Conversation
Notices
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Sunday, 21-Jan-2024 08:14:15 JST Jake Hildreth (acorn) :blacker_heart_outline: -
Embed this notice
Stompy Spring Robot (stompyrobot@mastodon.gamedev.place)'s status on Sunday, 21-Jan-2024 08:14:17 JST Stompy Spring Robot @varx
Sure! Wouldn't be great if all logs were in the same place? (You'd still need domain experience of course!)At an online company with Windows servers I know of, they used to use remote desktop to connect to the Windows servers, that each had a public IP address, to get the logs from that server.
All 12,000 of them.
Good times :-)
-
Embed this notice
varx/tech (varx@infosec.exchange)'s status on Sunday, 21-Jan-2024 08:14:18 JST varx/tech @StompyRobot ...pretty sure they just needed someone to look at the logs.
-
Embed this notice
Stompy Spring Robot (stompyrobot@mastodon.gamedev.place)'s status on Sunday, 21-Jan-2024 08:14:19 JST Stompy Spring Robot @SwiftOnSecurity
You need observability that can capture everything, store everything, join everything, and doesn't charge you through the nose.observeinc.com
Disclaimer: I'm a co-founder
-
Embed this notice
SwiftOnSecurity (swiftonsecurity@infosec.exchange)'s status on Sunday, 21-Jan-2024 08:14:21 JST SwiftOnSecurity Me, being brought into a multi-vendor multi-day P1 incident because I’m ~good at Windows~:
“Has anyone looked at the Windows logs?”
Narrator: They had not looked at the Windows logs.
Post-credits scene: The error was in the Windows logs.
-
Embed this notice