In #Proxmox we were not successful in adjusting the settings of the virtio interfaces, even on the command line of the host.
Is it possible that a deployment of #Suricata in Proxmox #VMs requires a different NIC driver, e.g., E1000?
That would be a real problem, since the throughput seems to be way smaller than with virtio.
@suricata
@satta It seems that activating ja4 leads to suppressing the log output of all tls-related fields in #Suricata 7.0.6
In Line 595 of output-json-tls.c it should probably be
tls_ctx->fields |= LOG_TLS_FIELD_JA4;
rather than
tls_ctx->fields = LOG_TLS_FIELD_JA4;
because all field flags are reset. Am I correct?
Is your network congested or in danger of becoming overloaded?
In "Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen" https://nxdomain.no/~peter/yes_you_too_can_be_an_evil_network_verlord.html you may find hints on how to solve that problem. #AppFlow #netflow #metadata #networkmonitoring #pflow #Surveillance #OpenBSD #IPFIX #nfsen #monitoring #congestion
Zeek: Open-source network traffic analysis, security monitoring https://www.helpnetsecurity.com/2024/06/25/zeek-open-source-network-analysis-framework-security-monitoring/ #networkmonitoring #networkanalysis #cybersecurity #monitoring #opensource #Don'tmiss #Hotstuff #software #GitHub #News
New video alert! Monitor Your Network with PowerShell - Learn how to create a script to monitor network uptime for multiple IPs and ensure accurate intervals. Don't miss it! Watch here: https://www.youtube.com/watch?v=NsCWmYjP9F4 #PowerShell #Automation #NetworkMonitoring
If you want to create your custom #packetsniffer based on #Scapy, the recent webcast by #ActiveCountermeasures could be a good starting point.
Bill provided nice explanation and his sniffer template is available on GitHub.
Is there anyone who has significant experiences with running #suricata in containers inside a VM?
I was hoping that it is possible to scale things up to process multiple gigabits of traffic.
The #afpacket interface works (in my setup in a #docker container inside a #Proxmox-VM w/ 2 cores and 16GB of RAM) for up to 180Mbit/s, but I assume that it produces significant overhead.
Splunk cuts 7% of workforce ahead of Cisco acquisition - The layoffs are happening in the wake of a market retraction, Splunk CEO Gary Steele said... - https://www.networkworld.com/article/3709848/splunk-cuts-7-of-workforce-ahead-of-cisco-acquisition.html#tk.rss_all #technologyindustry #networkmonitoring #networksecurity #ciscosystems
Attention, Zeek® users! Whether you’re new to Zeek or already a master of Zeek logs, don’t miss your chance to join us for our free public training event next week at the Grand Canyon University. Come unleash your network security prowess with a day of turbocharged learning, fun, and networking with the @corelight Open Source and @zeek teams! Register today https://go.corelight.com/zeekday-grand-canyon-university
Zeek is the gold standard for network security monitoring that’s also the foundation for Corelight network evidence. Learn more: https://corelight.com/products/zeek/
Think like your adversaries. While they may have a singular goal in mind, it’s likely that their path to get there is non-linear. In a new blog, Richard Bejtlich (@taosecurity) talks about why #cyber defenders should be cautious of linear thinking and applies “the kill web”—an evolved take on the “kill chain” from the United States Department of Defense—to #cybersecurity. https://corelight.com/blog/kill-webs
Unleash your network security prowess on Oct. 4 at the Grand Canyon University's free, public training event from @corelight Open Source and @zeek! We're thrilled to present a day of turbocharged learning, fun and networking with a world class open source project. https://go.corelight.com/zeekday-grand-canyon-university
Zeek is the gold standard for network security monitoring that’s also the foundation for Corelight network evidence. Learn more: https://corelight.com/products/zeek/
My work is looking for a network monitoring service that is not Solarwinds. Anyone have any recommendations? #network #networkmonitoring #
#SymLink: The latest Gestalt IT Rundown highlights the impact of MLPerf 3 benchmark results, discussing performance improvements in AI training and energy efficiency, along with news on Intel's Gaudi2, Nvidia's NeMo model, the expansion of MLPerf @GestaltIT @sfoskett
https://gestaltit.com/rundown/stephen/mlperf-3-upsets-the-ai-apple-cart-gestalt-it-rundown-june-28-2023/
#AI #CentOS #Cloud #MLPerf #MLPerf3 #NetworkMonitoring #RHEL #Rundown
Artificial Intelligence & Machine Learning in Network Management - Since its inception in 1955, Artificial Intelligence has remained at the forefront... - https://readwrite.com/artificial-intelligence-machine-learning-in-network-management/ #aifornetworkmanagement #artificialintelligence #networkmanagement #networkmonitoring #machinelearning #ai
Had a great time interviewing Tarus Balog from the The OpenNMS Group for The Server Room Show Podcast
It will be aired as a two part episode as it is 1,5 hour of great conversation ( Episodes 63 and 64 on the 13th and 20th of February 2021 on anonradio, tilderadio and youtube)
Learn more:
2. What happens with your company data? (3/8)
#networkmonitoring should provide all the information necessary to meet compliance rules, as risks remain even without a breach of data protection. This is already the case when companies do not know if their data is at risk.