Blog Entries

23. 09. 2025 Luigi Miazzo Bug Fixes, NetEye

Bug Fixes for NetEye 4.43

Satellite config creation in HA mode using zone names with whitespaces We’ve addressed an issue where running the neteye satellite config create for a satellite configured in HA mode having whitespaces in the Zone name prevented the procedure to successfully execute. List of updated packages To solve the issues mentioned above, the following packages have…

Read More
23. 09. 2025 Csaba Remenar NetEye

Minimizing Downtime: NetEye MariaDB Database Rebuild with Containers and Logical Backup

Familiar with the feeling when a critical system’s backup and recovery time is measured in hours? Operations teams rely heavily on the availability of monitoring data, so scheduling long periods of downtime is simply not an option. We recently faced this exact challenge: we had to schedule a multi-hour downtime because our MariaDB database had…

Read More
19. 09. 2025 Matteo Cipolletta NetEye

Native Monitoring of the Logstash Dead Letter Queue

When working with Logstash in production, one of the often-overlooked areas is the Dead Letter Queue (DLQ). This queue stores events that Logstash cannot process, usually due to parsing errors, mapping conflicts, or pipeline misconfigurations. While the DLQ is useful for troubleshooting, leaving it unmonitored can be dangerous: if it grows unnoticed, critical data might…

Read More
19. 09. 2025 Alessandro Taufer Development, DevOps

How to Debug Your Kernel Calls

Unexpected reboots, who doesn’t love them? A few weeks ago, we faced a problem that any platform engineer dreads: one of our nodes rebooted unexpectedly. The cause? The iDRAC watchdog forcefully terminated it. But what led iDRAC to decide it was time to shut down the node? A preliminary investigation concluded that there wasn’t any…

Read More
16. 09. 2025 Davide Sbetti DevOps, Kubernetes

Monitoring DBs through PMM: a Migration to OpenShift

Hi 😀 Today I’d like to explore with you a migration that we performed to a service that’s used internally to monitor the performance of various DBs, gathering data that’s especially useful for troubleshooting. This tool is the Percona Monitoring and Management (PMM) platform, which combines agents or direct access to various supported DBMS (MySQL,…

Read More
15. 09. 2025 Reinhold Trocker Log Management, Log-SIEM

Want to Manage a Large Elastic Agent Fleet?

Managing a large fleet of Elastic Agents efficiently requires careful planning and proactive strategies to ensure stability, scalability, and security. As a technical consultant, I’d like to present some key considerations to help organizations avoid common pitfalls and streamline their operations. 1. Avoid Trust Issues One of the most critical aspects of managing an extensive…

Read More
13. 09. 2025 Mirko Ioris Blue Team, SEC4U

A Practical Guide to Working with Windows Authentication Logs – Part 2

Welcome back for the second and last part of our journey into the jungle of Windows logs! In the first part we set out our goal – tracking admin authentications – and learned more about Windows, how authentication events are logged, and where can we focus to isolate the most accurate events. Today we’re going…

Read More
12. 09. 2025 Francesco Belacca Azure, Microsoft, Power Platform

Bulk-assigning Power Apps to Flow Owners

TL;DR. Owner assignment on the Power Platform via the UI requires a lot of clicks. I use a small, idempotent PowerShell 7+ script that assigns co-owners to many cloud flows across many environments using az tokens and Flow Admin REST APIs. It filters by name prefix, checks existing permissions, retries on throttling, and runs on…

Read More
11. 09. 2025 Andrea Mariani NetEye, PHP, Unified Monitoring

Using Keycloak to Secure Web Pages and Virtual Directories

While working on some internal tools, I needed secure access to a few PHP pages and virtual directories resources that, by default, didn’t have any built-in access control. Since NetEye already uses Keycloak as its authentication system, I decided to leverage it to handle login and user validation. This way I could avoid reinventing the…

Read More
11. 09. 2025 Davide Zeni Bug Fixes, NetEye

Bug Fixes for NetEye 4.43

Dashboard Graphs Now Use Full Width We’ve addressed an issue where service and host graphs on dashboards were not utilizing the full available width. This fix ensures the charts now expand to fill the space, providing a better and clearer data visualization. List of updated packages To solve the issues mentioned above, the following packages…

Read More
09. 09. 2025 Franco Federico NetEye

Backing up a MariaDB Galera Cluster

With NetEye version 4.42, we’re excited to introduce a clustered solution for MariaDB – MariaDB Galera – designed to enhance the high availability of all NetEye services. This improvement significantly increases the reliability of services that depend on the database, such as Icinga 2, Icinga Web 2, Grafana, Keycloak, and others. Thanks to this new…

Read More
08. 09. 2025 Alessandro Romboli Service Management

VMware ESXi Transparent Page Sharing

Scenario TPS (Transparent Page Sharing) is a proprietary functionality in VMware ESX(i) which essentially does deduplication of memory pages used for virtual machines. Identical memory content across multiple machines thus only consumes memory once. When you have multiple virtual machines with the same guest operating system running, there’s a high chance of identical content which…

Read More
05. 09. 2025 Beatrice Dall'Omo Red Team, SEC4U

Setting up a Vulnerability Enrichment Process: Prioritizing Risks Effectively

In the context of vulnerability management, it’s common to be faced with a long list of findings after each scan, often too many to tackle all at once. But how do you decide where to focus your efforts and resources? Which vulnerabilities are truly critical, the ones that could actually compromise your organization’s security? The…

Read More
02. 09. 2025 Alessandro Mizzaro Bug Fixes, NetEye

NetEye 4 – Security Advisory (SIEM)

Important: Elastic Stack security update (installed with SIEM) Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic An update for the elasticsearch package is now available for NetEye 4. Security Fix for NetEye 4.43 CVE-2025-54988 (Apache Tika): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/MPR:L For a detailed overview of the security issue(s), including the impact, CVSS score, acknowledgments,…

Read More
01. 09. 2025 Luigi Miazzo Bug Fixes, NetEye

Bug Fixes for NetEye 4.43

Fix redirect to __SELF__ We resolved a bug for which sometimes during the login workflow an automatic redirect to __SELF__ was performed, forcing the user to manually change the URL on the browser tab. List of updated packages To solve the issues mentioned above, the following packages have been updated for NetEye 4.43:

Read More

Archive