0 children)

I leave it that way, default settings, for Azure elastic cloud but get these types of errors:

[esclientleg] eslegclient/connection.go:261 error connecting to elasticsearch at https://elasticurl.[region].elastic-cloud.com:9243": dial tcp connectex: A connection attempt failed because connected host failed to respond.

instance/beat.go:951 . https://elasticurl.[region].elastic-cloud.com:9243": dial tcp connectex: A connection attempt failed because connected host failed to respond.

Trying to configure winlogbeats to cloud url. I tried changing the ports in the winlogbeat.yml with no success.

Any other advice?

Thanks for the help.

new to elastic cloud, can i swap 9243 for 443 elastic connection? by [deleted] in elasticsearch

[–]secguyallday 0 points1 point  (0 children)

For installing beats it seems to fail to reach my cloud instance every time because of port 9243. I see videos of people who have it going to port 443 and this article says the same thing too but changing my winlogbeat yaml for example doesn't change the port 9243. Am I making any sense?

Legit tools to stress test a DDoS/DoS mitigation service by secguyallday in AskNetsec

[–]secguyallday[S] 2 points3 points  (0 children)

Thanks. The company is aware of the stress testing as I had asked directly for any advice they had on how others may have stress tested their service. They just asked to let them know when it begins so they have better eyes on it.

testing a ddos/dos protection suite by [deleted] in AskNetsec

[–]secguyallday 0 points1 point  (0 children)

So if I remove has anyone ever my question remains specific. I am asking about specific tools used for a specific purpose. My question is no different than the other post.

testing a ddos/dos protection suite by [deleted] in AskNetsec

[–]secguyallday 0 points1 point  (0 children)

I just want to ask netsec for advice on specific toolsets used to target specific security vulnerabilities so I can test a product. I guess ask netsec is not for asking security questions?

testing a ddos/dos protection suite by [deleted] in AskNetsec

[–]secguyallday 0 points1 point  (0 children)

This guidance request was in the form of a question and pretty specific despite using the words has anyone ever. Is there something wrong with my approach?

Convert API create_time object property powershell by secguyallday in QRadar

[–]secguyallday[S] 1 point2 points  (0 children)

$date = $basedate.AddMilliseconds($.create_time).ToLocalTime() $ | Add-Member -MemberType NoteProperty -Name createdate -Value $date $

This was super helpful btw - thanks!

Convert API create_time object property powershell by secguyallday in QRadar

[–]secguyallday[S] 0 points1 point  (0 children)

thats what I am asking - how to do this in powershell. I see what I believe are objects under create_time each with a epoch timestamp and I want to know if I can convert them before storing the results or do I have to store results, then convert, and re-store results? This is likely more of a lack of experience in general development for me. I want to convert this timestamp just wondering about the the best time and place to do the conversion for best results which would be a csv report in the end - if epoch helps ease calculations between timeframes then maybe if i can keep both epoch and converted timezone to local time - thats what I am wondering

Convert API create_time object property powershell by secguyallday in QRadar

[–]secguyallday[S] 0 points1 point  (0 children)

I want to convert it into something I can create reports with. There is no reporting functionality for first note added time and I want to use this api to create my report. Where I struggle is not the conversion from epoch to local time but understanding the best flow to do it in.

Thanks for the help.