Alert before deleting SIEM Syslog source/agent
M
Matt Yordy
I discovered recently that we uninstalled/reinstalled a Huntress agent that was also serving as the Syslog source agent for a specific client. As a result, we lost our Syslog source on the network.
To prevent this from happening in the future, I request implementing a safeguard within Huntress:
Please consider adding an alert or confirmation prompt that triggers when attempting to delete an agent designated as a Syslog source. Ideally, this would require explicit approval or acknowledgment before proceeding with the deletion.
This change could help avoid unintended disruptions to logging and monitoring workflows.
C
Cody Arnold
I think it would be simple to add a check if a device has a syslog collector role to say “hey, this agent has the role of X, are you sure?”
B
Bjørn Mathisen
Or maybe just recreate the source connection automatically when the agent reappears?