<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Michel Oosterhof on @micheloosterhof</title><link>https://www.micheloosterhof.com/</link><description>Recent content in Michel Oosterhof on @micheloosterhof</description><generator>Hugo</generator><language>en</language><atom:link href="https://www.micheloosterhof.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Splunk Segmenter config for ISO8601 dates</title><link>https://www.micheloosterhof.com/posts/2018-10-31-iso8601/</link><pubDate>Wed, 31 Oct 2018 00:00:00 +0000</pubDate><guid>https://www.micheloosterhof.com/posts/2018-10-31-iso8601/</guid><description>&lt;p&gt;Recently I read an excellent article by Duane Waddle on
&lt;a href="https://www.duanewaddle.com/splunk-bucket-lexicons-and-segmentation/" class="external-link" target="_blank" rel="noopener"&gt;splunk bucket lexicons and segmentation&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This inspired to put a small app on SplunkBase that improves the default settings to ignore
&lt;a href="https://www.iso.org/iso-8601-date-and-time-format.html" class="external-link" target="_blank" rel="noopener"&gt;ISO8601 date and time stamps&lt;/a&gt; in the searchable lexicon
in Splunk.&lt;/p&gt;
&lt;p&gt;Practically this means Splunk will stop indexing parts of the timestamp, and you can no longer search for terms like &lt;code&gt;2018&lt;/code&gt;. Because this significantly reduces the index, this should save you a good amount of disk space.&lt;/p&gt;</description></item><item><title>Cowrie Honeypot</title><link>https://www.micheloosterhof.com/posts/2018-10-30-cowrie.org/</link><pubDate>Tue, 30 Oct 2018 00:00:00 +0000</pubDate><guid>https://www.micheloosterhof.com/posts/2018-10-30-cowrie.org/</guid><description>&lt;p&gt;Articles on the Cowrie Honeypot are now live at &lt;a href="http://www.cowrie.org" class="external-link" target="_blank" rel="noopener"&gt;www.cowrie.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The official Github repository has also moved and is now at &lt;a href="https://www.github.com/cowrie/cowrie" class="external-link" target="_blank" rel="noopener"&gt;www.github.com/cowrie/cowrie/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you want to know more, join us on the &lt;a href="http://cowrie.org/slack" class="external-link" target="_blank" rel="noopener"&gt;Cowrie Slack&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Cookie Policy</title><link>https://www.micheloosterhof.com/cookie-policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.micheloosterhof.com/cookie-policy/</guid><description>&lt;h1 id="cookies"&gt;
 Cookies
 &lt;a class="heading-link" href="#cookies"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h1&gt;
&lt;p&gt;A cookie is a small text file which is automatically saved on your
computer when you visit our website and is used to help track
activity across a website. &lt;em&gt;micheloosterhof.com&lt;/em&gt; uses cookies on our website
for the following purposes:&lt;/p&gt;
&lt;h2 id="google-analytics"&gt;
 Google Analytics
 &lt;a class="heading-link" href="#google-analytics"&gt;
 &lt;i class="fa-solid fa-link" aria-hidden="true" title="Link to heading"&gt;&lt;/i&gt;
 &lt;span class="sr-only"&gt;Link to heading&lt;/span&gt;
 &lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;We use Google Analytics to help provide anonymous web analytics for our website.&lt;/p&gt;</description></item><item><title>Thanks!</title><link>https://www.micheloosterhof.com/contact/thanks/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.micheloosterhof.com/contact/thanks/</guid><description>Thanks!</description></item></channel></rss>