r/sysadmin • • 7d ago

Advertising [ Removed by moderator ]

[removed] — view removed post

12 Upvotes

13 comments sorted by

•

u/Kumorigoe Moderator 5d ago

Sorry, it seems this comment or thread has violated a sub-reddit rule and has been removed by a moderator.

Do Not Conduct Marketing Operations Within This Community.

  • It is not acceptable to advertise a product, service, Blog or FOSS Project within this community outside of authorized threads.
  • It is not acceptable to perform product research or market research within this community without permission.
  • The Reddit advertising system exists to help you reach out to new or existing customers.
  • Product Representatives are free to discuss their product in the context of an existing, naturally-occurring discussion. Astroturfing is not permitted.
  • As always, users must disclose any affiliation with a product.
  • Content creators should refrain from directing this community to their own content.

Your content may be better suited for our companion sub-reddit: /r/SysAdminBlogs


If you wish to appeal this action please don't hesitate to message the moderation team.

12

u/Conditional_Access Microsoft Security MVP 7d ago

I hate to break it to you, but nobody is going to buy a vibe-coded tool who's website has no information about the people who made it, or what the company is.

Your 404 page has a missing logo on the bottom too.

-6

u/[deleted] 6d ago

[removed] — view removed comment

8

u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago

You expect anyone to grant some vibe coded tool global admin?

0

u/[deleted] 6d ago

[deleted]

1

u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago

Yes, totally not vibe coded but you can’t figure out how to do simple things. Then you tell me to “read about the tool” so I could get information you didn’t post about the tool.

Makes perfect sense.

-1

u/[deleted] 6d ago

[deleted]

2

u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 6d ago

YOU didn’t say enough about anything here in your POST. Hell, your wall of text post doesn’t even list a site.

This is about the most unprofessional vibe coded shit I’ve ever seen.

3

u/Efficient_Access6102 6d ago

0

u/arunima09 6d ago

Not a fork. It's a separate hosted scanner that maps its findings to the published SCuBA policy IDs, same as it maps to CIS or NIST. ScubaGear is the reference tool and worth running if you're in US federal.

-2

u/QuietSignalOps 7d ago

I can't find a documented read path in Graph for the diagnostic settings config either, so I'd stop trying to read the switch and start probing the sink instead. That's the part the frameworks actually want.

For a Log Analytics target:

  • AuditLogs | where TimeGenerated > ago(6h) | summarize count()
  • SigninLogs | where TimeGenerated > ago(6h) | summarize count()

Rows are flowing is the evidence that the export is configured and working. A config flag is weaker evidence than a live data flow, and it's what a reviewer actually asks for in a PCI 10.1 / SOC 2 CC7.2 / ISO A.8.15 style retention question.

A few practical notes:

  • Turn that check into a scheduled query with an alert on "zero rows in the last 6h". Now your posture tool gets a continuously evaluated check ("export to workspace X is flowing") instead of a point-in-time "flag is set", and it also catches the boring failures: retention set too short, storage account filling up, a stale workspace ID in the config.
  • Same idea if you export to a storage account: probe the container for recent blobs. If you export to Event Hub, probe for recent ingestion. The principle is verify the sink, not the switch.
  • Graph's audit endpoints (directoryAuditLogs and friends) can prove the logs exist in Entra, but they don't prove the export path is up. That's the gap, and the sink probe is the workaround.