<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Expert on sekureco42</title><link>https://sekureco42.ch/tags/expert/</link><description>Recent content in Expert on sekureco42</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>&amp;copy; 2025 rOger Eisenecher</copyright><lastBuildDate>Thu, 24 Jul 2025 12:17:15 +0100</lastBuildDate><atom:link href="https://sekureco42.ch/tags/expert/index.xml" rel="self" type="application/rss+xml"/><item><title>Use Grafana Alloy with SigLens</title><link>https://sekureco42.ch/posts/grafana-alloy-with-siglens/</link><pubDate>Thu, 24 Jul 2025 12:17:15 +0100</pubDate><guid>https://sekureco42.ch/posts/grafana-alloy-with-siglens/</guid><description>&lt;p>Until now I used vector.dev as my workhorse to collect logs and metrics from systems and deliver them to SigLens. In the mean time there is a new kid on the block: Grafana Alloy. In this article I will show you how you connect Grafana Alloy to your SigLens instance.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/grafana-alloy-with-siglens/featured.png"/></item><item><title>Phishing detection with LLM</title><link>https://sekureco42.ch/posts/phishing-detection-with-llm/</link><pubDate>Thu, 16 Jan 2025 20:16:06 +0100</pubDate><guid>https://sekureco42.ch/posts/phishing-detection-with-llm/</guid><description>&lt;p>In a recent project I tried to automate the phishing handling process. So if an email is reported as suspicious from end user the email is sent to a sandbox for a verdict and guess what: The sandbox mostly comes to the conclusion that the email is safe. But: IT IS NOT!&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/phishing-detection-with-llm/featured.png"/></item><item><title>Split log streams into Analytics and Auxiliary Table</title><link>https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/</link><pubDate>Fri, 22 Nov 2024 16:34:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/</guid><description>&lt;p>In the last article we found out that KQL transformation at ingestion time is not available for Auxiliary Logs. But in real cases you want to have the ability to send selective log lines to Analytics while sending the rest to Auxiliary. In this article we will discover the possibilities.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/split-log-streams-into-analytics-and-auxiliary-table/featured.png"/></item><item><title>Remap column names in Data Collection Rules (DCR)</title><link>https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/</link><pubDate>Thu, 21 Nov 2024 07:46:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/</guid><description>&lt;p>In real world scenarios you have a data source with field names which are not identical to those in your table. Beside of renaming the fields in your agent which sending logs also Data Collection Rules provide the ability to map fields with &lt;code>transformkql&lt;/code>.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/remap-column-names-in-data-collection-rule/featured.png"/></item><item><title>Auxiliary Logs in Azure Log Analytics</title><link>https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/</link><pubDate>Wed, 13 Nov 2024 17:29:12 +0100</pubDate><guid>https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/</guid><description>&lt;p>Microsoft provides a new type of Log Analytics tables called Auxiliary Logs. Currently this is in Public Preview and I did some lab testing which I documented in this blog post.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/auxiliary-logs/azure-log-analytics-with-auxiliary-log-tables/featured.png"/></item><item><title>Use Prometheus Node Exporter with SigLens and Vector.dev</title><link>https://sekureco42.ch/posts/prometheus-node-exporter-with-siglens-and-vector.dev/</link><pubDate>Wed, 15 May 2024 10:17:15 +0100</pubDate><guid>https://sekureco42.ch/posts/prometheus-node-exporter-with-siglens-and-vector.dev/</guid><description>&lt;p>Some days ago I discovered SigLens the first time and wrote a blog post about feeding logs into it with the help of Vector.dev. SigLens does not only provide fast log management - no; it also supports metrics. In this article I show you how to setup ingestion of metrics from Prometheus Node Exporters.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/prometheus-node-exporter-with-siglens-and-vector.dev/featured.png"/></item><item><title>Fast log management with SigLens and Vector.dev</title><link>https://sekureco42.ch/posts/log-management-with-siglens-and-vector.dev/</link><pubDate>Mon, 13 May 2024 22:29:15 +0100</pubDate><guid>https://sekureco42.ch/posts/log-management-with-siglens-and-vector.dev/</guid><description>&lt;p>A new star is born and my new personal favorite if you have to deal with logs: The Log Management solution from &lt;a href="https://siglens.com/" target="_blank" rel="noopener">https://siglens.com/&lt;/a> &lt;span class="text-xs">
&lt;span class="inline-block icon">
&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512">&lt;!--! Font Awesome Pro 6.2.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license (Commercial License) Copyright 2022 Fonticons, Inc. -->&lt;path fill="currentColor" d="M320 0c-17.7 0-32 14.3-32 32s14.3 32 32 32h82.7L201.4 265.4c-12.5 12.5-12.5 32.8 0 45.3s32.8 12.5 45.3 0L448 109.3V192c0 17.7 14.3 32 32 32s32-14.3 32-32V32c0-17.7-14.3-32-32-32H320zM80 32C35.8 32 0 67.8 0 112V432c0 44.2 35.8 80 80 80H400c44.2 0 80-35.8 80-80V320c0-17.7-14.3-32-32-32s-32 14.3-32 32V432c0 8.8-7.2 16-16 16H80c-8.8 0-16-7.2-16-16V112c0-8.8 7.2-16 16-16H192c17.7 0 32-14.3 32-32s-14.3-32-32-32H80z"/>&lt;/svg>
&lt;/span>
&lt;/span>
together with &lt;a href="https://vector.dev/" target="_blank" rel="noopener">https://vector.dev/&lt;/a> &lt;span class="text-xs">
&lt;span class="inline-block icon">
&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512">&lt;!--! Font Awesome Pro 6.2.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license (Commercial License) Copyright 2022 Fonticons, Inc. -->&lt;path fill="currentColor" d="M320 0c-17.7 0-32 14.3-32 32s14.3 32 32 32h82.7L201.4 265.4c-12.5 12.5-12.5 32.8 0 45.3s32.8 12.5 45.3 0L448 109.3V192c0 17.7 14.3 32 32 32s32-14.3 32-32V32c0-17.7-14.3-32-32-32H320zM80 32C35.8 32 0 67.8 0 112V432c0 44.2 35.8 80 80 80H400c44.2 0 80-35.8 80-80V320c0-17.7-14.3-32-32-32s-32 14.3-32 32V432c0 8.8-7.2 16-16 16H80c-8.8 0-16-7.2-16-16V112c0-8.8 7.2-16 16-16H192c17.7 0 32-14.3 32-32s-14.3-32-32-32H80z"/>&lt;/svg>
&lt;/span>
&lt;/span>
for log ingestion. This article describes the basic setup and the state of the project per may 2024.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/log-management-with-siglens-and-vector.dev/featured.png"/></item><item><title>Deploy Ubuntu 24.04 (Noble Numbat) with Autoinstall to Proxmox</title><link>https://sekureco42.ch/posts/deploy-ubuntu-24.04-with-autoinstall-to-proxmox/</link><pubDate>Sun, 28 Apr 2024 19:37:15 +0100</pubDate><guid>https://sekureco42.ch/posts/deploy-ubuntu-24.04-with-autoinstall-to-proxmox/</guid><description>&lt;p>Ubuntu provides several methods to automatically install Ubuntu on systems. This article will describe the method with an Autoinstall file to automatically make the base setup of the system.&lt;/p>
&lt;!-- more -->
&lt;h2 class="relative group">Introduction
&lt;div id="introduction" class="anchor">&lt;/div>
&lt;/h2>
&lt;p>When setting up VMs based on Ubuntu, I often go through the same setup steps. Naturally, I do this with Ansible. However, there&amp;rsquo;s a bit of a chicken-and-egg scenario: to manage the system with Ansible, a defined user must exist, along with an SSH key.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/deploy-ubuntu-24.04-with-autoinstall-to-proxmox/featured.png"/></item><item><title>Azure Batch and how to avoid misuse</title><link>https://sekureco42.ch/posts/azure-batch-mitigation/</link><pubDate>Tue, 23 Apr 2024 18:22:15 +0100</pubDate><guid>https://sekureco42.ch/posts/azure-batch-mitigation/</guid><description>&lt;p>Azure Batch is quite powerful tool if you want to scale compute intensive tasks in your environment due it lets you manage scaled workload in Azure. This article will present counter measure to reduce the risk of misuse.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/azure-batch-mitigation/featured.png"/></item><item><title>Deploy Windows 11 Dev VM to Proxmox</title><link>https://sekureco42.ch/posts/deploy-windows-11-dev-vm-to-proxmox/</link><pubDate>Sun, 21 Apr 2024 12:22:15 +0100</pubDate><guid>https://sekureco42.ch/posts/deploy-windows-11-dev-vm-to-proxmox/</guid><description>&lt;p>Microsoft provides Windows 11 Developer VMs for several Hypervisors like VMware, Hyper-V and more - but not for Proxmox. This article shows how to automate the process of deploying Windwos 11 Developer VM to Proxmox.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/deploy-windows-11-dev-vm-to-proxmox/featured.png"/></item><item><title>Add automatically Catch-All addresses as Send-from addresses in Exchange Online</title><link>https://sekureco42.ch/posts/add-automatically-catch-all-addresses-as-send-from-addresses-in-exo/</link><pubDate>Wed, 19 Apr 2023 07:59:15 +0100</pubDate><guid>https://sekureco42.ch/posts/add-automatically-catch-all-addresses-as-send-from-addresses-in-exo/</guid><description>&lt;p>In previous post I wrote about several possibilities to automate tasks in Azure. In this post I will show you an additional possibility to automate tasks in a cloud native environment with the help of &lt;code>Automation Account&lt;/code>.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/add-automatically-catch-all-addresses-as-send-from-addresses-in-exo/featured.png"/></item><item><title>Microsoft Defender for Endpoint API with Logic App</title><link>https://sekureco42.ch/posts/microsoft-defender-for-endpoint-api-with-logic-app/</link><pubDate>Mon, 20 Mar 2023 20:06:15 +0100</pubDate><guid>https://sekureco42.ch/posts/microsoft-defender-for-endpoint-api-with-logic-app/</guid><description>&lt;p>In another post I already wrote about managed identities and using API. There I also showed how to adapt the required permissions. In this post you will see how to set up required permissions for Microsoft Defender for Endpoint (internally called &lt;code>WindowsDefenderATP&lt;/code>).&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/microsoft-defender-for-endpoint-api-with-logic-app/featured.png"/></item><item><title>Graph API with Logic App</title><link>https://sekureco42.ch/posts/graph-api/graph-api-using-logic-app/</link><pubDate>Wed, 15 Mar 2023 07:51:15 +0100</pubDate><guid>https://sekureco42.ch/posts/graph-api/graph-api-using-logic-app/</guid><description>&lt;p>In the first part of this serie we checked the basics of the Graph API. Now in this part we will use Logic App to query the API. This opens new way to automate tasks.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/graph-api/graph-api-using-logic-app/featured.png"/></item><item><title>Nextcloud SSO with Azure Active Directory (AAD)</title><link>https://sekureco42.ch/posts/nextcloud-sso-with-azure-active-directory/</link><pubDate>Wed, 22 Feb 2023 11:00:15 +0100</pubDate><guid>https://sekureco42.ch/posts/nextcloud-sso-with-azure-active-directory/</guid><description>&lt;p>Nextcloud is a file sharing platform like Sharepoint. Providing SSO for this application for your Azure Active Directory users is easy - especially if you know which SAML properties you have to setup on both ends, Nextcloud and AAD. This article shows you how to do it.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/nextcloud-sso-with-azure-active-directory/featured.png"/></item><item><title>Comment function for static websites with Remark42</title><link>https://sekureco42.ch/posts/comment-function-for-static-websites-with-remark42/</link><pubDate>Sat, 04 Feb 2023 15:53:15 +0100</pubDate><guid>https://sekureco42.ch/posts/comment-function-for-static-websites-with-remark42/</guid><description>&lt;p>Static websites are incredibly fast - but the drawback is that you can&amp;rsquo;t use dynamic content like commenting of articles. But there is a solution for this issue: You could integrate external commenting services. One of them is Remark42 which can be self-hosted. This Article has some Tipps for setting up Remark42.&lt;/p></description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://sekureco42.ch/posts/comment-function-for-static-websites-with-remark42/featured.png"/></item></channel></rss>