Blog Entries

07. 09. 2021 Alessandro Valentini Bug Fixes, Log-SIEM, NetEye

Bug Fixes for NetEye 4.19

We fixed two bugs in Logstash: an issue related to corrupted jvm.options configuration files, which prevents Logstash from starting properly a pipeline bug will cause Logstash to index every time in the same index which will grow up infinitely if a proper rollover template is not defined For NetEye 4.19 we updated the following packages:…

Read More
18. 08. 2021 Alessandro Valentini Bug Fixes, Log-SIEM, NetEye

Bug Fixes for NetEye 4.19

We fixed a bug in Logstash pipelines which causes, in some cases, logs to be written on the day before invalidating the logmanager blockchain. For NetEye 4.19 we updated the following packages: elasticsearch elasticsearch-autosetup elasticsearch-neteye-config elasticsearch-xpack-license elastic-stack-userguide filebeat filebeat-autosetup filebeat-neteye-config kibana kibana-autosetup kibana-neteye-config logstash logstash-autosetup logstash-neteye-config logstash-neteye-config-autosetup to version 7.12.1_neteye3.30.1-1

Read More
24. 06. 2021 Alessandro Valentini Contribution, NetEye

NetEye Backup: MariaDB

Roughly one year ago I started working on a set of backup scripts for NetEye with the following requirements: Cluster support without standby Configuration backups InfluxDB backup MariaDB backup In this post I’ll focus on the journey through my MariaDB backup implementation. Backing up MariaDB is usually a simple task: you run the mysqldump command…

Read More
04. 06. 2021 Alessandro Valentini Bug Fixes, NetEye

Bug Fixes for NetEye 4.18

We upgraded icingaweb2-module-vsphere to version 1.1.1 which fixes authentication issues with vSphere 7. For NetEye 4.18 we updated icingaweb2-module-vsphere to version 1.1.1_neteye1.3.1-1

Read More
29. 04. 2021 Alessandro Valentini Bug Fixes, Log-SIEM, NetEye

Bug Fixes for NetEye 4.17

We fixed a bug in the SIEM Module, which prevented Kibana Canvas to work properly. For NetEye 4.17 we updated the following packages: icingaweb2-module-kibana and icingaweb2-module-kibana-autosetup to version 1.17.1-1

Read More
22. 04. 2021 Alessandro Valentini Bug Fixes, Log-SIEM, NetEye

Bug Fixes for NetEye 4.17

SIEM Module We fixed a bug in SIEM Module which prevents Kibana to generate reports. For NetEye 4.17 we updated the following packages: elasticsearch elasticsearch-autosetup elasticsearch-neteye-config elasticsearch-xpack-license filebeat filebeat-autosetup filebeat-neteye-config kibana kibana-autosetup kibana-neteye-config logstash logstash-autosetup logstash-neteye-config logstash-neteye-config-autosetup to version 7.10.1_neteye3.22.1-1. Tornado Module We fixed a bug in Tornado which prevented, in cluster installations, the configuration…

Read More
02. 04. 2021 Alessandro Valentini NetEye

RPM Package Verification

Why it’s important to use signed packages RPM signing is an often underestimated feature: you use official repositories, why shouldn’t you trust them? Those repositories are also probably protected with TLS encryption, so you feel safe against man-in-the-middle attacks. But you may not be as safe as you think you are. Have you heard about that time when the repository…

Read More
25. 02. 2021 Alessandro Valentini NetEye

How I Became an Elastic Certified Professional, Part II

This post follows the one written some time ago by my colleague Mirko Bez. We became Elasticsearch Certified Professionals after passing both the Engineer exam and Analyst exam. In this post I’d like to tell you about my experience with the Analyst certification. This exam focuses mainly on Kibana, and 99% of the task can be done…

Read More
03. 02. 2021 Alessandro Valentini Bug Fixes, NetEye

Bug Fixes for NetEye 4.16

We improved the documentation about Icinga2 agent installation including detailed information about supported operating systems and versions. For NetEye 4.16 we updated to version 1.80.3-1 following packages: icingaweb2-module-neteye icingaweb2-module-neteye-autosetup

Read More
22. 10. 2020 Alessandro Valentini NetEye, Unified Monitoring

Kentix MultiSensor-LAN: Integration with NetEye4

Kentix MultiSensor is a device which includes many sensors for use in monitoring server and IT rooms. The sensor only needs to be connected to your network (PoE is required) and to have SNMP configured through its web interface. The LAN version we used in this test monitors: Temperature Humidity Dewpoint Fire (carbon monoxide) Motion…

Read More
05. 10. 2020 Alessandro Valentini Bug Fixes, NetEye

Bugfix for NetEye 4.14

We fixed an issue related to the execution of GLPI automatic actions. For NetEye 4.14 we updated: glpi, glpi-neteye-config and glpi-autosetup to the version 9.5.1_neteye1.9.2-1

Read More
08. 09. 2020 Alessandro Valentini Log-SIEM, NetEye

Sigma Rules in NetEye SIEM

In order to protect your business against cyber attacks you need to both harden your systems and promptly detect suspicious activities in your infrastructure. Sigma is an open source project which defines specifications for a standard signature format that allows you to describe relevant log events for security purposes. The Sigma rules language is intended…

Read More
07. 09. 2020 Alessandro Valentini Bug Fixes, NetEye

Bug Fixes for NetEye 4.13

With this bugfix release, we fixed a an issue causing tornado to crash when opening more than 1024 files . For NetEye 4.13 we updated: tornado, tornado-autosetup, tornado-common, tornado-neteye-config, tornado-rsyslog-collector-logmanager to version 0.39.6-1

Read More
01. 09. 2020 Alessandro Valentini Icinga Web 2, NetEye

NetPye: how to use a RaspberryPi as NetEye Satellite

This article explains how to set up a NetEye4 satellite using a Raspberry Pi. This is not an official guide and this solution is not officially supported. As test-bed I used a Raspberry Pi 4B with 4GB of ram, 32GB microSD card and NetEye 4.12 single-node installation as master. Master Configuration Add a new zone…

Read More
25. 06. 2020 Alessandro Valentini NetEye

Configuring Fencing on Dell Servers

As a NetEye User I want to handle node failures when they happen in my cluster. When a node becomes unresponsive, it might still be accessing your data: the only way to ensure that a node is truly offline is to shut it down. This procedure is called fencing. NetEye 4 relies on Corosync/Pacemaker, also…

Read More

Archive