-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathindex.html
More file actions
166 lines (163 loc) · 26.4 KB
/
Copy pathindex.html
File metadata and controls
166 lines (163 loc) · 26.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
<!DOCTYPE html>
<html lang="en">
<head>
<meta name="generator" content="Hugo 0.87.0" />
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="robots" content="noodp" />
<meta http-equiv="X-UA-Compatible" content="IE=edge, chrome=1">
<title></title><meta name="Description" content=""><meta property="og:title" content="" />
<meta property="og:description" content="" />
<meta property="og:type" content="website" />
<meta property="og:url" content="http://example.org/" />
<meta name="twitter:card" content="summary"/>
<meta name="twitter:title" content=""/>
<meta name="twitter:description" content=""/>
<meta name="application-name" content="">
<meta name="apple-mobile-web-app-title" content=""><link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" />
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png"><link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png"><link rel="manifest" href="/site.webmanifest"><link rel="canonical" href="http://example.org/" /><link rel="alternate" href="/index.xml" type="application/rss+xml" title="">
<link rel="feed" href="/index.xml" type="application/rss+xml" title=""><link rel="stylesheet" href="/lib/normalize/normalize.min.css"><link rel="stylesheet" href="/css/style.min.css"><link rel="stylesheet" href="/lib/fontawesome-free/all.min.css"><link rel="stylesheet" href="/lib/animate/animate.min.css"><script type="application/ld+json">
{
"@context": "http://schema.org",
"@type": "WebSite",
"url": "http:\/\/example.org\/","inLanguage": "en","license": "This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.","name": ""
}
</script></head>
<body header-desktop="" header-mobile=""><script type="text/javascript">(window.localStorage && localStorage.getItem('theme') ? localStorage.getItem('theme') === 'dark' : ('' === 'auto' ? window.matchMedia('(prefers-color-scheme: dark)').matches : '' === 'dark')) && document.body.setAttribute('theme', 'dark');</script>
<div id="mask"></div><div class="wrapper"><header class="desktop" id="header-desktop">
<div class="header-wrapper">
<div class="header-title">
<a href="/" title=""></a>
</div>
<div class="menu">
<div class="menu-inner"><a class="menu-item active" href="/"> Home </a><a class="menu-item" href="/posts/"> Posts </a><a class="menu-item" href="/tags/"> Tags </a><a class="menu-item" href="/categories/"> Categories </a><span class="menu-item delimiter"></span><a href="javascript:void(0);" class="menu-item theme-switch" title="Switch Theme">
<i class="fas fa-adjust fa-fw"></i>
</a>
</div>
</div>
</div>
</header><header class="mobile" id="header-mobile">
<div class="header-container">
<div class="header-wrapper">
<div class="header-title">
<a href="/" title=""></a>
</div>
<div class="menu-toggle" id="menu-toggle-mobile">
<span></span><span></span><span></span>
</div>
</div>
<div class="menu" id="menu-mobile"><a class="menu-item" href="/" title="">Home</a><a class="menu-item" href="/posts/" title="">Posts</a><a class="menu-item" href="/tags/" title="">Tags</a><a class="menu-item" href="/categories/" title="">Categories</a><a href="javascript:void(0);" class="menu-item theme-switch" title="Switch Theme">
<i class="fas fa-adjust fa-fw"></i>
</a></div>
</div>
</header>
<div class="search-dropdown desktop">
<div id="search-dropdown-desktop"></div>
</div>
<div class="search-dropdown mobile">
<div id="search-dropdown-mobile"></div>
</div>
<main class="main">
<div class="container"><div class="page home" posts><div class="home-profile"><div class="links"><a href="https://github.com/robrankin" title="Github" target="_blank" rel="noopener noreffer me"><i class="fab fa-github-alt fa-fw"></i></a><a href="https://twitter.com/mahhyzero" title="Twitter" target="_blank" rel="noopener noreffer me"><i class="fab fa-twitter fa-fw"></i></a><a href="https://www.linkedin.com/in/rob-rankin-7312234" title="LinkedIn" target="_blank" rel="noopener noreffer me"><i class="fab fa-linkedin fa-fw"></i></a><a href="mailto:blog@undertow.ca" title="Email" rel=" me"><i class="far fa-envelope fa-fw"></i></a></div></div>
<article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/github-org-auditlogs-elasticsearch/">Storing GitHub Org Auditlogs in Elasticsearch</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2022-04-22">2022-04-22</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/github/"><i class="far fa-folder fa-fw"></i>github</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">I had a need to generate an alert when someone overrode a Branch Protection setting. To do this I decided to pull some of the GitHub Auditlog into Elasticsearch.
Theres a GitHub API client written in sh, called ok.sh, which can be found here. At the time it didn’t support querying the Org Auditlog, so I PR’d that here.
Once the PR was in place, I wrote a Dockerfile to create a container to deploy on Kubernetes.</div><div class="post-footer">
<a href="/posts/github-org-auditlogs-elasticsearch/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/azure/">azure</a>, <a href="/tags/cloud/">cloud</a>, <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/logstash/">logstash</a>, <a href="/tags/alerting/">alerting</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/packet-capture-tcpdump-kubernetes-pods-azure/">Packet Capture using tcpdump on Kubernetes Pods in Azure AKS</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2022-04-21">2022-04-21</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/kubernetes/"><i class="far fa-folder fa-fw"></i>kubernetes</a></span></div><div class="content">Assuming the target containers can actually install new software (apt install is available) what follows is a quick and very dirty method to run tcpdump on k8s/AKS containers in Azure.
If you’re running Kubernetes 1.23 and up, please read this instead:
https://downey.io/blog/kubernetes-ephemeral-debug-container-tcpdump/
Install some needed utilities Use whatever pod label is required to target the right pods.
kubectl get pods -l <LABEL> -o name | \ xargs -I{} kubectl exec {} -- apt-get -y update Install tcpdump, screen, psmisc, and rclone</div><div class="post-footer">
<a href="/posts/packet-capture-tcpdump-kubernetes-pods-azure/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/kubernetes/">kubernetes</a>, <a href="/tags/aks/">aks</a>, <a href="/tags/azure/">azure</a>, <a href="/tags/k8s/">k8s</a>, <a href="/tags/tcpdump/">tcpdump</a>, <a href="/tags/packet-capture/">packet capture</a>, <a href="/tags/rclone/">rclone</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/azure-translation-services-elasticsearch-logstash/">Azure Translation Services with Elasticsearch and Logstash</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2022-03-31">2022-03-31</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">Recently had a need to parse some XML into Elasticsearch, specifically some CERT RSS feeds. Logstash has an RSS input, but it’s a bit basic, and doesn’t provide any language indications if the RSS feed includes them. One of the feeds I’m using can be various languages per item, and many others are non-english entirely.
Since this would be parsing the same RSS feeds repeatedly, I need a predictable Document ID, so I can re-insert / upsert the item, and not create a new document every time the RSS feed is parsed.</div><div class="post-footer">
<a href="/posts/azure-translation-services-elasticsearch-logstash/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/azure/">azure</a>, <a href="/tags/cloud/">cloud</a>, <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/logstash/">logstash</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/fedora-coreos-on-raspberry-pi4/">Fedora CoreOS 35 USB Boot on Raspberry Pi 4</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2022-03-23">2022-03-23</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/raspberrypi/"><i class="far fa-folder fa-fw"></i>raspberrypi</a></span></div><div class="content">Note: While the RPI now boots, if I have anything else plugged into USB ports, such as a keyboard, it throws the same TRB related error.
For whatever reason, Fedora’s support of Raspberry Pi4’s seems a bit iffy. The official documentation (here) is quite good, and I managed to easily get the RPI4 booting CoreOS via the EDK2 UEFI firmware approach. The problem was that I wanted to use the U-Boot approach, and that was just not playing ball.</div><div class="post-footer">
<a href="/posts/fedora-coreos-on-raspberry-pi4/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/raspberrypi/">raspberrypi</a>, <a href="/tags/fedora/">fedora</a>, <a href="/tags/coreos/">coreos</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/modsecurity-detectiononly-and-enforcing-select-rules/">Modsecurity, DetectionOnly and enforcing select rules</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2021-08-17">2021-08-17</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/security/"><i class="far fa-folder fa-fw"></i>security</a> <a href="/categories/modsecurity/"><i class="far fa-folder fa-fw"></i>modsecurity</a></span></div><div class="content">I recently had a reason to want to achieve the following:
ModSecurity globally in DetectionOnly mode (not enforcing rules, just logging) Continue to operate the CRS in DetectionOnly mode. For a specific ruleset: Enforcing a default deny on inbound requests to an API. Enforcing allow rules for specific API routes and methods of the API So I wanted all of our inbound CRS rules to continue to work in DetectionOnly mode, while I had a custom set of rules that would deny all access, with a set of whitelists to specific methods/paths.</div><div class="post-footer">
<a href="/posts/modsecurity-detectiononly-and-enforcing-select-rules/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/modsecurity/">modsecurity</a>, <a href="/tags/waf/">waf</a>, <a href="/tags/web-application-firewall/">web application firewall</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/alerting-using-siem-detections-and-elastalert/">Alerting using SIEM Detections and ElastAlert2</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2021-08-17">2021-08-17</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/security/"><i class="far fa-folder fa-fw"></i>security</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">ElasticSearch SIEM Detections and Alerts and Actions are quite useful features, except for the fact that actual alerting is behind a license paywall. So while both of these features can run rules, check for conditions, and record the results in an index, neither of them actually provide alerting support.
Alerting requires a Gold License, which if alerting is the only thing you want, is an excessive cost.
If you can’t move off ElasticSearch to OpenSearch, which has Alerting available for free, you can use tools such as ElastAlert21 to handle the Alerting requirements.</div><div class="post-footer">
<a href="/posts/alerting-using-siem-detections-and-elastalert/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/opensearch/">opensearch</a>, <a href="/tags/elastalert/">elastalert</a>, <a href="/tags/elastalert2/">elastalert2</a>, <a href="/tags/alerting/">alerting</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/using-elasticsearch-upserts-to-combine-multiple-event-lines-into-one/">Using Elasticsearch Upserts to Combine Multiple Event Lines Into One</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2020-11-24">2020-11-24</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">Note This approach is probably not appropriate for high volume / high throughput events. It required in my case quite a lot of Logstash parsing, and Elasticsearch doc_as_upsert use, both of which will have a significant performance penalty. For low throughput use it works fine.
Sometimes log sources split logically grouped events into separate lines, and sometimes those logically grouped event lines are mixed into the same log file with actual singular line events.</div><div class="post-footer">
<a href="/posts/using-elasticsearch-upserts-to-combine-multiple-event-lines-into-one/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/filebeat/">filebeat</a>, <a href="/tags/logstash/">logstash</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/shell-script-azure-storage-using-a-service-principle/">Shell script, Azure Storage using a Service Principle</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2020-10-20">2020-10-20</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/azure/"><i class="far fa-folder fa-fw"></i>azure</a> <a href="/categories/azure-storage/"><i class="far fa-folder fa-fw"></i>azure storage</a></span></div><div class="content">Needed something in shell to upload files to an Azure Storage account. Hopefully its useful for others, so put it up on Github here ( https://github.com/robrankin/bash-azure-storage )</div><div class="post-footer">
<a href="/posts/shell-script-azure-storage-using-a-service-principle/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/azure/">azure</a>, <a href="/tags/azure-storage/">azure storage</a>, <a href="/tags/bash/">bash</a>, <a href="/tags/shell/">shell</a>, <a href="/tags/script/">script</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/event-threat-enrichment-logstash-minemeld/">Event Threat Enrichment using Logstash and Minemeld</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Author</a></span> <span class="post-publish">published on <time datetime="2020-09-25">2020-09-25</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/security/"><i class="far fa-folder fa-fw"></i>security</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">At my work we use the Elastic Stack for quite a few things, but one of the more recent-ish “official” roles is as our SIEM. Elastic introduced SIEM specific funcationality to Kibana a few releases ago, around 7.4 if I rembember correctly.
One of the features that the Elastic Stack doesn’t really support well (yet) is an enrichment system. They did introduce an elasticsearch side enrichment system in 7.5, but in my opinionn theres a few problems with it:</div><div class="post-footer">
<a href="/posts/event-threat-enrichment-logstash-minemeld/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/minemeld/">minemeld</a>, <a href="/tags/logstash/">logstash</a>, <a href="/tags/threat-feeds/">threat feeds</a>, <a href="/tags/security/">security</a>, <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/kibana/">kibana</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/querying-cylance-protect-api-from-shell/">Querying Cylance Protect Api From Shell</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2020-09-11">2020-09-11</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/cylance/"><i class="far fa-folder fa-fw"></i>cylance</a></span></div><div class="content">We use Cylance as our AV type protection. They’re one of the better solutions I’ve seen, but theres some strange gaps in my opinion. There doesn’t seem to be a built in method for alerting. One of the things we’d like to be able to alert on is when a devices goes “offline”, and apparently this information is not provided through Cylance’s syslog output. It is however available from their API.</div><div class="post-footer">
<a href="/posts/querying-cylance-protect-api-from-shell/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/jwt/">jwt</a>, <a href="/tags/shell/">shell</a>, <a href="/tags/cylance/">cylance</a>, <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/curl/">curl</a>, <a href="/tags/jq/">jq</a>, <a href="/tags/openssl/">openssl</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/kibaba-oauth-kubernetes/">Kibaba Authentication using OAuth2 Proxy in Kubernetes</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2020-08-06">2020-08-06</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a> <a href="/categories/kubernetes/"><i class="far fa-folder fa-fw"></i>kubernetes</a> <a href="/categories/elasticsearch/"><i class="far fa-folder fa-fw"></i>elasticsearch</a></span></div><div class="content">NOTE: There appears to be a bug with Kibanas impersonation features, and SIEM detection rules (and possibly elswhere): https://github.com/elastic/kibana/issues/74828
Recently I had reason to want to integrate Kibana with Azure Active Directory for authentication. This might be easily possible if you have a commercial license with Elastic, but this wasn’t the case this time.
After a little bit of research I found this article, from February 2017:
User Impersonation with X-Pack: Integrating Third Party Auth with Kibana</div><div class="post-footer">
<a href="/posts/kibaba-oauth-kubernetes/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/kubernetes/">kubernetes</a>, <a href="/tags/kibana/">kibana</a>, <a href="/tags/authentication/">authentication</a>, <a href="/tags/mfa/">mfa</a>, <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/oauth2_proxy/">oauth2_proxy</a></div></div>
</article><article class="single summary" itemscope itemtype="http://schema.org/Article"><h1 class="single-title" itemprop="name headline">
<a href="/posts/elasticsearch-provided-name/">Elasticsearch Provided Name and ILM</a>
</h1><div class="post-meta"><span class="post-author"><a href="/" title="Author" rel=" author" class="author"><i class="fas fa-user-circle fa-fw"></i>Rob Rankin</a></span> <span class="post-publish">published on <time datetime="2020-06-04">2020-06-04</time></span> <span class="post-category">included in <a href="/categories/tech/"><i class="far fa-folder fa-fw"></i>tech</a></span></div><div class="content">As I was learning a little about ElasticSearch’s ILM (Index Lifecycle Management) feature, I ran across a parameter called provided_name when examining an index.
A bit of searching turned up the this Github issue, but it doesn’t really explain where it comes from.
A bit more searching led me here.
So provided_name is a method of templating index names it seems, using date math as explained in the documentation.
Just make sure to HTML encode the index name, as per the example from the documentation:</div><div class="post-footer">
<a href="/posts/elasticsearch-provided-name/">Read More</a><div class="post-tags">
<i class="fas fa-tags fa-fw"></i> <a href="/tags/elasticsearch/">elasticsearch</a>, <a href="/tags/opensearch/">opensearch</a>, <a href="/tags/provided_name/">provided_name</a>, <a href="/tags/ilm/">ilm</a>, <a href="/tags/index-lifecycle-management/">index lifecycle management</a></div></div>
</article><ul class="pagination"><li class="page-item active">
<span class="page-link">
<a href="/">1</a>
</span>
</li><li class="page-item ">
<span class="page-link">
<a href="/page/2/">2</a>
</span>
</li></ul></div></div>
</main><footer class="footer">
<div class="footer-container"><div class="footer-line">Powered by <a href="https://gohugo.io/" target="_blank" rel="noopener noreffer" title="Hugo 0.87.0">Hugo</a> | Theme - <a href="https://github.com/dillonzq/LoveIt" target="_blank" rel="noopener noreffer" title="LoveIt 0.2.10"><i class="far fa-kiss-wink-heart fa-fw"></i> LoveIt</a>
</div><div class="footer-line"><i class="far fa-copyright fa-fw"></i><span itemprop="copyrightYear">2022</span><span class="author" itemprop="copyrightHolder"> <a href="/" target="_blank"></a></span></div>
</div>
</footer></div>
<div id="fixed-buttons"><a href="#" id="back-to-top" class="fixed-button" title="Back to Top">
<i class="fas fa-arrow-up fa-fw"></i>
</a><a href="#" id="view-comments" class="fixed-button" title="View Comments">
<i class="fas fa-comment fa-fw"></i>
</a>
</div><script type="text/javascript" src="/lib/smooth-scroll/smooth-scroll.min.js"></script><script type="text/javascript" src="/lib/lazysizes/lazysizes.min.js"></script><script type="text/javascript" src="/lib/clipboard/clipboard.min.js"></script><script type="text/javascript">window.config={"code":{"copyTitle":"Copy to clipboard","maxShownLines":10}};</script><script type="text/javascript" src="/js/theme.min.js"></script></body>
</html>