A blocked malware site in DefensX becomes a SuperOps ticket within five minutes, with no technician watching a dashboard.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using an n8n workflow to watch a DefensX global URL group and open a SuperOps ticket whenever a client machine tries to reach a site on it. We keep a global malware list in DefensX that applies to every customer. A block on that list is not routine web filtering. It means something on that machine tried to reach a known bad destination, and we want a technician looking at it in minutes, not at the next report review.
Research
DefensX has a Partner API with log endpoints for every customer, and SuperOps has a GraphQL API that can create tickets. The plan was simple: poll DefensX, find blocks from our list, create a ticket for the right client. Getting there took more discovery than expected. Here is what we ran into:
There is no webhook, and the logs don’t say which group caused the block. The URL log gives you the URL, the action and a category, but not the URL group that matched. The workflow has to pull the group’s entries itself and do the matching. That means handling all three entry styles DefensX allows: exact hostnames, *.domain.com wildcards, and full URLs with a path.
Browser logs are only half the picture. Our first test was a curl from a command prompt, and it never appeared in the URL logs. The browser extension only sees browser traffic. Anything else, including scripts and processes running as SYSTEM, is caught by the agent and written to the DNS logs. Since malware rarely uses the browser, the workflow checks both endpoints for every customer.
DNS logs are large. One customer returned more than 5,700 DNS rows in a 20-minute window, which is over the 5,000-row page limit. Pagination is not optional.
SuperOps required a field the schema calls optional. Our first ticket failed with mandatory_validation_failed on requestType, even though introspection shows it as a plain optional string. The tenant enforces it.
The next error named a field we never sent. After adding requestType: "Incident", SuperOps answered with referred_value_does_not_exist on ticketType. The field was renamed at some point and the error still uses the old name. The real problem was the value: ticket types are customizable per tenant, and ours has no type called “Incident”. It has “Incident – Security”.
Our API token could not look up the answer. We tried reading the type from existing tickets. The list query returned a total count of 429 and zero rows, and single-ticket lookups returned forbidden. The token could create tickets but not read them. What finally explained everything was asking the schema for field descriptions, not just field types. The description for requestType states that it replaced ticketType and tells you which query lists the valid options.
Repeat hits would flood the board. A machine retrying a blocked connection every few seconds would create a ticket on every run. The workflow remembers each user and site pair for 24 hours and tickets it once. It also keeps a separate time cursor per customer, so a failed API call for one customer is retried from where it left off without holding up the others.
Variables
Everything you need to change lives in one Set node at the top of the workflow:
urlGroupName – the exact name of the DefensX URL group to watch, for example Global Malware List
groupOwnerCustomerId – leave blank if the group lives on your partner account; otherwise the ID of the customer that owns it
suppressHours – how long to stay quiet about the same user and site after a ticket is created (default 24)
overlapMinutes – how far each run reaches back past the last one, to catch logs that arrive late (default 5)
includeConsented – whether to report blocks the user clicked through (default true)
defangUrls – writes sites as example[.]com in the ticket so nobody clicks one by accident (default true)
superopsSubdomain – your SuperOps subdomain, sent as the CustomerSubDomain header
ticketRequestType – one of your own ticket type names, spelled exactly as it appears in SuperOps
fallbackSuperOpsAccountId – the client that receives the ticket when a DefensX customer name has no match in SuperOps
customerNameMap – optional JSON for customers whose names differ between the two systems
API keys go in n8n credentials, never in the workflow itself.
Script Snippet
The matching logic runs in a Code node. Wildcard entries match the domain and every subdomain, and path entries are only checked against URL logs because a DNS lookup has no path:
function findEntry(target, hasPath) {
for (const e of ctx.entries) {
const hostOk = e.wildcard
? (target.host === e.host || target.host.endsWith('.' + e.host))
: target.host === e.host;
if (!hostOk) continue;
if (!e.path) return e;
if (hasPath && (target.path === e.path || target.path.startsWith(e.path + '/'))) return e;
}
return null;
}
Both log endpoints use the same pagination settings on the HTTP Request node:
Each ticket lands on the matching SuperOps client with a table showing the time, user, device, site, number of blocks and whether it came from the browser or the agent. Query strings are stripped from URLs before they are written, so session tokens never end up in a ticket.
The complete workflow, with the customer loop, DNS and URL log handling, SuperOps client matching and duplicate suppression, is free on our GitHub: [GITHUB LINK]
If your company is a MSP or wants to become one and automation just seems out of reach, then contact us to run your RMM for you.
Duo authentication and admin activity logs flowing into a self-hosted Wazuh SIEM, ready for MFA monitoring and CMMC audit evidence.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using a Bash script to forward Cisco Duo MFA logs into a self-hosted Wazuh SIEM.
We recently connected Duo to the onsite Wazuh server of a client working toward CMMC Level 2. Logging every MFA event and every admin change is part of the evidence an assessor wants to see (NIST 800-171 controls 3.3.1 and 3.5.3). Duo ships an official tool for exactly this. Getting it to produce real Wazuh alerts took some work, so we turned everything we learned into one script that you can run by hand or from SuperOps RMM.
Research
Duo publishes DuoLogSync (github.com/duosecurity/duo_log_sync), a small Python service that pulls logs from the Duo Admin API and sends them as JSON over TCP. The plan was simple: run DuoLogSync on the Wazuh manager, send its output to a syslog listener that only accepts local connections, and let Wazuh’s built-in JSON decoder do the rest. No agent, no public port, no custom decoder.
In practice, five things got in the way. They aren’t obvious from the documentation:
Stock Wazuh rule 86600 (Suricata) matches any JSON event that has both “timestamp” and “event_type” fields. Duo auth logs have both, so every event was captured by a level 0 rule and silently thrown away. Our rules now hang under 86600 as child rules.
Wazuh loads every rule file, stock and custom together, in alphabetical order. Naming the file 9999_duo_rules.xml makes sure it loads after the stock rules it depends on.
“action” is a reserved Wazuh field name, so a field match on it stops the whole ruleset from loading. Use the <action> tag or a dotted field like action.name instead.
DuoLogSync 2.4 retired the “adminaction” endpoint. Admin events now come from the “activity” log, which has a completely different JSON layout.
DuoLogSync opens one TCP connection and never reconnects. Every Wazuh manager restart quietly lost the next batch of logs. The fix is a systemd unit tied to the manager with PartOf=wazuh-manager.service.
The payoff showed up right away. The 180-day history pull surfaced twelve failed Active Directory syncs, all caused by a Duo Authentication Proxy outage. If an AD sync fails, a user you just disabled in AD can still pass Duo, so that’s a finding worth knowing about.
Variables
DuoIntegrationKey = The integration key of a Duo Admin API application with only “Grant read log” permission – i.e. DIXXXXXXXXXXXXXXXXXX DuoSecretKey = The secret key for that application (mark this as a secure variable in SuperOps) DuoApiHost = The API hostname from the same application – i.e. api-xxxxxxxx.duosecurity.com DuoEndpoints = Optional. Which Duo logs to pull – default auth,telephony,activity DuoOffsetDays = Optional. How many days of history to pull on the first run, maximum 180 DuoAction = Optional. install, status, resend or uninstall
Script Snippet
The full script handles prerequisite checks, backups, validation, automatic rollback, and a final check with wazuh-logtest. These are the core pieces:
# DuoLogSync config - single quotes are required by DLS
cat > /opt/duologsync/config.yml <<EOF
version: '1.0.0'
dls_settings:
log_format: 'JSON'
api:
offset: $DLS_OFFSET_DAYS
checkpointing:
enabled: True
directory: '/opt/duologsync/checkpoints'
servers:
- id: 'wazuh'
hostname: '127.0.0.1'
port: 5140
protocol: 'TCP'
account:
ikey: '$DUO_IKEY'
skey: '$DUO_SKEY'
hostname: '$DUO_API_HOST'
endpoint_server_mappings:
- endpoints: ['auth', 'telephony', 'activity']
server: 'wazuh'
EOF
# Local-only listener added to ossec.conf
<remote>
<connection>syslog</connection>
<port>5140</port>
<protocol>tcp</protocol>
<local_ip>127.0.0.1</local_ip>
<allowed-ips>127.0.0.1</allowed-ips>
</remote>
# Duo auth events are claimed by Suricata rule 86600 - attach under it
<rule id="120000" level="0">
<if_sid>86600</if_sid>
<field name="txid">\.+</field>
<field name="factor">\.+</field>
<description>Duo: authentication event</description>
</rule>
# systemd: restart with the manager, wait for the listener first
[Unit]
After=wazuh-manager.service
PartOf=wazuh-manager.service
[Service]
ExecStartPre=/bin/bash -c 'until ss -ltn | grep -q "127.0.0.1:5140 "; do sleep 2; done'
ExecStart=/opt/duologsync/venv/bin/duologsync /opt/duologsync/config.yml
Restart=always
The complete script, the SuperOps edition, and the full ruleset (with alerts for MFA fraud reports, MFA fatigue, admin panel brute force, Duo configuration changes and AD sync failures, all tagged for NIST 800-171) are free on our GitHub: https://github.com/FarmhouseNetworking/Duo-Wazuh-LogSync
If your company is a MSP or wants to become one and automation just seems out of reach, then contact us to run your RMM for you.
Key network monitoring tools every small business needs for optimal performance
As a business owner, you know reputation and customer trust are everything. But cybercriminals don’t discriminate by size—small and midsize businesses (SMBs) are increasingly the targets of ransomware and data theft. CIS Critical Security Control 13 gives you a practical way to stay ahead of attackers and protect your company’s future.
Practical Action Steps for SMBs:
Enable real-time network monitoring: Know immediately if your systems are under attack.
Centralize your logs: Aggregate data to detect issues before they escalate.
Set threshold-based alerts: Don’t wait until damage is visible to respond.
Review reports regularly: Make monitoring part of monthly executive/IT reviews.
Q&A for SMBs:
“Aren’t we too small for hackers to notice?” No—SMBs are now among the most targeted because criminals assume defenses are weak.
“Do I need an in-house IT team for this?” Not necessarily—outsourced experts can cost-effectively handle monitoring for you.
How Farmhouse Networking Helps: Farmhouse Networking provides SMBs with managed network monitoring, advanced alerts, and proactive defense strategies. We scale solutions to fit your size, budget, and growth goals.
Don’t leave your business exposed. Email Farmhouse Networking today and start building stronger defenses for lasting success.
How MSP Automation Transforms Manual Workflows for Business Owners
MSP automation eliminates manual tasks and boosts operational efficiency
Are you still relying on manual processes and inefficient workflows to run your business? If so, you’re not alone—but you may be leaving significant productivity and profitability on the table. Modern Managed Service Providers (MSPs) are helping business owners like you automate routine tasks, integrate essential applications, and streamline operations like never before. Here’s how MSP-driven automation can revolutionize your daily operations and set your business up for scalable success.
The Problem: Manual Workflows Are Costing You Time and Money
Manual data entry, repetitive administrative tasks, and disconnected systems can bog down even the most dedicated teams. These inefficiencies lead to:
Wasted time: Employees spend hours on tasks that could be automated.
Increased errors: Manual processes are prone to mistakes, leading to costly corrections.
Slower growth: When staff are overwhelmed with routine tasks, there’s little bandwidth left for innovation and strategic initiatives.
Seamless Integration of Essential Business Applications
Many businesses use a patchwork of tools for CRM, accounting, project management, and more. When these systems don’t communicate, data silos form, leading to confusion and inefficiency.
MSPs help you:
Integrate your tech stack: Connect CRM, email, project management, and other tools so data flows smoothly between them.
Eliminate manual data entry: Employees no longer need to copy information from one system to another, reducing errors and saving time.
Gain unified visibility: Centralized dashboards provide real-time insights into performance, helping you make informed decisions quickly.
Streamlined Workflows for Maximum Productivity
With automation and integration in place, MSPs help you:
Simplify complex processes: Workflows are automated and streamlined, reducing manual intervention and freeing up your team.
Reduce errors and delays: Automation minimizes human error and ensures tasks are completed on time.
Improve employee satisfaction: Staff can focus on meaningful work, leading to higher morale and better retention.
The Results: More Time, Fewer Errors, and a Stronger Bottom Line
Businesses that embrace MSP-driven automation see:
40%+ improvement in process efficiency
75% reduction in manual errors
ROI within six months
These gains translate into faster growth, happier clients, and a more resilient business.
Ready to Transform Your Business?
Don’t let manual processes hold your business back. Farmhouse Networking specializes in helping business owners automate routine tasks, integrate essential applications, and streamline workflows—so you can focus on what you do best.
Contact Farmhouse Networking today to discover how MSP automation can boost your productivity and accuracy—and set your business on the path to lasting success.
Enhanced DNS filtering protects networks from phishing, malware, and non-compliant content.
This is a quick note to all current and future customers, we have made a business decision to move from our old DNS filter / web filter software (called DNSFilter) to a new provider called DefensX.
Why Does This Even Matter?
We recently performed network inventory for all our Monthly Managed IT Services clients and found that many of them had an issue where the filtering software was in an error state and needed to be re-installed. This started our search for a more reliable partner. We found that DefensX provided all the needed functionality and gave our clients the added benefit of reports to see who is looking at what on the internet – something we think that business owners will find extremely valuable.
What Happens Now?
We are automatically removing the old software and deploying the new software to those who have already signed up for service. If you are Monthly Managed IT Services client and do not currently use our DNS filtering service, then reach out to get started at No Additional Cost!
This new service has many new categories to choose from as well, so if there are any sites being blocked or not blocked that you see in your new reports, then just let us know and we can quickly make those changes.
Don’t wait for a cyber attack to compromise your business. Take proactive steps to safeguard your network today! Contact Farmhouse Networking now to implement our advanced DNS filtering solution. Our experts will tailor a protection plan that fits your unique business needs.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using PowerShell to deploy Synology Active Backup for Business.
Research
Found a support page from Synology that details how to edit the MSI file and deploy it via a Group Policy Object. We are using a similar method to edit the MSI package and deploy it from a local share to all computers via the RMM. You will need to configure a Synology Active Backup for Business template for PCs and download the MSI installer. We use a software called InstEd to edit the MSI installer as follows:
Click Property in the Tables list on the left. Enter the values for the following properties3:
USERNAME: Enter the username for accessing the Synology NAS.
NO_SHORTCUT: Enter “1” if you want to hide the Active Backup for Business Agent’s icon from the main menu of the end user’s device.
ADDRESS: Enter the IP address of the Synology NAS.
PASSWORD: Enter the password for accessing the Synology NAS.
ALLOW_UNTRUST: Enter “1” if you want to connect to the Synology NAS using an IP address instead of a domain or DDNS.
PROXY_ADDR, PROXY_PORT, PROXY_USERNAME, PROXY_PASSWORD: Enter these values only when users have to access your Synology NAS via proxy.
Click File > Save
Once done, upload to the local network share and take note of the share path – i.e. \\192.168.20.10\Support
Variables
$MSIArguments = This will include full file name of the Synology Active Backup for Business MSI installer – i.e. ‘Synology Active Backup for Business Agent-2.7.0-3221-x64.msi’
Script Snippet
Push-Location -Path '\\192.168.20.10\Support' -StackName 'Backup'
Set-Location -StackName 'Backup'
$MSIArguments = "/i Synology Active Backup for Business Agent-2.7.0-3221-x64.msi"
Start-Process "msiexec.exe" -ArgumentList $MSIArguments -Wait -NoNewWindow
The script will take several seconds to minutes to run based on the speed of the computer. The computers will start populating on their own into the Synology Active Backup for Business app.
If your company is a MSP or wants to become one and automation just seems out of reach, then contact usto run your RMM for you.
Streamline client maintenance via RMM automation and AI at Farmhouse Networking
Farmhouse Networking (FHN) is constantly looking for ways to enhance the services that we offer to our clients. Automation and artificial intelligence (AI) are two technologies that have emerged to streamline this process.
FHN uses automation to manage tasks that are typically performed manually, such as system configuration, software installation, and server maintenance. By automating these tasks, FHN can prevent human error and ensure that their clients’ systems remain up to date and secure.
In addition, FHN uses AI to monitor clients’ systems for potential issues, such as hardware failure, security breaches, or performance issues. AI-powered systems can analyze data to detect patterns or anomalies that may indicate a problem, allowing FHN to act quickly based on this laser focused data to prevent downtime or data loss.
Contact us today to learn how Farmhouse Networking can future-proof your network with our innovative maintenance solutions.
Managed cloud services pricing helps small businesses control IT costs with transparent, predictable monthly cloud support.
We have received numerous inquiries from potential customers regarding our pricing structure. Specifically, they want to know if we offer monthly contracts or if we charge an hourly rate. The answer is Yes.
Hourly Rate
For customers who require a one-time fix or need a project completed, we offer a service based on an hourly rate. Our rate for remote or on-site work that is not covered under a contract is $150 per hour. We bill in 15-minute increments and take pride in our efficiency. For clients with more than 2 service requests per month, we highly recommend signing up for a contract to save money and benefit from our expert oversight.
Monthly Contracts
There are three types of monthly contracts:
Remote Maintenance Contract
This is the package that most of our clients choose. It includes automated maintenance, cyber security protections, and unlimited remote support. Since most problems and questions can be handled remotely, this package offers real value.
Full Service Maintenance Contract
This package is for clients who want complete peace of mind. It includes all services, whether remote or at their offices. Additionally, it provides some additional benefits, such as top priority in our support queue.
Co-Managed IT Contract
This special package is designed for companies that already have a full-time IT employee or IT service companies in need of extra help. It provides them with the necessary automations and tools to make their jobs easier, allowing them to focus on what matters. This package also includes a discount on our remote and on-site services.
All contracts are based on a per-device model, taking into account the number of workstations, printers, servers, switches, etc. on the client’s network. We use this model because the other popular model, per user, is too vague and can easily hide excessive profit margins. Contracts can be month-to-month or a yearly commitment. The difference is that with a yearly commitment, you are protected from price increases for the entire year. We also offer many optional add-ons for our clients, such as Office 365, Employee Security Training, Penetration/Vulnerability Scanning, Mobile Device Management, Compliance, Secure Remote Access, and Security Operations Center.
Are you looking for reliable IT support that suits your business’s unique requirements? Look no further! Our flexible pricing options cater to businesses of all sizes. Whether you require one-time assistance or ongoing support, we have the right plan for you. Ready to take your business IT support to the next level? Contact us today to discuss your needs and find the perfect plan for your business.
MSP console managing SMB BYOD smartphones and laptops with centralized MDM and security policies.
Small and medium-sized businesses (SMBs) face numerous challenges when it comes to managing their IT. Limited resources (both human and money), lack of expertise, and the need to focus on core business operations often make it difficult for SMBs to understand and manage technology needs. This is where Managed Service Providers (MSPs) come in. In this blog article, we will explore the reasons why SMBs should consider partnering with MSPs to enhance their IT capabilities and drive business growth.
Cost-Effective IT Solutions:
One of the primary reasons why SMBs need MSPs is the cost-effectiveness they offer. By outsourcing their IT needs to MSPs, SMBs can avoid the high costs associated with hiring and training an in-house IT team. MSPs provide a range of services, including network monitoring, data backup and recovery, cybersecurity, and software updates, all at a predictable monthly cost. This allows SMBs to allocate their resources more efficiently and focus on their core business.
Access to Expertise and Advanced Technology:
MSPs are experts in providing IT services and have a team of highly skilled professionals with expertise in variety of technology. By partnering with MSPs, SMBs gain access to the depth of knowledge and experience from IT experts who can handle complex tasks and provide strategic guidance. Additionally, MSPs stay up-to-date with the latest technology trends and can recommend and implement solutions that can help SMBs stay competitive in the market and safe from hackers.
Proactive IT Support and Maintenance:
MSPs offer proactive IT support and maintenance, which is crucial for SMBs. They monitor networks, identify potential issues, and take preventive measures to avoid downtime and disruptions. MSPs also provide regular software updates, security patches, and system maintenance, ensuring that SMBs’ IT remains secure and up-to-date. This proactive approach helps SMBs minimize the risk of costly IT failures and ensures smooth business operations.
Enhanced Data Security:
Data breaches and cyberattacks pose a significant threat to SMBs. MSPs play a vital role in safeguarding SMBs’ sensitive data and protecting them from potential security breaches. They implement robust cybersecurity measures, such as firewalls, antivirus software, and encryption, to ensure data confidentiality and integrity. MSPs can also conduct regular security audits and vulnerability assessments to identify and address any potential weaknesses in the IT infrastructure.
Scalability and Flexibility:
As SMBs grow, their IT needs evolve. MSPs offer scalable solutions that can adapt to changing business requirements. Whether it’s adding new users, expanding storage capacity, or integrating new software, MSPs can quickly and efficiently accommodate these changes. This scalability and flexibility allow SMBs to focus on their growth without worrying about the limitations of their IT infrastructure.
If your company could use the cost-effective solutions, access to expertise, proactive support, enhanced data security, and scalability that come from using a MSP, then contact us for assistance.
Farmhouse Networking cloud automation eliminates manual IT tasks for Oregon SMBs using Power Automate and PowerShell workflows.
Worked with a client lately to help them Automate a workflow, but you may be wondering what does that even mean. Let me explain. We all have tasks in our workday that are repetitive and consume little bite size pieces of our time. Depending on the steps needed to accomplish these tasks, they can be “delegated” to a computer process via scripting aka we automate them. In the case of the client we helped, they received emails from an eFax service which included attachments. These attachments had to be manually saved into a shared folder for the rest of the staff to access as needed. This process probably took about 30 to 60 seconds each, but multiply this by the 30+ faxes they received each day you have 15 to 30 minutes of wasted time each day (65-130 hours per year). This does not take into account the time taken to stop doing one thing, accomplish this task, and restart the original thing they were doing.
Automate to Freedom
What if we could automate this little task and keep them employee free to do other more important things? We did. They customer uses Office 365 which includes a service called Power Automate. We scripted this tool to look at incoming messages, find ones from the eFax vendor, strip out the attachment, and save it to a SharePoint folder. This can then be shared with other employees and even synced via OneDrive to their Desktops for viewing, etc. That is just the tip of the iceberg as there is so much more that can be done with this technology.
If your company wasting little bite size pieces of time in repetitive taks, then contact us for assistance.
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say, “They share freely and give generously to the poor. Their good deeds will be remembered forever.” For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.