Tag: monitoring

  • Why Wazuh

    Something has to watch the machines themselves. Not the edge, where attackers arrive from the internet, but the hosts: files changing that should not change, packages with known vulnerabilities, logins that succeeded and should not have, a process doing something…

    Read on →

  • Ninety-seven percent of the alerts were one monitor

    A monitor checking that certificate issuance still worked had been alternating between down and up on every single cycle, for at least four days. Roughly 540 state changes a day, each one sending a notification.

    Read on →

  • Status: the lab stops being one machine

    The second physical server is online. For the first time this project is not one computer with a lot of ambition attached to it.

    Read on →

  • The alert fired six times and the test said it did not

    A new alert had just been added to catch a server simply dying. Proving it meant inducing the failure: stop the thing that reports the machine is alive, wait, and confirm the alert fires and the notification arrives.

    Read on →

  • Exit 3 means either

    A new test suite reported a problem on two healthy gateways. The lab’s monitoring notes said drift was zero on both machines. One of the two had to be wrong, and finding out which produced a defect worth more than…

    Read on →

  • Why CrowdSec

    Anything with a public address is attacked continuously, within minutes of existing, by software that is not interested in what it found. The rented gateways in this lab carry that traffic all day.

    Read on →

  • Status: the loop is closed

    The tunnel from the rented edge to the house is up and carrying traffic. That was the last structural piece of the original design never exercised end to end, and it has now been exercised in both directions.

    Read on →

  • The check that punished uptime

    A test asserted that the tunnel between two servers was up. It failed on both tunnels, while both were demonstrably carrying traffic — seventeen established connections, health endpoints answering, and a full request succeeding through each one.

    Read on →

  • If the watcher dies, its last words are reassuring

    The monitoring system was switched off for eighteen minutes. Every monitor reported UP for the entire period.. Status 1 is UP. Both rows were real, correct, and eighteen minutes old.

    Read on →

  • Status: the first VMs, and the tier they unblock

    Three virtual machines exist. After weeks of rented gateways and documents, something is finally running on hardware in the building.

    Read on →