<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tech Tips on Rex Consulting · LDAP and identity infrastructure that doesn't go down</title><link>https://rex.consulting/blog/</link><description>Recent content in Tech Tips on Rex Consulting · LDAP and identity infrastructure that doesn't go down</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 25 Jul 2024 07:25:41 +0000</lastBuildDate><atom:link href="https://rex.consulting/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Preparing for IT Disasters: Identifying Weaknesses and Conducting Effective Drills</title><link>https://rex.consulting/blog/preparing-for-it-disasters-identifying-weaknesses-and-conducting-effective-drills/</link><pubDate>Thu, 25 Jul 2024 07:25:41 +0000</pubDate><guid>https://rex.consulting/blog/preparing-for-it-disasters-identifying-weaknesses-and-conducting-effective-drills/</guid><description>Disaster can strike at any time, and you need to be prepared. This article will give some tips on how to identify and eliminate weaknesses in your IT systems and provide suggestions on preparing for disasters with drills.
Identify Critical Core Services Systems to Focus On: Key services include cloud providers, network appliances, DNS, and LDAP. The failure of any of these can cascade into a full-scale outage. Why They Matter: These core services are foundational.</description></item><item><title>Best practices: Securing Passwords in Command-Line Operations</title><link>https://rex.consulting/blog/best-practices-securing-passwords-in-command-line-operations/</link><pubDate>Tue, 07 May 2024 09:21:57 +0000</pubDate><guid>https://rex.consulting/blog/best-practices-securing-passwords-in-command-line-operations/</guid><description>When working with command lines that require passwords, such as using ldapsearch, it&amp;rsquo;s crucial to manage these credentials securely. Storing passwords directly in command-line scripts or entering them in ways that leave them accessible in history files poses significant security risks. Such practices can lead to accidental exposure through system logs or even simple copy-paste errors into communications like chats or emails.
Here&amp;rsquo;s a simple yet effective method to keep your passwords secure:</description></item><item><title>Why Offline Backups Are Needed</title><link>https://rex.consulting/blog/why-offline-backups-are-needed/</link><pubDate>Mon, 24 May 2021 13:11:14 +0000</pubDate><guid>https://rex.consulting/blog/why-offline-backups-are-needed/</guid><description>Here at Rex Consulting, Inc. we have multiple virtual machines running a myriad of different services. With the hypervisor and a secondary server managing the backing up of said services. While many companies may see this as a perfectly fine backup policy, it can still be improved. Therefore, to take our backups to the next level, we push these to an offline source.
With the emerging threat of ransomware attacks, which capitalizes on poor backup policies.</description></item><item><title>Checking TLS/SSL Services with Check SSL Cert</title><link>https://rex.consulting/blog/checking-tls-ssl-services-with-check-ssl-cert/</link><pubDate>Wed, 01 Jul 2020 17:50:42 +0000</pubDate><guid>https://rex.consulting/blog/checking-tls-ssl-services-with-check-ssl-cert/</guid><description>Check SSL Cert Matteo Corti created a great shell script that can be used for TLS certification that enhances Nagios monitoring tools. The repo for the project can be found at here. This script parses data from an x509 certificate that can be pulled via openSSL or stored locally. It&amp;rsquo;s a general tool that can use a multitude of different protocols, including LDAP.
Basic Certificate Expiration Check ./check_ssl_cert -H host [options]</description></item><item><title>Checking TLS/SSL Services with Nagios Service Checks</title><link>https://rex.consulting/blog/nagios-for-tls/</link><pubDate>Wed, 13 May 2020 21:30:15 +0000</pubDate><guid>https://rex.consulting/blog/nagios-for-tls/</guid><description>A TLS (or SSL) certificate expiration should never be the cause of an outage, but we&amp;rsquo;ve all heard about this happening before. If it does happen, it usually causes a high impact, so follow these tips to help track your TLS validity.
You can easily monitor TLS expiration using Nagios XI. A lot of the Nagios check plugins that come with Nagios XI support TLS. Note the options are slightly different among the plugins.</description></item><item><title>Managing Host Removals In Nagios XI</title><link>https://rex.consulting/blog/managing-host-removals-nagios-html/</link><pubDate>Thu, 28 Mar 2019 08:19:31 +0000</pubDate><guid>https://rex.consulting/blog/managing-host-removals-nagios-html/</guid><description>A client recently asked me what is the best way to remove Nagios XI object definitions for hosts that have been retired. Well there&amp;rsquo;s a few ways to accomplish this:
Script using the excellent Nagios XI REST API to do the removals + hooks into their Puppet configuration management system. The documentation for the Nagios XI REST API is built into Nagios XI itself. Just log into your XI instance, click Help and look under the &amp;ldquo;Developer Docs&amp;rdquo; section.</description></item><item><title>Rex To Offer Basic Linux Training Classes Soon</title><link>https://rex.consulting/blog/rex-offer-basic-linux-training-classes-soon-html/</link><pubDate>Wed, 12 Sep 2018 08:16:02 +0000</pubDate><guid>https://rex.consulting/blog/rex-offer-basic-linux-training-classes-soon-html/</guid><description>Rex Consulting is working on a curriculum for some technical training classes. We&amp;rsquo;re starting with Basic Linux Training. My main motivation here is that I want to teach some skills that, in the 21st century, should be taught in the 3rd grade. The main reward I plan on obtaining from this is a few hundred or thousand &amp;ldquo;Thank you for starting my career&amp;quot;s. The classes will start out in person, not on-line, in our local area.</description></item><item><title>Wanting Better Monitoring, Just After A Disaster Strikes</title><link>https://rex.consulting/blog/optimism-html/</link><pubDate>Wed, 05 Sep 2018 08:12:51 +0000</pubDate><guid>https://rex.consulting/blog/optimism-html/</guid><description>The man who is a pessimist before 48 knows too much; if he is an optimist after it, he knows too little.
- Mark Twain
We often hear from people who want better monitoring, just after a disaster strikes. I guess that&amp;rsquo;s just human nature. I think also we technologists are, by nature, optimistic. In order to build something new, we must believe in things that others have thought impossible.</description></item><item><title>Using Duo 2FA To Improve Security In Nagios XI</title><link>https://rex.consulting/blog/using-duo-2fa-improve-security-nagios-xi-html/</link><pubDate>Thu, 09 Aug 2018 08:05:53 +0000</pubDate><guid>https://rex.consulting/blog/using-duo-2fa-improve-security-nagios-xi-html/</guid><description>Starting with version 5.5, Nagios XI has implemented 2 factor authentication using DUO. DUO 2FA improves the security for Nagios XI by letting users log in using a 2nd factor (Phone App, SMS, Phone Call, emaill). Currently there are 2 ways to enable 2FA, through the Nagios XI admin settings (the security tab in Admin &amp;gt; Settings) and the DUO Nagios XI component.
Setting Up Email 2FA
Email 2FA can be set up without having a DUO account.</description></item><item><title>An Introduction To Nagvis</title><link>https://rex.consulting/blog/an-introduction-to-nagvis-html/</link><pubDate>Thu, 19 Jul 2018 08:02:18 +0000</pubDate><guid>https://rex.consulting/blog/an-introduction-to-nagvis-html/</guid><description>Nagvis is a visualization utility that is included in all Nagios XI installations. As it&amp;rsquo;s name suggests, Nagvis can create dynamic visualizations of almost all types of Nagios data. Nagvis is great for organizations that are currently using Nagios and want to set up a large screen onsite to monitor the current status of the system or network infrastructure. To start using Nagvis, select the &amp;lsquo;Nagvis&amp;rsquo; link under the Nagios XI home page:</description></item><item><title>Automating Firewall Block Rules For Malicious Attackers With Nagios Logserver And OpenBSD</title><link>https://rex.consulting/blog/making-use-nagios-logserver-block-malicious-attackers-html/</link><pubDate>Thu, 14 Jun 2018 07:55:10 +0000</pubDate><guid>https://rex.consulting/blog/making-use-nagios-logserver-block-malicious-attackers-html/</guid><description>While Nagios Logserver is a useful tool for system analysis and central log management, it is also a great tool to analyze network security. One can actually make use logserver to improve security by using it to dynamically block IP&amp;rsquo;s from malicious attackers. Assuming you are using OpenBSD as a gateway for incoming traffic which uses pf to block IP&amp;rsquo;s, to set up dynamic filtering you would do the following:</description></item><item><title>Phone (Telecom) Phishing</title><link>https://rex.consulting/blog/phone-telecom-phishing-html/</link><pubDate>Wed, 09 May 2018 07:48:25 +0000</pubDate><guid>https://rex.consulting/blog/phone-telecom-phishing-html/</guid><description>We received a call today to our main business line from someone who asked to &amp;ldquo;speak to the person who handles Worker&amp;rsquo;s Comp. Insurance.&amp;rdquo;
The call routed to our receptionist, who wisely asked &amp;ldquo;Who&amp;rsquo;s speaking please?&amp;rdquo;, to which the caller replied, &amp;ldquo;Joey&amp;rdquo;.
Our receptionist asked, &amp;ldquo;Joey from where?&amp;rdquo;.
The caller replied, &amp;ldquo;Joey from Grunston&amp;rdquo;, but it was hard to make out as the caller did not enunciate the company name very well, and spoke very quickly.</description></item><item><title>NSClient++ With Signed SSL Certificates And Strong Encryption</title><link>https://rex.consulting/blog/nsclient-signed-ssl-certificates-strong-encryption-html/</link><pubDate>Thu, 03 May 2018 07:46:58 +0000</pubDate><guid>https://rex.consulting/blog/nsclient-signed-ssl-certificates-strong-encryption-html/</guid><description>By using NSClient++ with Signed SSL Certificates and strong encryption, you can guard your monitoring traffic against eavesdroppers. If you are using NSClient++ to send data to your monitoring system and you care about the security of your network, by all means, make sure you use strong encryption like TLS 1.2 (not Anonymous Diffie-Helman!) and signed SSL certificates. With Anonymous Diffie-Hellman, the keys used in the exchange are not authenticated so the the protocol is susceptible to Man-in-the-Middle attacks.</description></item><item><title>Nagios Event Handlers: Self-Healing And More</title><link>https://rex.consulting/blog/nagios-event-handlers-self-healing-html/</link><pubDate>Mon, 26 Feb 2018 07:39:36 +0000</pubDate><guid>https://rex.consulting/blog/nagios-event-handlers-self-healing-html/</guid><description>For self-healing in IT operations, Nagios event handlers are a great way to go. Event handling scripts can be written to restart services that die, which is a sometimes unfortunate fact of life.</description></item><item><title>Merging Multiple Nagios Check Outputs Using Macros</title><link>https://rex.consulting/blog/merging-multiple-nagios-check-outputs-using-macros-html/</link><pubDate>Mon, 05 Feb 2018 07:37:16 +0000</pubDate><guid>https://rex.consulting/blog/merging-multiple-nagios-check-outputs-using-macros-html/</guid><description>Macros in Nagios are a powerful tool. There are countless (see link) macros in existence that allow users to obtain Nagios check data easily. Among such macros, there exists $SERVICEOUTPUT$ that replaces itself with a string of the output of a chosen service. To specify such a service you can use the following syntax:
$SERVICEMACRONAME:host_name:service_description$ These type of macros are known as on-demand macros. In our particular case we want to merge 2 checks together by grabbing each check&amp;rsquo;s output, parsing a chosen value, and summing those values together.</description></item><item><title>Checklists Plus Good Monitoring = Reliability</title><link>https://rex.consulting/blog/checklists-html/</link><pubDate>Sun, 03 Dec 2017 07:35:35 +0000</pubDate><guid>https://rex.consulting/blog/checklists-html/</guid><description>SYSTEM HEALTH CHECKLISTS + GOOD AUTOMATED MONITORING WILL DRASTICALLY INCREASE THE RELIABILITY OF YOUR SYSTEM. The use of checklists in order to increase the reliability of complex systems and practices such as aviation and surgery is less than 100 years old. In information technology, checklists are popular too. Checklists are used manually in order to monitor the health of services after deployment, or on a regular basis to check functionality. Since the early days of IT, before automated monitoring became the normal practice, the checklist (or sometimes called, &amp;ldquo;daily checklist&amp;rdquo;) was the primary method used to assess the availability and health of an IT system.</description></item><item><title>The WMI Plus File Checks</title><link>https://rex.consulting/blog/wmi-plus-file-checks-html/</link><pubDate>Fri, 15 Sep 2017 07:33:14 +0000</pubDate><guid>https://rex.consulting/blog/wmi-plus-file-checks-html/</guid><description>The WMI Plus nagios plugin (found at http://www.edcint.co.nz/checkwmiplus/?q=overview) is an agentless &amp;lsquo;agent&amp;rsquo; that comes with several different built in checks. One particularly useful WMI Plus check is the checkfiles collection of checks which consist of checkfileage and checkfilesize. Note that you will need to either feed your username and password into the command or make a file that contains both your username and password for the windows machine and then on the WMI Plus setup, point the authentication path to the credentials path.</description></item><item><title>Applying Double Filters In NXLOG For Windows Event Logs</title><link>https://rex.consulting/blog/applying-double-filters-nxlog-windows-event-logs-html/</link><pubDate>Sat, 29 Jul 2017 07:31:24 +0000</pubDate><guid>https://rex.consulting/blog/applying-double-filters-nxlog-windows-event-logs-html/</guid><description>In our previous NXLOG article, it was mentioned how it was possible to create filters by using the Exec drop() directive in NXLOG accompanied by a filtering if statement. This works well as a general solution to incoming logs, however, there exists a more specific way to filter out windows event logs. This works by adding a query inside the &amp;lt;input eventlog&amp;gt; tag inside nxlog.conf:
Query &amp;lt;QueryList&amp;gt;\ &amp;lt;Query Id=&amp;quot;0&amp;quot; Path=&amp;quot;Security&amp;quot;&amp;gt;\ #Selects the default path of the location of the event logs &amp;lt;Select Path=&amp;quot;Security&amp;quot;&amp;gt;*[System[EventID=4663]]&amp;lt;/Select&amp;gt;\ #Selects an event log with a specific ID.</description></item><item><title>Adding An Additional Layer Of Filtering Through NXLOG</title><link>https://rex.consulting/blog/adding-additional-layer-filtering-nxlog-html/</link><pubDate>Thu, 08 Jun 2017 07:29:56 +0000</pubDate><guid>https://rex.consulting/blog/adding-additional-layer-filtering-nxlog-html/</guid><description>Have you ever wanted to apply an additional filtering layer to your logs before sending them to Nagios Log Server (NLS)? If you have are sending streams of logs to NLS but know that certain logs will not be used you can use NXLOG to mitigate data usage by filtering out the unnecessary logs. One method for doing this is as follows:
Set up NXLOG if you have not already done so.</description></item><item><title>Two Easy Ways To Increase Email Security &amp; Legitimacy For Your Domain</title><link>https://rex.consulting/blog/two-easy-ways-increase-email-security-legitimacy-domain-html/</link><pubDate>Tue, 21 Feb 2017 07:24:49 +0000</pubDate><guid>https://rex.consulting/blog/two-easy-ways-increase-email-security-legitimacy-domain-html/</guid><description>HERE IS TWO EASY WAYS TO INCREASE EMAIL SECURITY AND LEGITIMACY FOR YOUR ORGANIZATION AND DOMAIN. USE Sender Policy Framework (SPF). SMTP, the email protocol in use in the internet for over 40 years, works well in many ways but is far from perfect. When it was originally created, no one had to worry about people trying to send mail as people other than themselves. SMTP, on its own, places no restriction on what a sending host can use as the &amp;ldquo;MAIL FROM&amp;rdquo; of a message or the domain.</description></item><item><title>Nagios Monitoring: Planning Is The Hallmark Of Intelligence</title><link>https://rex.consulting/blog/hallmark-of-intelligence-html/</link><pubDate>Thu, 25 Aug 2016 07:16:07 +0000</pubDate><guid>https://rex.consulting/blog/hallmark-of-intelligence-html/</guid><description>&amp;ldquo;PLANNING IS THE HALLMARK OF INTELLIGENCE&amp;rdquo; With Nagios Monitoring implementations, &amp;ldquo;Planning is the Hallmark of Intelligence&amp;rdquo;. Actually I borrowed that phrase from some animal show about squirrels and how squirrels become better planners each season, as they build the skill of planning. It was some evidence of animal learning, but what really stuck in my mind was the phrase &amp;ldquo;Hallmark of Intelligence&amp;rdquo;. It still amuses me because it sounds haughty at the same time it oversimplifies.</description></item><item><title>Tip: Destroy Expire SSH And SSL Keys</title><link>https://rex.consulting/blog/tip-destroy-old-ssh-ssl-keys-html/</link><pubDate>Wed, 25 May 2016 07:14:40 +0000</pubDate><guid>https://rex.consulting/blog/tip-destroy-old-ssh-ssl-keys-html/</guid><description>Be sure to delete expired SSH and SSL keys that you no longer use. If someone is capturing your encrypted data and saving it somewhere, they would be able to decrypt that data with the matching key, even if it&amp;rsquo;s expired.</description></item><item><title>Best Practice: Privilege Separation In Monitoring Agents</title><link>https://rex.consulting/blog/best-practice-privilege-separation-in-monitoring-agents-html/</link><pubDate>Wed, 09 Mar 2016 07:12:29 +0000</pubDate><guid>https://rex.consulting/blog/best-practice-privilege-separation-in-monitoring-agents-html/</guid><description>It is a Best Practice to run monitoring agents with privilege separation. This means that the user ID that you run the monitoring agent should be a different user ID than the applications run as.
But privilege separation makes it challenging to check the application, run application commands, access application logs, etc.
There are some tricks you can use though which aren&amp;rsquo;t too difficult, and once you get the hang of them, should not be too much a burden to add.</description></item><item><title>Monitoring Systems And Discipline</title><link>https://rex.consulting/blog/monitoring-systems-and-discipline-html/</link><pubDate>Fri, 18 Dec 2015 07:08:32 +0000</pubDate><guid>https://rex.consulting/blog/monitoring-systems-and-discipline-html/</guid><description>If you have a monitoring system, for maximum effectiveness, you need to be disciplined about handling alerts. &amp;ldquo;Handling alerts&amp;rdquo; means either A) fixing the problem that caused the alert in the case of a valid alert, or B) in case of false alarm, tuning the monitor system.
If you don&amp;rsquo;t handle the alerts promptly by either fixing the problem or fixing the alarm, three main things will happen:
Problems won&amp;rsquo;t be handled promptly.</description></item><item><title>Jython Monitoring JMX and Java Applications</title><link>https://rex.consulting/blog/jython-jmx-monitoring-html/</link><pubDate>Sun, 31 May 2015 07:00:58 +0000</pubDate><guid>https://rex.consulting/blog/jython-jmx-monitoring-html/</guid><description>Jython, an implementation of python which runs on java, is a great tool to use to access java applications thru JMX and directly calling java classes. We wrote here earlier about monitoring Cassandra using JMX and mentioned some command-line tools that can be used within scripts to access JMX. Depending on exactly what you&amp;rsquo;re doing, jython may be a better way to go. Certainly the command-line tools are great for browsing mbeans and also for wrapping into scripts, and for ad-hoc administrative tasks, but a language like jython is probably a better way to go if you need to employ more complex logic.</description></item><item><title>Nagios Monitoring Check Resolution</title><link>https://rex.consulting/blog/check-resolution-html/</link><pubDate>Wed, 25 Mar 2015 06:57:27 +0000</pubDate><guid>https://rex.consulting/blog/check-resolution-html/</guid><description>When constructing new checks for Nagios, sometimes it&amp;rsquo;s worthwhile to consider what we&amp;rsquo;ll call &amp;ldquo;check resolution&amp;rdquo;. What we mean by this term is how many distinct checks you wrap within one service check object. As an example, consider the &amp;ldquo;check_disk&amp;rdquo; check, which by default and out of the box, will check all mounted file systems, so, assuming there is more than one file system mounted, this one service check object is checking multiple file systems.</description></item><item><title>Hackers Don't Holiday</title><link>https://rex.consulting/blog/hackers-dont-holiday-html/</link><pubDate>Thu, 25 Dec 2014 06:54:47 +0000</pubDate><guid>https://rex.consulting/blog/hackers-dont-holiday-html/</guid><description>Hackers don&amp;rsquo;t holiday. I know of a client, who, a couple years ago, was hacked right around the time that Santa was delivering gifts. Which, needless to say, was inconvenient. She (and I) had to work on evicting the intruders all Christmas day, and then battening defenses, etc, etc.
This is going to be a short post today, because my hope is to work very little today, but I&amp;rsquo;ll be aware, and watching.</description></item><item><title>Year End Reminder On Password Changing &amp; Email Forgery Phish Prevention Tips</title><link>https://rex.consulting/blog/phish-prevention-tips-html/</link><pubDate>Wed, 24 Dec 2014 06:38:48 +0000</pubDate><guid>https://rex.consulting/blog/phish-prevention-tips-html/</guid><description>Since we&amp;rsquo;re nearing the end of the year, I thought it&amp;rsquo;d be a good idea to remind the world to change their passwords.
Also I want to provide some tips on phish attack prevention. Beyond having a good inbound email filter and a good web browsing filter, it&amp;rsquo;s good for users to be educated on how to detect a phishing email from a real one.
First rule to remember: DON&amp;rsquo;T JUST CLICK ON THINGS!</description></item><item><title>Tricks: Apache Cassandra Monitoring Tricks With The Help Of JMX And Nagios</title><link>https://rex.consulting/blog/nagios-cassandra-monitoring-tricks-html/</link><pubDate>Sun, 02 Nov 2014 06:22:11 +0000</pubDate><guid>https://rex.consulting/blog/nagios-cassandra-monitoring-tricks-html/</guid><description>If you run Apache Cassandra, you can monitor it with the help of Nagios and JMX. Apache Cassandra has come to &amp;ldquo;change the world&amp;rdquo;, I was told at the Cassandra Summit, back in September. It has certainly made a splash, like a gorilla in a bathtub. Problems can come up with new deployments of technology. It can be a challenge to stabilize something that is brand new, and changing so fast.</description></item><item><title>"Heartbleed", Internet Security And "The Internet Of Things"</title><link>https://rex.consulting/blog/heartbleed-bug-html/</link><pubDate>Tue, 15 Apr 2014 06:18:14 +0000</pubDate><guid>https://rex.consulting/blog/heartbleed-bug-html/</guid><description>The &amp;ldquo;HeartBleed&amp;rdquo; bug is a huge crisis for Internet Security and &amp;ldquo;The Internet of Things&amp;rdquo;.
The past 15 years of progress in the computing and internet world have been interesting. In the past 15 years, we&amp;rsquo;ve seen the creation of Google, Wikipedia, Facebook, Twitter, drones, and smartphones. Each day, the world is more and more connected in new exciting, powerful, and sometimes dangerous ways. The average person can now easily and cheaply access information and services unimaginable 15 years ago.</description></item><item><title>DST: Bad For Tech</title><link>https://rex.consulting/blog/dst-bad-for-tech-html/</link><pubDate>Mon, 10 Mar 2014 06:12:33 +0000</pubDate><guid>https://rex.consulting/blog/dst-bad-for-tech-html/</guid><description>Daylight savings time is probably to blame for a decent percentage of technology related problems, especially the first week of November and the second week of March. Studies report an increase in traffic accidents in both the Fall and Spring daylight time changes. On Mondays after the changes, the NYSE, AMEX and Nasdaq exchanges average a one-day loss of $31 billion.
We&amp;rsquo;ve said it before to always use GMT as your timezone.</description></item><item><title>What's Your Threat Model?</title><link>https://rex.consulting/blog/whats-threat-model-html/</link><pubDate>Thu, 03 Oct 2013 06:10:45 +0000</pubDate><guid>https://rex.consulting/blog/whats-threat-model-html/</guid><description>Do you have a security threat model in place? What&amp;rsquo;s a security threat model? When we talk about security threat model, it means that we discuss, document, and diagram who we&amp;rsquo;re protecting sensitive information from. It matters to a large business, and it also matters to an individual. There&amp;rsquo;s been a lot of talk lately about government agencies&amp;rsquo; ability to read your information. And so it should matter to you who can read it, and at what lengths it will take them to read it.</description></item><item><title>Environment Awareness And The Application Health Monitoring Spreadsheet</title><link>https://rex.consulting/blog/ea-html/</link><pubDate>Tue, 09 Jul 2013 06:09:39 +0000</pubDate><guid>https://rex.consulting/blog/ea-html/</guid><description>THE APPLICATION HEALTH MONITORING SPREADSHEET - HOW GOOD MONITORING AND REGULAR AUDITING CONTRIBUTES TO A BETTER ENVIRONMENT AWARENESS It might be redundant to say that good system/application health monitoring contributes to system application awareness. However, this article is going to outline some of the reasons how and why, because it is important to recognize them, as better system awareness contributes greatly to overall application effectiveness. Success depends primarily upon awareness. Environment Awareness is the foundation of a sound operations environment.</description></item><item><title>Tip: Centralized Logging Benefits</title><link>https://rex.consulting/blog/tip-centralized-logging-benefits-html/</link><pubDate>Sat, 06 Apr 2013 06:07:32 +0000</pubDate><guid>https://rex.consulting/blog/tip-centralized-logging-benefits-html/</guid><description>Centralized logging benefits more than just application troubleshooting. Today, many organizations are required to comply to regulatory standards like HIPAA, SOX, or FINRA, which means that application log control becomes even more important.
Few application infrastructures are built with good log handling functionality. Typically, applications just write log files to some location, possible roll log files according to date or size, and generally accumulate logging data on the application servers themselves.</description></item><item><title>Tip: Validation Best Practice</title><link>https://rex.consulting/blog/tip-validation-html/</link><pubDate>Thu, 21 Feb 2013 06:03:57 +0000</pubDate><guid>https://rex.consulting/blog/tip-validation-html/</guid><description>Validation best practice is an important topic that is often not given the importance it is due until it is too late. It is skipped by the undisciplined, hurried over by the impatient, and pushed aside by short-term-cost cutters. And sometimes, it just happens, like when experience is lost due to the retirement or turnover of skilled staff.
The basic question is (or should be): how do you know your system works as designed, and, in a disaster event, recovers as designed?</description></item><item><title>Tip: Finding The Right Deployment Pace</title><link>https://rex.consulting/blog/right_deployment_pace-html/</link><pubDate>Thu, 27 Dec 2012 05:47:14 +0000</pubDate><guid>https://rex.consulting/blog/right_deployment_pace-html/</guid><description>When I was young I built model airplanes. The instructions were usually simple, clear, and easy to follow. I was eventually able to build some cool looking planes, which I hung from the ceiling in my bedroom. But despite how clear the instructions were, it was easy to overlook the part that said &amp;ldquo;Allow the glue to dry completely.&amp;rdquo; Building model airplanes is mostly careful sanding and gluing of little parts and then letting them dry.</description></item><item><title>Trick: New Graymail Blocking Feature</title><link>https://rex.consulting/blog/trick-new-graymail-blocking-feature-html/</link><pubDate>Tue, 20 Nov 2012 05:40:29 +0000</pubDate><guid>https://rex.consulting/blog/trick-new-graymail-blocking-feature-html/</guid><description>We offer a new Graymail Blocking Feature which blocks mail not considered spam, yet is still a nuisance to recipients. Some of these types of email include unsubscribe options that do not work. Spam is easy to define - unsolicited email that a recipient does not want nor has asked to receive - unlike &amp;lsquo;graymail,&amp;rsquo; which is usually legitimate bulk mail that was requested by the user in the past, but is no longer wanted by the user.</description></item><item><title>Tip: Design Operation-Ready Solutions</title><link>https://rex.consulting/blog/tip-design-operation-ready-solutions-html/</link><pubDate>Thu, 08 Nov 2012 05:34:27 +0000</pubDate><guid>https://rex.consulting/blog/tip-design-operation-ready-solutions-html/</guid><description>Design operation-ready solutions so that your solutions will run well in production. If you hire someone to recommend, design, and implement solutions in your environment, you would be wise to make sure they have significant proven experience in both system design and in operations management. There is a big difference between getting something to run in a test environment, without users, and running a highly available production system.
Many times what can be tested and proven in test environments cannot imagine all of the random situations which can happen in a production environment with real users.</description></item><item><title>Nagios For Application and System Monitoring</title><link>https://rex.consulting/blog/nagios-for-application-and-system-monitoring-html/</link><pubDate>Sat, 13 Oct 2012 05:33:15 +0000</pubDate><guid>https://rex.consulting/blog/nagios-for-application-and-system-monitoring-html/</guid><description>Nagios is the premier monitoring application. Like a swiss-army knife, Nagios is highly versatile and extensible, and works very well for monitoring the health of any type of system or application, checking practically anything you can measure numerically and/or with simple &amp;ldquo;OK, WARNING, CRITICAL&amp;rdquo; status. It comes with all sorts of service checks for protocols, system load, memory, process tracking, and SNMP. New service checks can be developed rapidly when no &amp;ldquo;out-of-the-box&amp;rdquo; service checks fill a requirement gap.</description></item><item><title>Tip: Better Application Logging</title><link>https://rex.consulting/blog/tip-better-application-logging-log-levels-log-spam-html/</link><pubDate>Sat, 08 Sep 2012 05:29:28 +0000</pubDate><guid>https://rex.consulting/blog/tip-better-application-logging-log-levels-log-spam-html/</guid><description>Good application logging is invaluable to a well-functioning application team. From troubleshooting problem incidents to collecting and plotting performance trending, good logging is one of the best ways to track application health. Better logging will set you apart from the rest, and give your operations staff the tools it needs to succeed.
Good application logging is:
Complete: Each line contains the event timestamp, log level transaction ID, and other relevant transaction processing data such as user or account ID, IP address, other logical application addresses.</description></item><item><title>Tip: Timezones: Always Set Your Servers To GMT</title><link>https://rex.consulting/blog/tip-timezones-always-set-your-servers-to-gmt-html/</link><pubDate>Mon, 20 Aug 2012 04:12:01 +0000</pubDate><guid>https://rex.consulting/blog/tip-timezones-always-set-your-servers-to-gmt-html/</guid><description>It rarely makes any good sense to set a server to a timezone other than GMT. GMT is the best practice for the following reasons:
You don&amp;rsquo;t have to worry about daylight savings time changes. No chance of confusing timezones, either between applications, or administrators. It is more likely that someone will make a timezone mistake if you use them, and getting out of these situations can be difficult. Correlations of system logs from systems physically residing in different timezones is easier to do.</description></item><item><title>Tip: Password Management Best Practice: Tiered Passwords</title><link>https://rex.consulting/blog/tip-tiered-passwords-emails-html/</link><pubDate>Sat, 07 Jul 2012 04:08:54 +0000</pubDate><guid>https://rex.consulting/blog/tip-tiered-passwords-emails-html/</guid><description>With the recent password database break-ins at some very high-profile companies, those whose passwords were exposed should change their passwords, and consider using a tiered password structure, along with tiered email addresses.
**A tiered password structure **is a list of passwords that you use for different types of accounts, where the complexity of the password depends on what the exposure would be if that password is obtained. For example, for your bank accounts, you might create a very difficult and highly random password that you could never possibly remember.</description></item><item><title>Tip: Java Does Not Honor DNS TTL; Recommendation in Enterprise Environment</title><link>https://rex.consulting/blog/tip-java-does-not-honor-dns-ttl-recommendation-in-enterprise-environment-html/</link><pubDate>Tue, 05 Jun 2012 04:07:37 +0000</pubDate><guid>https://rex.consulting/blog/tip-java-does-not-honor-dns-ttl-recommendation-in-enterprise-environment-html/</guid><description>When using the java/JVM DNS caching, you should know that java caches DNS entries by default, which is abnormal for most client and server applications. It also strange that does not honor the DNS TTL when it caches. The DNS system has had TTL in it since 1987 (see RFC 1035) and most applications will not cache DNS entries. Most applications just rely on the local UNIX DNS resolvers which do not cache DNS entries.</description></item><item><title>Who Did What? Privileged Execution, and How No-Password Accounts (Even For Root) Help You Achieve This</title><link>https://rex.consulting/blog/who-did-what-why-all-you-need-is-sudo-passwordless-accounts-even-for-root-html/</link><pubDate>Fri, 27 Apr 2012 04:05:31 +0000</pubDate><guid>https://rex.consulting/blog/who-did-what-why-all-you-need-is-sudo-passwordless-accounts-even-for-root-html/</guid><description>Privileged account access is a sensitive thing today, especially with all the compliance and regulations requirements built into most corporate information systems. Even without any regulation, most good UNIX and application operations people will want to know WHO did WHAT?
In the old days (pre-sudo), there was just &amp;ldquo;su&amp;rdquo; which was used to achieve the ability to run a command as another user, typically but not always root. The &amp;ldquo;su&amp;rdquo; was logged but it still could result in a lack of access control due to the ability of passwords to be shared.</description></item><item><title>Opportunistic vs. Required TLS</title><link>https://rex.consulting/blog/opportunistic-vs-required-tls-html/</link><pubDate>Thu, 19 Apr 2012 04:03:50 +0000</pubDate><guid>https://rex.consulting/blog/opportunistic-vs-required-tls-html/</guid><description>TLS is Transport Layer Security, the public version of the SSL protocol originally developed by Netscape. It&amp;rsquo;s used today to secure many client server connections over TCP/IP networks, including web (HTTP), email (SMTP), directory (LDAP) connections as well as many more types of traffic. It&amp;rsquo;s fairly easy to set up and maintain. You have to be concerned with and schedule certificate replacements and deployments, but that can be easily accomplished with a solid procedure that can be dovetailed into the rest of the periodic system auditing and maintenance work.</description></item><item><title>Tip: Good Application Monitoring and Alerting Saves Money and Promotes Health</title><link>https://rex.consulting/blog/tip-good-monitoring-and-alerting-saves-money-and-promotes-health-html/</link><pubDate>Fri, 24 Feb 2012 03:49:07 +0000</pubDate><guid>https://rex.consulting/blog/tip-good-monitoring-and-alerting-saves-money-and-promotes-health-html/</guid><description>A good application monitoring alerting system significantly increases the reliability and reduces the amount of work that needs to be done to operate a client server- or cloud- application system. Without a good monitoring system, administrators must rely on hit or miss spot-checking of logs and available metrics or instrumentation. Without good monitoring, there is no way to be sure that the system is healthy. It is true that a good administrator should and will continue to spot check logs and other instrumentation even with good monitoring in place, but without an effective monitoring and alerting rig, there is no way to know if the application is working properly.</description></item><item><title>Tip: Think Before Using San Technology</title><link>https://rex.consulting/blog/tip-dont-use-san-technology-html/</link><pubDate>Sun, 29 Jan 2012 03:46:16 +0000</pubDate><guid>https://rex.consulting/blog/tip-dont-use-san-technology-html/</guid><description>In many situations, it is difficult recommend SAN technology. The advantages of central management, ease of backup, better disk utilization are clear, but availability is not improved by SAN vs DAS. And the reason for this is that SANs do fail, and when they do, they cause an entire data center to fail. When a SAN goes down, the storage and UNIX teams are heavily overwhelmed with incidents to manage and resolve.</description></item></channel></rss>