Blog Entries

28. 03. 2022 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.22

We fixed a bug for which the healthcheck 00400_local_neteye_target_services_are_disabled was failing on NetEye Satellites due to some services enabled by default on the NetEye Satellites. The healthcheck now does not control the state of such services on Satellites. For NetEye 4.22 we updated the following packages: neteye-setup to version 1.83.4-1

Read More
25. 03. 2022 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.22

We fixed a bug for which the healthcheck 01220_telegraf_retention_policy_set was failing on NetEye Satellites. The healthcheck is now skipped on Satellites. For NetEye 4.22 we updated the following packages: icingaweb2-module-analytics, icingaweb2-module-analytics-autosetup to version 1.48.3-1

Read More
02. 03. 2022 Damiano Chini APM, Log-SIEM, NetEye

Observing Events in Tornado with Elastic APM

Sometimes you’d just really like to have an overview of what happens to the Events that flow through Tornado. Where do they come from? Did they get stuck somewhere in the Collectors or in Tornado? Which Tornado Actions did they trigger? Gathering all this information from hundreds of log lines across different services (i.e., Tornado…

Read More
28. 02. 2022 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.22

We fixed a bug in El Proxy, which caused the El Proxy service to not being able to sign new logs after a restart, in the particular case that the last signed log of the blockchain was put in the Dead Letter Queue. For NetEye 4.22 we updated the following packages: elastic-blockchain-proxy, elastic-blockchain-proxy-autosetup to version…

Read More
22. 02. 2022 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.22

We fixed a bug in Tornado which caused rules to not match if the ${item} of the ForEach action was interpolated with other strings. For NetEye 4.22 we updated the following packages: tornado, tornado-autosetup, tornado-common, tornado-neteye-config, tornado-dto, tornado-rsyslog-collector to version 1.18.3-1

Read More
18. 02. 2022 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.22

We fixed a bug in Tornado which caused Elastic APM to be unable to relate the traces coming from the Tornado Collectors to the traces of the Tornado Engine. For NetEye 4.22 we updated the following packages: tornado, tornado-autosetup, tornado-common, tornado-neteye-config, tornado-dto, tornado-rsyslog-collector to version 1.18.2-2 icingaweb2-module-tornado, icingaweb2-module-tornado-autosetup to version 1.5.0-3 icingaweb2-module-tornadocarbon, icingaweb2-module-tornadocarbon-autosetup to version…

Read More
31. 12. 2021 Damiano Chini Development, Log Management, Log-SIEM, NetEye

Real Time Log Signing on Fleet-managed Elastic Agents – A Preliminary Investigation

The R&D Team is currently working on the integration of the new Elastic Fleet management tool in NetEye 4. Once Elastic Fleet is fully integrated in NetEye 4, all of the Log Management features currently supported will also need to work with the Elastic Fleet. In particular, the integration of Elastic Fleet with the Log…

Read More
31. 12. 2021 Damiano Chini Development, NetEye

Tornado Monitoring and Statistics

When I’m running a service which processes a lot of data, sooner or later I start to wonder: what is the service doing? What data is it processing? This also applies to our event processor Tornado. For the Tornado Engine, the administrator may wonder for example how many events Tornado is receiving, how many actions…

Read More
17. 12. 2021 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.21

We fixed a bug in NetEye 4.21 that caused the healthcheck command to fail when executed on NetEye Satellites. For NetEye 4.21 we updated the following packages: tornado, tornado-autosetup, tornado-common, tornado-neteye-config to version 1.12.1-1

Read More
18. 10. 2021 Damiano Chini Bug Fixes, NetEye, SLM

Bug Fixes for NetEye 4.19

We fixed a bug in the SLM Reports, wherein case the icinga2 downtime depth at the beginning of the report was greater than 1, the report would consider the downtime depth equal to 1. This bug was also raising an error when PGSQL was enabled. For NetEye 4.19 we updated the following packages: icingaweb2-module-slm to…

Read More
30. 09. 2021 Damiano Chini Development, NetEye

Tornado: Tracing

How can we allow a Tornado administrator to successfully track down the flow of an event through Filters, Rules and Actions of Tornado, when Tornado is processing thousands of events per second? Tornado administrators can have a hard time reading Tornado logs to understand where for example an action error comes from. Take this log…

Read More
14. 09. 2021 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.19

We fixed a bug that caused the yum groups “neteye” and “neteye-tools” to not being marked as installed on some NetEye instances. For NetEye 4.19 we updated the following packages: neteye-setup to version 1.75.1-1

Read More
01. 07. 2021 Damiano Chini Log Management, Log-SIEM, NetEye

El Proxy – Error Handling

Beginning with NetEye 4.17, the NetEye Log Management module has been able to rely on the new Real Time Log Signing architecture, which aims to overcome some weaknesses in the previous Log Management implementation based on rsyslog. One of the core components of the new architecture is the new El Proxy daemon, whose tasks are…

Read More
07. 04. 2021 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.17

We fixed a bug in the Log Manager for which it was not possible to verify Elasticsearch blockchains containing more than 10,000 documents. For NetEye 4.17 we updated the following packages: elastic-blockchain-proxy and elastic-blockchain-proxy-autosetup to version 0.8.1-1

Read More
01. 04. 2021 Damiano Chini Development, Log Management, Log-SIEM, NetEye

Log Management – Real Time Log Signing

Meeting the highest security standards is an absolute priority in NetEye. For this reason, in the continuous process of improving security in NetEye 4, we brought an important architectural improvement in the Log Manager module in the NetEye 4.17 release. The new architecture takes the name of Real Time Log Signing and its main focus…

Read More

Archive