Lawrence

1.1K posts

Lawrence banner
Lawrence

Lawrence

@only_Lawrence

Learning networking & cybersecurity , Cisco NetAcad | Blue Team path Documenting the journey to SOC Analyst | Learning in public

127.0.0.1 Katılım Aralık 2023
325 Takip Edilen220 Takipçiler
Lawrence
Lawrence@only_Lawrence·
Installed Splunk Enterprise on my Ubuntu VM today. Network was 45Kbps all day so the BOTS dataset download is still running, I wasnt able to finish it . But Splunk is up and running on localhost:8000. Tomorrow the actual queries start. #SOCAnalyst #Splunk
Lawrence tweet mediaLawrence tweet mediaLawrence tweet mediaLawrence tweet media
English
0
0
2
13
Dhruv Kumar
Dhruv Kumar@dhruvkumar1805·
finally hit 50 followers 🎉 didn't go viral, didn't do anything special just showed up every day drop your GitHub below, let's connect there too👇
English
78
0
77
2K
siddharth
siddharth@buildwithsid·
kindly share your github profile i wanna judge you
English
587
6
501
71.6K
Lawrence
Lawrence@only_Lawrence·
@simply_eju As I see this thing, na once I burst 😂😂😂😭
English
0
0
0
1
captain
captain@simply_eju·
See kolu😂😂
captain tweet media
Eesti
1
0
1
4
Lawrence retweetledi
Elorm Daniel
Elorm Daniel@elormkdaniel·
.@cyber_razz has been restored 🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥
Elorm Daniel tweet media
English
8
3
30
4K
Lawrence
Lawrence@only_Lawrence·
So when I generated a user.info message: Facility = 1, Severity = 6 PRI = (1 × 8) + 6 = 14 I also generated messages at all 8 severity levels using the logger command — from emergency (0) all the way to debug (7). All 8 showed up in /var/log/syslog including debug
English
1
0
1
42
Lawrence
Lawrence@only_Lawrence·
Today I learned how syslog actually works under the hood. Every syslog message has a PRI value that encodes two things at once — the facility (what system sent it) and the severity (how serious it is). Formula: PRI = (Facility × 8) + Severity
Lawrence tweet mediaLawrence tweet media
English
1
0
3
22
Lawrence
Lawrence@only_Lawrence·
Everyone talks about SIEMs. Nobody talks about how the logs actually get there. Windows doesn't speak syslog. Cloud doesn't push logs to you. Network devices lose logs if your collector goes down. The SIEM is just the end of a pipeline.
English
0
1
2
31