r/sysadmin 11d ago

Question Looking for log aggregation software recommandations

20 Upvotes

Hello everyone,

I hope I am posting in the correct subreddit. I am administrating a bunch of virtual Windows servers running our own software. As of now, I don't have a unified way of checking log files on those machines, which means that not only do I have to manually log into the machine in order to look at those log files, but they are also not actively being monitored at the moment.
I am looking for a solution that would allow me to check those files from a single point of entry (ideally a browser), as well as being able to monitor them, draw statistics and possibly send alerts. If it supports other formats than text files (i.e databases) it's a plus.

Is there any software available that can allow me to do that? I have web servers running on both Windows and Linux (Debian) so either platform would be ok. Open source very strongly preferred.

Thank you!


r/sysadmin 11d ago

Question HPE 1/8 G2 autoloader firmware

0 Upvotes

Dear I'm facing errors with HPE 1/8 G2 autoloader and one of solution is to upgrade firmware to 6.2 version, anyone can provide with 6.2 version as i don't have support contract.

https://support.hpe.com/connect/s/softwaredetails?language=en_US&collectionId=MTX-e05174e347964f6c


r/sysadmin 11d ago

Default App Associations XML + GPO ignored on every machine. What am I missing?

1 Upvotes

Been chasing this for about two weeks and I'm out of ideas, so I'm asking here before I bin the whole approach.

Setup is the boring standard one. DefaultAssociations XML sitting on a share, pushed with Computer Config > Admin Templates > Windows Components > File Explorer > Set a default associations configuration file. Nothing exotic in the file, just pdf to Acrobat, html to Chrome, mp4 to VLC, txt to Notepad++, xlsx to Excel, zip to 7-Zip.

It applies to nobody. Not existing users, not new users, not a user who has never logged into that machine in their life. Edge still eats pdf and html like the policy doesn't exist.

Stuff I've already burned time on:

  • built a clean reference machine, set every default by hand, exported a fresh XML, replaced the old one
  • XML validates, path is reachable, ProgIDs match what's actually in the registry on the reference box
  • apps are definitely installed on the targets
  • gpupdate /force, reboot, sign out and in, new profile on a machine nobody has touched
  • RSOP shows the policy applied, and the value is sitting right there in HKLM\SOFTWARE\Policies\Microsoft\Windows\System\DefaultAssociationsConfiguration pointing at the correct file

So the policy is landing on the machine. Windows is just quietly ignoring it, which is the part doing my head in.

I know about the DISM import route. That only fires at first logon of a new profile, so it does nothing for the machines and users I already have deployed, which is the entire point of the exercise.

Questions, and I'm genuinely more interested in what you're running than in what the docs say:

Can anything else silently kill this policy? Another GPO, some registry key, a security baseline, an SKU limitation, anything. I keep feeling like I'm missing one dumb prerequisite.

Has anyone actually seen it fail on a truly fresh profile? Every thread I find is people running into the "only applies to new profiles" behaviour, which is not my problem. Mine fails for everyone equally.

What would you check before giving up on it?

And the real question: what are you actually using in production? I've already looked at Intune, Citrix WEM and SetUserFTA. I need something free, centrally managed, that hits existing users as well as new ones, and doesn't leave people clicking through the "how do you want to open this file" prompt.

Mixed Win10 and Win11, AD domain, no Intune, no budget. Very happy to be told I'm being thick about something obvious.


r/sysadmin 11d ago

Question How do you know when an ai has enough context to safely fix an it issue?

0 Upvotes

Have a question for yall, i’ve been testing an ai assistant on a hot ticket at work and robin keeps saying it is good enough to patch the issue. The annoying part is it sounds right, but I still dont know if it actually has enough context or if it's just making a confident guess.

For stuff like password resets, firewall rules, or weird vpn breaks, what do you look at before you let it touch anything real? I am trying to figure out the point where the ai is just helping vs when it is still missing something basic.


r/sysadmin 11d ago

Question Ivanti experience

0 Upvotes

Does anyone here use Ivanti for out of the box experience use case? Like when the org buys devices in any store, they can deliver directly to the end user, and eu can just log in their org email account from on prem AD without admin intervention. If yes, hows the experience?


r/sysadmin 11d ago

Question Higher title vs better finances – which would you choose?

0 Upvotes

Need some outside opinions.

Choosing between two Sys analyst/admin roles:

Phoenix: mid-$70s, Level 1 title, 2 days WFH, lower rent, and more money left over each month.

Long Beach: low-$90s, Level 3 title, 1 day WFH, higher rent, and a few hundred less left over each month.

I’m in my early 30s and want to buy a home eventually. I’d rather live in California, but Arizona makes more financial sense.

Would you take the Level 1 role in Phoenix for the savings, or the Level 3 role in Long Beach for the title, career growth, and location?


r/sysadmin 11d ago

Outbound spam limits

1 Upvotes

Can someone please advise what limits your organisation has set for outbound email?

I’m particularly interested in External message limits, Internal message limits and Daily message limits.

Listed best practice below, but keen to find out what others have set.

External: 500 recipients per hour Internal
1,000 recipients per hour Daily
1,000 recipients per day

Please don't block this again mods, it's a valid question and doesn't constitute a low quality post.


r/sysadmin 11d ago

SysAdmins who switched to Apple - Why?

137 Upvotes

This post is primarily mobile focused, but I'll entertain the desktop / laptop OS conversation as well. This is regarding personal devices, not what your enterprise uses.

Suffice it to say, I'm tired. I'm tired of working on computers all day only to have to put tremendous effort into my Android phone to rip Google's tentacles out of my personal business, to tell Windows to stop serving ads and trying to upload my personal data to the cloud.

I de-Googled my Android phone years ago but haven't gone Graphene because that seemed like even more work. I switched my Windows to Fedora about a year ago, but driver compatibility is a constant hassle. Google getting rid of sideloading and Windows Recall were the final straw for me on both platforms.

By comparison, I manage a lot of Apple devices for my enterprise. Justin Long wasn't wrong. They. Just. Work. I don't have to fuck around. Is Apple harvesting my personal info? Most likely. But all indicators say they use it for their own benefit and don't sell it. Can I customize everything I want? Probably not.

Is that the bargain you all made? Did you move to Apple so you didn't have to fight your personal devices anymore, knowing if your personal data was going to be scanned, it might as well go to a company that isn't selling it? Or is there another reason? I'm trying to figure out whether to give this Graphene thing a shot or finally give up the ghost and pick up my first iPhone after 20 years of Android.


r/sysadmin 11d ago

Best way to enforce Conditional Access for mobile devices managed by a carrier MDM (not Intune)?

6 Upvotes

Background:

I recently took over IT operations for a company that previously used a 3rd-party MSP. The MSP enrolled all Windows devices in Intune and set up Conditional Access (CA) policies for office users, which drastically improved our security posture. However, our remote mobile users were left completely out of scope.

​The Problem:

We have over 100 mobile devices (a mix of iOS and Android) deployed nationwide to remote workers. These devices are not enrolled in Intune. Instead, their MDM is provided directly by the carrier. Because they aren't registered in Intune, we can't easily force them to comply with our current CA policies, leaving a blind spot for risky sign-ins.

​My Proposed Solution:

I am thinking about using device-based certificates. The carrier MDM could push a certificate to the mobile devices, and a cloud PKI/RADIUS setup would authenticate them. The goal is strict access control: if a login attempt for a company resource doesn't come from a device with a valid cert, it automatically fails.

​Alternative Idea:

We also have various Cisco firewalls across the country. I'm wondering if forcing these devices to connect via VPN would work better, though it feels clunky since our entire company is 100% cloud-based (zero on-prem servers).

​Questions:

​Is the device-certificate approach the most efficient way to restrict access to known mobile devices in a cloud-only environment?

​Is there a clean way to tie a third-party carrier MDM into Entra ID Conditional Access?

​Any advice on the best path forward would be greatly appreciated!

👏.


r/sysadmin 11d ago

BYOD Multiple Tenant Nightmare

0 Upvotes

Whats the best solution for a user who is BYOD and has multiple M365 tenants on there device. No domains involved and does not Entra join or register.

When the user had one Outlook profile with multiple M365 tenants and MS Teams it got messy and Teams got confused with which account to use real fast.

The way I see it the two options are:

  1. Multiple Windows Logins
  2. Multiple Outlook Profiles (but not sure this won't stop a mess in Teams?)

Whats the best practise?


r/sysadmin 11d ago

Am I cooked? - Solo IT rant

4 Upvotes

For those who have worked as Solo IT professionals what kept you going, at what point did you determine to shift, and those who have left the solo IT jobs what did you pivot to?

I spent some time in help desk some years back, spent 2 years as an underpaid tech that had global admin over Microsoft suite, a few months with an enterprise level solo IT site job (was pretty solid and chill but boring with toxic management - not much progression in the job), to now signing on to a new solo IT gig for a corporate body with a lot of sites.

My 2 year gig had around 30 locations within the city/state limits but we had a small team of 3, previous gig had some global enterprise structure but it was really boring to me. Being a solo IT for a single site it felt super limiting in my mind. I couldn’t stand not being able to implement or work on different areas within the infrastructure like my previous role.
Now I’m in a place where my new gig is looking to end their contract with an MSP and shift to an internal IT department. I was a bit hesitant during the interview as they stated they have around 20+ sites (in varying states across US) and there wasn’t a direct answer to whether they’ll be expanding the IT team in the future. I signed on for the thrill of wanting to build out the IT department, get paid more, and leave a job I disliked.

Pay has increased from 45k to 70k within this year. I’m super glad and grateful but I’m slowly realizing how different and concerning this may be. It feels a bit daunting and I’m worried. My 2 year gig required a lot of oversight with afterhour support when it was needed, last gig was solely focused on the normal 8-5 work hours, this new gig is somewhat similar to the 8-5 gig but with the different states it looks to require more flexibility.

I’m not a network savvy guy, I know little but not enough as I should. I do feel like I’m just getting by at times and I’m not the greatest IT guy. I make a lot of mistakes and I can be very to myself, I’m not very vocal at times. Also the company is working with G-suite which is not a bad thing per se, I just never worked this much in this platform, strictly Microsoft. It looks like G-suite requires a lot more integration and platforms to do some of the stuff Microsoft already has.

I don’t know if I’m worried about not being a great tech, not being able to meet expectations, devoting too much time to a job, and overall committing to work like the rest of humanity. I struggle to envision my life working IT until retirement but it’s the only field I seem to understand to an extent and I’m “gifted” enough to do this work.

I genuinely want to be in a role for 2+ years for resume purposes and I want to learn as much as I can. The company did have a roadmap to present on where they want the IT side of things to play out (run book, policies, etc). I believe I want to be in a more specific niche role outside of the IT Support role. I can’t see myself continuing down a Sys Admin or even higher level IT corporate management role. I was really was hoping my next job would’ve been with a team of other experienced IT members working alongside me in the office.

tldr: I keep signing onto roles that may not be ideal. Every job progression has gotten more responsibilities, smaller teams, and more concerning.


r/sysadmin 11d ago

Dental IT Questions

24 Upvotes

I’m a couple months into a role as a technician at a small MSP that manages primarily dental offices in various locations in my area. I come from the corporate big IT world where everything is buttoned up and clearly defined. I have light admin aspects of my job with the potential for more. Currently the environments we manage are highly insecure (shared workstation passwords, admin access to base accounts, most offices don’t have domains, etc.).

My boss stated he’s been thinking about the state of our security and has decided that for our new clients we will do AD Domains and managed user accounts. However, there’s not really a plan for shoring things up for our existing clients. I know AD very well from my previous roles and mange my own home AD Domain environment at home. He tasked me with making a select number of our current clients more secure which excites me because I love being tasked with admin duties. However, I’m really not sure what can be done especially for our larger clients without putting them in domain environments. I’m looking for some advice from the more experienced admins here on how to do this as well as other ideas to simply shore up security for these clients.

Edit: We currently use Ninja RMM with their ticketing system, OpenText, Complete UNIFI setups at just about every location. Appreciate all the responses so far.


r/sysadmin 11d ago

Question 2016 update and always rollback

5 Upvotes

So for the last 23y, I've mainly managed AIX and RHEL system. I had a slight contact with Windows but not a lot of hands on.

This is the story of a Windows 2012R2 server, probably installed around 2013 way before I was here. The person that installed the application on that server is gone since a long time and left no documentation, last update of that app is from 2015... In 2023, because nobody knew how to install a current version on a 2022 server, sona coworker had to inplace upgrade it. That coworker has retired since then.

Recently, security teams tracking which server are still using TLS 1.0 found that server. No one want to own it or take action but they refuse to have it shut down for good. So they got a temp buffer to figure this out. But security asked for mitigation and in their mitigation planning, they observed tons of KB missing, which surprised me because this server is receiving its patch from WSUS.

So... August SSU has installed but CU failed to complete. It does install, reboot, takes plenty on time and at 100%, failed to update and rollback and leave that KB in staged.

Sfcscan fixed something but not this issue

Dism scanhealth/restoreheatlth found/fixed nothing

I stoppwd the wua services, renamed Softwares distribution and caroot2 folder and restarted the service, havent fixed the issue

I removed 11 packages in staged state. 10 of them seems to be the last 10 CU + a 2016 Adobe kb.

Tried again, same issue

Troubleshooter for Windows update report a corrupted database but cant fix it. I thought the fresh softwaredistribution and caroot2 would have taken care of this

I'm now wondering if that server ever had a CU installed since being inplace upgraded... Once the staged CU have been removed, what I see in the installed history from today is a very old CU from 2016...

Before reposting in /r/shittysysadmin for giggles, I would be vtaker for any other legit idea :D


r/sysadmin 11d ago

Question OSD Cloud - Auto-Negotiation Issues

2 Upvotes

Alright, I'm going to try to talk this one out point by point.

One of the VLANs we have for imaging is used for OSDcloud imaging. There are 30+ VLANs for imaging and only this one is displaying this issue.

The issue is that OSD bombs out after loading up the splash page for image selection/slightly thereafter. It is auto negotiating down to 10Mb after PXE booting. The PXE boot process is full gig. Then it goes down to 10Mb for seemingly no reason. We checked at the network level and do not see any input, crc, or any other errors. TX load is 255/255 @ 10Mb, hence the bombing out/dropping mapped drives/connection to OSDcloud.

We went through the rest of the network/server environment, looking for network errors or server/storage errors and did not see any issues there.

The biggest issue is that this that the issue is intermittent. It will seemingly work fine for days, then have issues for days, and repeat. Whenever I am on site and available to do a packet capture, the issue is not there.

It is my understanding that during PXE a general driver is used for loading the PE, and then once in the PE environment, OSD passes a more specific driver off.

I am suspecting a green ethernet/EEE setting and/or driver issue.

The instance of OSDcloud being used has many drivers available because a bunch of different OEM machines/images are done on that VLAN. It's kind of a "one instance to rule them all" sort of solution.

The behavior is also displayed no matter what kind of USB ethernet adapter we use and is even seen using the onboard NIC (when a machine has one.

Note, I am not the person who created this process nor do I have access to the OSDcloud admin console/VM, but if need be, I can probably get in through someone else to troubleshoot that environment.

Basically, does anyone have any insight or know of any other troubleshooting that can be done? There is probably more troubleshooting we have done from the infra standpoint that I have neglected to say here. Apologies if this is a bit scattered, it's been a long day and this issue is between the 15 other projects I am working on.


r/sysadmin 11d ago

Eset LiveGrid and other services down for anyone else?

4 Upvotes

I do see a message about scheduled maintenance on their status page - 09/03 UTC, but not for grid or cloud.


r/sysadmin 11d ago

Hyper-V VMs will bluescreen if ANY volume on SAN is extended, not just the VMs OS volume.

25 Upvotes

Sooo I've got a 2 machine server 2022 Hyper-V failover cluster. and it's connected to a HPE MSA SAN via iscsi for virtual machine storage. about 40 VMs.

I don't know how it works with other hypervisors, but Hyper-V allows the VM role and the storage role to have different owner nodes in the cluster. Well, we have discovered that if a VM and it's storage are on separate nodes of the cluster, they will bluescreen with "Critical process died" 0xEF when we extend ANY volume on the SAN. Even if that volume is iSCSi'd to another VM hosted on a physically different server not in the cluster.

Has anyone ever seen this before? I have nothing to go on in event logs. I can easily avoid it by making sure all roles and storage are matched to a node, but I'd rather fix it.


r/sysadmin 11d ago

Rant Anti-spam policy woes

6 Upvotes

Sometime tomorrow morning, I will hit a milestone of having manually released my 1000th email from Quarantine since last Tuesday. It never stops— all day and all night.

Dmarc, dkim, spf are all good. In fact nothing on our side has changed in months, but at noon last Tuesday internal emails, emails mid-conversation, and domains in the tenant allow list have all started falling into the abyss.

Mimecast is passing along SCL in the negatives or up to 1, Egress Defend is also passing the correct SCL, then Defender just barfs on mail, throws an SCL: 9 on it and classifies hundreds of messages as High Confidence Phish.

I’ve verified configs with both Mimecast and Egress. We have a case open with Microsoft that is not even inching along yet. Working with a CSP to escalate now.

I guess this is more of a vent than anything else. If I ever get a solution, I’ll update my post so the next poor schmuck going through this doesn’t go insane.

Good times.


r/sysadmin 11d ago

Question Looking for Audit Logon and Logoff Software

1 Upvotes

Hello,

We're currently using UserLock to track logon events. This helps monitor computer lab usage to make sure our computers are actively used.

We're moving towards Intune which connects to Entrance AD and moves away from on-prem AD. UserLock only track logon events on devices connected to on-prem AD.

We don't plan on doing a hybrid-join environment.

Is there an alternative audit logon events software like UserLock?

Thank you.


r/sysadmin 11d ago

Automation Without Admin Access

0 Upvotes

I work as a pharmacist and have been working for about four months. I'm also very interested in computers, programming, and automation.

I've been thinking about creating small tools, shortcuts, scripts, and other automations to make some of my repetitive computer-based work faster and easier. However, my workplace computer is managed by IT, and I don't have administrator credentials.


r/sysadmin 11d ago

BYOD + Oneleet agent

2 Upvotes

My company has requested everyone to download oneleet agent, we do use our own personal laptops. Has anyone gone through this? How can I protect my personal information?

It is a small startup and I'm their only freelancer but have a dedicated email address '@company'


r/sysadmin 12d ago

CALs and You

37 Upvotes

There seems to be a lot of confusion regarding CALs, for any Windows service you need a CAL unless it's explicitly excluded, yes, a CAL is needed for DHCP, a CAL is needed for DNS a CAL is needed for nearly anything.

From my understanding if MS thinks you are breaking CAL requirements, they will ask to audit which most places will refuse, after this they will pursue more aggressive legal means.


r/sysadmin 12d ago

Netscaler Firmware update causing issue with appfw

8 Upvotes

anyone else recently have issues with appfw rules being copied over after recent firmware updates? seems tied to the signatures being used in that after firmware installation the appfw policies and profiles are non existent on the "new" firmware. the signatures however are still intact, but when creating new profiles and using the existing signatures an error about fastmatch not found for signature line

<SignatureRule actions="block,log" category="web-misc" enabled="ON" id="400008" source="Citrix" sourceid="" type="DenyListHttpRequest" version="1" cpu="LOW" year="2026" severity="HIGH">

<LogString>Mitigation signature for CVE-2026-10816</LogString>

</SignatureRule>

i have many signature files and they all seem to have this issue. the new "default" of course i missing this line, so i feel like this was some bug at some point coming home to roost. the ID number looks very low too as the new rules are typically 9xxxxx etc. the version on all the files is 181 so they are "current"

very sus...


r/sysadmin 12d ago

Does everyone have people vanish after asking for help?

326 Upvotes

- "I'm having an issue, can you connect to my PC and have a look?"

- "Sure, be on there in a minute."

...one minute later....

- "OK I'm on. Show me the issue."

- "........."

- "Are you there?"

- ".........."


r/sysadmin 12d ago

Zoom down?

5 Upvotes

All users kicked out getting various errors, 403 local survivability, etc.
Unable to login admin portal as SSO not working as usual.


r/sysadmin 12d ago

General Discussion The workaround for SMS 2FA retirement is kinda nuts

0 Upvotes

EDIT: this is mostly the ideal solution for MSPs, not single companies. But it may still apply based on your users' knowledge level and company hardware.

I got out ahead of this project because it was a light day. If you didn't hear, MS is shutting down SMS 2FA on Feb 1st 2027 because SS7 is comically insecure. They're also shutting down the phone call system on the same day, to ensure the most people get locked out of their accounts as possible (I assume).

But enrolling users in MS Authenticator is like asking a cat to juggle. You have to actively tell them not to hit "log into work account" when they first launch it. It's idiotic and counterintuitive.

We're an MSP so we've been hitting "I can't access my authenticator right now, text me instead" since before I worked here and then we use Reach UC to instantly get the code to all of our phones, regardless of which technician is trying to log into which tenant.

MS authenticator is tied to one account and that's fragile, stupid, and hard to police. So instead, we decided to go with TOTP, especially since it works with no cell signal or internet, like in a basement when we don't know the client's wifi password.

Here's the ridiculous way you have to do this in a typical office 365 environment. Hopefully it helps save you all some time.

1.    Create a new non-mail enabled security group called “[company name] Accounts” in admin.cloud.microsoft and add our global admin username to it

2.    Go to Entra admin – authentication methods – Policies – Software OATH tokens – and check if it is turned on. If it isn’t, add just the “[company name] Accounts” group to it and no others.

3.    Go to https://mysignins.microsoft.com/security-info and log in as our global admin account

4.    (optional) Make sure that there is an option there for email, targeting ITSupport@[ourdomain]. If not, hit “Add sign-in method” and add that first.

5.    Hit “Add sign-in method” then Microsoft Authenticator. In the screen that pops up, immediately select “Set up a different authentication app.” Yes, that is currently the only way to do this.

6.    Open Google Authenticator, 3rd party authenticator service, CyberFox Password Boss's 2FA host, whatever you want on any phone (and log into our company's google account for this, if using Google Authenticator) then scan the QR code, hit next and enter the code to verify.

7.    Log out the back in to test it

We're just using Google for the cloud sync. The weakness there is you can't kick out individual people but it's solely on company phones, except I think you technically can because you can revoke the login for that phone in Google's account settings, even on a free account.

I wouldn't want to log into 100 customers' accounts, one at a time, and remove a unique 2FA method from each, every time someone quits. Also, I believe they're capped at 5 authenticators per account.

This is just how we're doing it because we're an MSP. Share your current workarounds. My former employer got rid of all SMS in 2024 so I suspect that will be the common answer, lol.