[blog.rayfoo] Infosec, DFIR, tech geekery, thoughts and whatnot

18Jan/110

(Many) Sick Linux Commands

These 75 (so far) tips are too good not to repost/archive for all the *nix geeks! ;)

I did NOT write these, see the links below:

[via URFIX #1 #2 #3]

20Apr/100

Getting additional (IP/network/location) info along with your Splunk searches

Chanced upon some of the info by accident (smack at the bottom of one part of the Splunk documentation...), but I can't find it now.  Going to share here anyway :D

Some (or probably most/all) of your searches might involve public IP addresses, and more often than not we would want to have additional info along with the IP address to work with.

Three of the things that we could do in Splunk automatically would be to get IP-location info, or to reverse lookup an IP to a domain, or to lookup a domain to an IP.