Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
LochNessMonster
Feb 3, 2005

I need about three fitty


Solaron posted:

Well, this process is managed overseas and they're not really open to giving us access to see the inner workings, so I only know what they're telling me. I own the SIEM and that's why I'm even having to be involved. I'm told that Splunk is just forwarding the logs they receive from Netscaler but we're seeing IPADDR TIMESTAMP IPADDR instead of the 3164 format of <PRI> TIMESTAMP IPADDR when we receive the logs from Splunk, and it's breaking the parser.

I can only assume they're massaging the data on their end somehow but all I'm being told is 'Splunk doesn't offer any options to let us modify this'.

Put logstash on your end and strip the useless crap from it.

If you're using ArcSight you can use the CEF codec to format your data.

Adbot
ADBOT LOVES YOU

LochNessMonster
Feb 3, 2005

I need about three fitty


ChubbyThePhat posted:

drat this actually looks fun.

It does. Are there tutorials that teach you these kind of things because I'm reading this with close attention but would have no clue where to begin on stuff like this.

LochNessMonster
Feb 3, 2005

I need about three fitty


Furism posted:

Check your PMs.

I'm looking to move in the same direction. Could you PM me the same info?

LochNessMonster
Feb 3, 2005

I need about three fitty


Thanks Ants posted:

I've not seen the usual vendors crawl out of their holes to tell people to use their Internet security suite that tunnels everything back to their :yaycloud: yet, presumably that's on the way

You can stop checking LinkedIn for the next 2-4 weeks because every vendor will be unbearable.

LochNessMonster
Feb 3, 2005

I need about three fitty


If you're setting up a large environment you have to think about CA's, sub CA's, publishing of ARL's/CRL's and how you want devices to retrieve certs (scep/cmp) etc.

And what precious posters said about building a trust and how to manage that trust so it doesn't become worthless due to people loving things up.

Adbot
ADBOT LOVES YOU

LochNessMonster
Feb 3, 2005

I need about three fitty


EssOEss posted:

You can paste a key here to check it: https://keychest.net/roca
Another site is https://keytester.cryptosense.com/

Ars Technica says it is Estonia and Slovakia that are vulnerable (I misremembered the second one earlier). I did find the Portugese cards listed on Gemalto's website. As Gemalto was the provider of the Infineon-manufactured cards to Estonia, there is some cause to suspect a link here, indeed.


Yeah, the RNG vulnerability that affects the TPMs is the exact same as the one for the ID cards. In both cases, they generate RSA keys that are not as unpredictable as they should be.

Gemalto hasn't come forward with an official reaction yet. They're "working on it".

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply