Anyone any ideas?
224 karma · joined March 14, 2012
Anyone any ideas?
Ubuntu, Firefox 20.0
No need for extra steps - this module shall be compiled and part of nginx-full package from nginx official PPA, if OP is using Ubuntu.
thank you
> Yes ;)
ok, missed it, checked again. UDP, TCP - yes. TLS - not yet?
I checked tutorial, nothing there. Since most [semi]serious projects have a least some servers, I suggest to add a separate example, smth like:
1. We have 5 servers. And we collect logs to server 6. 2. These are settings you need to use for 5 servers. 3. And these are settings you need to use for the collector [IP:Port:TCPwithTLS].
> Dendrite scrapes your existing logs
Does Dendrite tail? Can Dendrite consume/scrape some existing/old log files?
BTW, what was your actual max throughput? Did you use some internal queue in the design, like rsyslog is doing?
> Dendrite isn't trying to be Logstash. I'd like dendrite to be the agent you use with logstash, greylog, papertrail, or whatever.
I am confused here a bit. So Dendrite is like StatsD on steroids?
Why did you use yaml for configs? Yaml is/can be kind of fragile (whitespace, etc). Do you consider something more practical - nginx config formats?
How to set-up log collector? For example I need to collect logs from several instances. Could not find in cookbook.
How do you separate logs for different hosts/applications?
How do you ship logs? UDP? TCP? TLS?
How is this compared vs Logstash?
Thank you!
Usually it helps when you learn to consiously (on demand) get yourself into a more relaxed state/mood internally. I found that when I am in the relaxed state, this really smoothes some rough edges in how people perceive myself.
Apple's ban does not help in improving users' [that's us] experience. A better response from Apple would be fixing core of the matter.
I recall that couple of years ago Apple purchased app search&discovery start-up for circa $50M. Looks like reverse integration took place... unfortunately.
I discovered more high quality apps on HN than in App Store.
Bug?
Also, how was performance using JSON data format compared with ProtoBuffers & MsgPack?
Also, are you missing any features in nsq?
Can you please elaborate on this? Do you mean that Apply is paying some kind of affiliate fee? And what happens if the app is free of charge (FOC)?
Edit: sorry, mixed the thread
Just put it in.
I would suggest that you add a couple of Starting Up tutorials - smth like:
Tutorial 1/2/3
"I have my collection of photos on Ubuntu/Windows/MacBook"
Level Beginner
Time estimate 5-10-15 min
Goal: in 5 min your collection is backed-up and synced with your mobile device.
ToDo....................
If starting up with you is easy, then make it easy for people to discover this in the form they already got used to (most good libraries and plugins announced here have Quick Start Up section).
> compile and use large swathes
Can someone elaborate in plain speak?
You have asked Firefox to connect securely to cacert.org, but we can't confirm that your connection is secure. Normally, when you try to connect securely, sites will present trusted identification to prove that you are going to the right place. However, this site's identity can't be verified.
Basic:
1. SSH - security related - modify sshd config - no password auth, only key based, no root login, other than that the default sshd config for Ubuntu 12.04 is pretty ok.
PermitRootLogin no
If you do not use IPv6, you can disable sshd to use it.
#ListenAddress ::
ListenAddress 0.0.0.0
2. SSH - ease of maintenance related - change default port from 22 to smth else. This will not help against targeted attacks, but this will reduce the noise in the logs and will allow better visibility of attack attempts.
#Port 22
Port 63777 (or whatever)
Don't forget to reload ssh for changes to take effect and check with netstat what's running where.
If you are concerned with getting locked out you can do this:
2.1. enable sshd to listen on multiple ports simultaneously
Port 22
Port 63777 (or whatever)
2.2. Login through Port 63777, and only then disable Port 22.
3. The PRC thing - fail2ban and hosts is simple but not the best tools for the job.
3.1. You can disable access to your site for all China (or any other country for this matter) using ipset. Much better speed and ease of maintenance, it's even better then using iptables itself [ipset is iptables module], one set can contain/block up to 65000+ IPs.
3.2. If you want smth more targeted, then consider either sshguard or psad. They can be configured to block inline and dynamically add rules [perm/temp] to iptables.
Edit: forgot to mention another cute recipe. see below
If you are on AWS and are using security groups (you should), after you are done on the server, you can go to the security group in AWS Mgt Console and remove ingress for ssh ports. Now your server is accessible only on 80/443 and ssh is NOT accessible to anyone. Later, when you need to access the server - enable ingress for the ssh ports, do your job and disable again.
Can someone recommend good tutorials on:-
1. Using IRC [beginner] & [advanced]?
2. How to set-up own IRC server and which are the good ones?
Based on your experience, how do they charge (per employee, per transaction, etc) and how much does it cost, roughly?
the fork docs point to the original site, which was taken down :-(
Edit: docs are in index.html, but w/o css
docs no? :-(