Elektrine lite

← Feed

@nomad@masto.hackers.town

Post #2257903

2026-05-06 20:36 UTC

I just had to slap quite the bandaid on our Splunk ingester. We were getting DDoS'd by a bunch of failed kerberos requests from certain gateway windows hosts resulting in the security log overwhelming our splunk license. The bandaid was to add that eventID to the blacklist on things that get sent to the indexer. I also opened a ticket saying "find a fail2ban for windows to fix this properly." I wonder if that'll ever happen. I do not like being blind to events like this.

Replies (1)