Blog Entries

23. 03. 2026 Alessandro Valentini Uncategorized

How to collect Cloudwatch AWS logs in NetEye

Recently, we had to monitor an EKS cluster and several other resources using NetEye. AWS already provides solid dashboards out of the box, but log analysis is not as flexible as in Elasticsearch, and costs can easily grow out of control. Our goals were: AWS CloudWatch is a monitoring and observability service that collects logs,…

Read More
23. 03. 2026 Simone Ragonesi Offensive Security, Red Team, SEC4U, Uncategorized

Writing High Quality Pentesting Reports

A pentest is only as valuable as the report that comes out of it. You can find critical vulnerabilities, chain exploits creatively, and demonstrate full infrastructure compromise, but if your report is unclear, overly technical, or poorly structured, its impact will be limited. A strong pentesting report bridges the gap between technical discovery and business…

Read More
23. 03. 2026 Alessio Dallaporta Blue Team

Inside Elastic Security Detection Rules: Internal Structure & Upgrade Mechanics

A Rule Is More Than a Query In modern detection engineering, a rule is often misunderstood as just a query that triggers alerts. In reality, within Elastic Security, a detection rule is a structured, versioned, and lifecycle-managed object that goes far beyond simple query logic. Understanding this structure is essential for anyone operating in a…

Read More
21. 03. 2026 Andrea Mariani AI

Reflections on Running LLMs Locally: Why It Is Worth Running Them on Your Own Infrastructure

Model selection, infrastructure sizing, vertical fine-tuning and MCP server integration. All explained without the fluff. Why Run AI on Your Own Infrastructure? Let’s be honest: over the past two years, LLMs have evolved from a tool perceived as experimental and reserved for researchers into something companies use every day for concrete, practical tasks. And with…

Read More
19. 03. 2026 Dennis Orlando Bug Fixes, NetEye

Bug Fixes for NetEye 4.46

We addressed the following issues in the Alyvix module UI: List of updated packages

Read More
18. 03. 2026 Francesco Belacca Uncategorized

Thanks EU: LinkedIn Finally Gave Me My CV Data

TL;DR The Challenge LinkedIn is my single source of truth for professional experience. Every new role, certification, or skill update goes there first. A person’s CV should reflect those changes automatically – not weeks later when he or she remembers to manually copy information across formats and through different portals. The idea was simple: build…

Read More
16. 03. 2026 Daniele Saccon APM, Knowledge Management, Log-SIEM, Training

Inside Elastic Certifications: My Experience Between Preparation and Exams

In this article I’d like to share my experience with Elastic certifications. Recently, I had the opportunity to take the Elastic Certified Engineer and Elastic Certified Observability Engineer exams and I’d like to describe my preparation, experience and finally share some useful tips for anyone else who wants to follow the same path. Overview of…

Read More
16. 03. 2026 Francesco Penasa APM, Development

Bringing OpenTelemetry to Flutter Android for Client-side Observability

Because “it works on my machine” is not an observability strategy. How It Started As an observability engineer, my workflow when starting a new project is pretty consistent: find the OpenTelemetry SDK for the language or framework in use, understand its quirks and limitations, and build from there. So when I picked up a Flutter…

Read More
13. 03. 2026 Davide Sbetti Bug Fixes, NetEye

Bug Fixes for NetEye 4.46

Error during GLPI inventory task execution We have fixed a bug related to the Asset Management module and in particular in the usage of the GLPI inventory plugin to gather the inventory. List of updated packages To solve the issue mentioned above, the following packages have been updated for NetEye 4.46:

Read More
11. 03. 2026 Daniel Degasperi Blue Team, Log-SIEM, SEC4U, Threat Intelligence

From Static Lists to Threat Intelligence: Better Domain Detection in Elastic

A scalable approach to detecting malicious domains using Threat Intelligence and Indicator Match Rules One of the most common techniques used in phishing and initial access campaigns is the creation of domains that closely resemble legitimate ones. Attackers exploit typosquatting, homograph attacks, and brand impersonation to deceive users and steal credentials. For a Security Operations…

Read More
10. 03. 2026 Franco Federico Unified Monitoring

Elastic AutoOps in NetEye: Simplifying Elasticsearch Operations with Real-Time Intelligence

Introduction Managing Elasticsearch effectively – especially as environments grow in size and complexity – can quickly become a challenging task. Performance tuning, identifying the true root cause behind slowdowns, and optimizing resource allocation often demand specialized expertise and a significant investment in time. In enterprise ecosystems, where observability underpins critical services and reliability expectations are…

Read More
06. 03. 2026 Damiano Chini Log-SIEM, NetEye

One Elastic Fleet Policy, Multiple Behaviors: Selective Agent Configuration with Agent Providers

In many Elastic deployments, the natural approach every time you encounter a server with different needs is to create a new Fleet policy. Each group seems to require its own small set of tweaks or additional integrations. But the more policies you create, the harder it becomes to maintain and scale your configuration. In reality…

Read More
05. 03. 2026 Alice Rozzoni Atlassian

A Future-ready Knowledge Base

Once upon a time, humanity passed down epic stories and religious texts by memory alone. Entire civilizations relied on oral tradition to preserve their most important knowledge. Fast‑forward a few thousand years, and some companies are still doing the same thing with their procedures and information: trusting that Bob from Accounting… would “just remember it.”…

Read More
05. 03. 2026 Gianluca Piccolo Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.46 Summary The vulnerability is about a Stored XSS and an Authenticated SQL Injection. For details on how to apply this update, which…

Read More
04. 03. 2026 Damiano Chini Bug Fixes, NetEye

NetEye 4 – Security Advisory (Lampo)

Important: Lampo security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the lampod packages is now available for NetEye 4. Security Fix for NetEye 4.46 Summary The vulnerability is about sensitive information exposure due to improper error handling. For details on how to apply this update, which…

Read More

Archive