Forum
Top
Newest
Ask
Search
Sign in
Top
Newest
All time
1
▲
FortiGate logid 0000000013 is 90% of my log volume. Can I drop it?
31 points by
shadepl
1 month ago
·
3 answers
2
▲
What open-source tools do you use for security monitoring?
27 points by
aklaha
1 month ago
·
5 answers
3
▲
Windows 4625 failed logon every morning at exactly the same time
26 points by
a8hda
1 month ago
·
4 answers
4
▲
Everyone ignores our alerts. How do we fix that without turning them all off?
24 points by
cclondon
1 month ago
·
4 answers
5
▲
Does anyone here dealt with siem platform pricing lately?
22 points by
cclondon
1 month ago
·
5 answers
6
▲
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
(slcyber.io)
21 points by
shadepl
29 days ago
·
2 answers
7
▲
How do I alert on something not happening?
19 points by
aklaha
1 month ago
·
3 answers
8
▲
wp2shell: pre-authentication RCE in WordPress core
(wp2shell.com)
18 points by
dcid
(Daniel)
26 days ago
·
answer
9
▲
GitHub issues $100,000 bounty for critical RCE vulnerability
(runtimewire.com)
18 points by
dcid
(Daniel)
1 month ago
·
1 answer
10
▲
PCI DSS says 12 months of logs, does that mean 12 months of everything?
17 points by
gerald
(Gerald)
1 month ago
·
3 answers
11
▲
What Windows event IDs are actually worth collecting?
16 points by
javiiw
1 month ago
·
3 answers
12
▲
PCI 10.7, detecting failures of security controls. What does an assessor want to see?
15 points by
tony
(Tony)
1 month ago
·
2 answers
13
▲
Synthetic log generators for SIEM testing
(github.com)
15 points by
shadepl
1 month ago
·
answer
14
▲
What should I be looking for in the logs for wp2shell?
14 points by
cclondon
26 days ago
·
3 answers
15
▲
Nginx access logs are 95% of my ingest, what can I safely drop?
14 points by
cclondon
1 month ago
·
2 answers
16
▲
Event 1102, the audit log was cleared. How seriously should I take this?
13 points by
gerald
(Gerald)
28 days ago
·
2 answers
17
▲
How much log storage per server, roughly?
13 points by
shadepl
1 month ago
·
2 answers
18
▲
rsyslog vs syslog-ng vs journald forwarding for shipping off-host
12 points by
vivida
(David)
1 month ago
·
2 answers
19
▲
How do I stop one broken app from eating all my log storage?
11 points by
aklaha
25 days ago
·
2 answers
20
▲
Should I log allowed firewall traffic, or only blocks?
11 points by
vivida
(David)
1 month ago
·
2 answers
21
▲
Security Policies - Logging Best practice
11 points by
gerald
(Gerald)
1 month ago
·
2 answers
22
▲
Microsoft 365 audit logs, which feeds are actually useful?
10 points by
vivida
(David)
29 days ago
·
2 answers
23
▲
Logon Type 3 is flooding my logs, can I filter it out?
10 points by
a8hda
1 month ago
·
1 answer
24
▲
Is it worth normalising logs to ECS or OCSF?
9 points by
aklaha
1 month ago
·
2 answers
25
▲
My log timestamps are hours off and correlation is impossible
9 points by
mcaptain
1 month ago
·
2 answers
26
▲
Implementing SIEM for my small size company
9 points by
a8hda
1 month ago
·
5 answers
27
▲
Why are my syslog messages truncated at 1024 characters?
8 points by
palegreen
23 days ago
·
1 answer
28
▲
Azure sign-in logs showing countries nobody in the company has visited
8 points by
shadepl
24 days ago
·
1 answer
29
▲
Agent based or agentless collection at 200 servers?
8 points by
mbxsec
26 days ago
·
3 answers
30
▲
OSSEC or Wazuh?
8 points by
notthebear
1 month ago
·
2 answers
More
Guidelines
Newest
Search
Back to Trunc