{"@attributes":{"version":"2.0"},"channel":{"title":"Brad Lhotsky","description":"Foolishly applying a development and operations background to security problems at a ridiculous scale for love and money.","link":"https:\/\/speakerdeck.com\/reyjrar","lastBuildDate":"2014-10-05 08:34:57 -0400","item":[{"title":"Hard Earned Lessons in Observability, Security, and Life","description":"In the age of AI, this talk will be abnormally focused on the humans the machines are meant to serve. We'll look at successful security and observability solutions and how they map to the human behind the keyboard. Learn from more than two decades of mistakes in both to build successful and celebrated security and observability programs without them.","pubDate":"Sun, 29 Mar 2026 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/hard-earned-lessons-in-observability-security-and-life","guid":"https:\/\/speakerdeck.com\/reyjrar\/hard-earned-lessons-in-observability-security-and-life"},{"title":"Breaking the Rules - Rate Limiting with ClickHouse","description":"So you want to build a rate limiter? The obvious choice is to use Redis. It's sorted sets make short work of the logic required. But, what if you wanted something a little different? Something more flexibly? Something a little counter-culture?  This is a quick introduction and overview of one such exploration. Rather than use a customary Redis counter based system, we built a rate limiter using SQL queries backed by ClickHouse.\n\nTo download the slides with presenter notes, <a href=\"https:\/\/divisionbyzero.net\/ClickHouse-Ratelimiter-WithNotes.pdf\" alt=\"Slides with presenter notes\">click here<\/a>.","pubDate":"Sun, 10 Mar 2024 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/reyjrar\/breaking-the-rules-rate-limiting-with-clickhouse","guid":"https:\/\/speakerdeck.com\/reyjrar\/breaking-the-rules-rate-limiting-with-clickhouse"},{"title":"TPCiC 2021: ElasticSearch Exploration in Your Terminal","description":"\n\nYou've seen the pretty graphs. Visuals are great for signaling there is a problem somewhere in your system. How do you, a command line guru, go from pretty graphs to root cause analysis? Most likely you'll be reaching for paradigms from the command line: composability and a flexible, compact syntax to ask your questions. I'd like to talk more about integrating ElasticSearch-based dashboards back to the command line workflows I love.\n\nThis talk is an overview of a tool I developed while working at Booking.com to drastically reduce the time and complexity of performing incident reponse against rich, structured data in ElasticSearch. It was developed with the help of the security and fraud teams to perform ad-hoc queries critical for incident response. The tool served the team well and it's been under active development ever since. It continues to grow in capabilities aimed to make adhoc analysis simple, easy, and accessible to hardened command line jockeys and command line newbies.\n\nJoin me to learn how to bring the logging data you love back to your terminal!\n","pubDate":"Wed, 09 Jun 2021 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/tpcic-2021-elasticsearch-exploration-in-your-terminal","guid":"https:\/\/speakerdeck.com\/reyjrar\/tpcic-2021-elasticsearch-exploration-in-your-terminal"},{"title":"ElasticSearch Data Exploration in Your Terminal","description":"\n\nYou've seen the pretty graphs. Visuals are great for signaling there is a problem somewhere in your system. How do you, a command line guru, go from pretty graphs to root cause analysis? Most likely you'll be reaching for paradigms from the command line: composability and a flexible, compact syntax to ask your questions. I'd like to talk more about integrating ElasticSearch-based dashboards back to the command line workflows I love.\n\nThis talk is an overview of a tool I developed while working at Booking.com to drastically reduce the time and complexity of performing incident reponse against rich, structured data in ElasticSearch. It was developed with the help of the security and fraud teams to perform adhoc queries critical for incident response. The tool served the team well and it's been under active development ever since. It continues to grow in capabilities aimed to make adhoc analysis simple, easy, and accessible to hardened command line jockeys and command line newbies.\n\nJoin me to learn how to bring the logging data you love back to your terminal!\n","pubDate":"Tue, 22 Oct 2019 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/elasticsearch-data-exploration-in-your-terminal","guid":"https:\/\/speakerdeck.com\/reyjrar\/elasticsearch-data-exploration-in-your-terminal"},{"title":"Finding Meaning in Operational Data","description":"Overview of what operational data is, where to start, and how to leverage it.","pubDate":"Tue, 20 Jun 2017 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/finding-meaning-in-operational-data","guid":"https:\/\/speakerdeck.com\/reyjrar\/finding-meaning-in-operational-data"},{"title":"DevOps Data Storage","description":"What data do we need to store to be more devopsy?  How can we use the data?  What data stores are out there, where and why might we use them?","pubDate":"Tue, 21 Feb 2017 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/reyjrar\/devops-data-storage","guid":"https:\/\/speakerdeck.com\/reyjrar\/devops-data-storage"},{"title":"Lessons from High Veolcity Logging (2016 Edition)","description":"Do you need to send, parse, store, and search large volumes of logging data? Well, step right up! We'll briefly stumble over the landscape and then embark on lessons learned about Perl, ElasticSearch, life, and ultimately ourselves! We'll talk about sending logging data using retro protocols like syslog. We'll discuss the up, down, left, and right sides of log parsing! We'll investigate my love-hate relationship with scaling and stabilizing ElasticSearch. Finally, we'll dive into interacting with your data and what unexpected things it can teach you!","pubDate":"Tue, 15 Nov 2016 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/reyjrar\/lessons-from-high-veolcity-logging-2016-edition","guid":"https:\/\/speakerdeck.com\/reyjrar\/lessons-from-high-veolcity-logging-2016-edition"},{"title":"Writing CLI Tools for Other People","description":"A talk on how to write a CLI tool for other people using Perl and some CPAN Modules.","pubDate":"Mon, 20 Jun 2016 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/writing-cli-tools-for-other-people","guid":"https:\/\/speakerdeck.com\/reyjrar\/writing-cli-tools-for-other-people"},{"title":"Everything You Never Knew You Wanted to Ask about Time Series Databases","description":"This talk covers the Graphite ecosystem.  It is intended to serve as an introduction to core concepts.  I also highlight some gotchas I see people run into when they start using time series databases.","pubDate":"Sat, 17 Oct 2015 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/everything-you-never-knew-you-wanted-to-ask-about-time-series-databases","guid":"https:\/\/speakerdeck.com\/reyjrar\/everything-you-never-knew-you-wanted-to-ask-about-time-series-databases"},{"title":"Lessons from High Velocity Logging","description":"Talk for YAPC::NA 2015 discussing the lessons learned from shipping, parsing, storing, and using logs!","pubDate":"Tue, 09 Jun 2015 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/lessons-from-high-velocity-logging","guid":"https:\/\/speakerdeck.com\/reyjrar\/lessons-from-high-velocity-logging"},{"title":"OSSEC at Scale","description":"Presentation given on applying DevOps mindset to Security with OSSEC as the Focus.","pubDate":"Tue, 16 Sep 2014 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/ossec-at-scale","guid":"https:\/\/speakerdeck.com\/reyjrar\/ossec-at-scale"},{"title":"ElasticSearch for Logging","description":"A brief overview of the landscape of logging data with ElasticSearch followed by a number of lessons learned.  By the end of the talk you should want to use ElasticSearch for logging and know enough to prevent shooting yourself in the foot.","pubDate":"Fri, 20 Sep 2013 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/elasticsearch-for-logging","guid":"https:\/\/speakerdeck.com\/reyjrar\/elasticsearch-for-logging"},{"title":"The Elephant in the Room","description":"A presentation on PostgreSQL for the AmsterdamX.pm at Booking.com HQ.","pubDate":"Tue, 27 Aug 2013 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/the-elephant-in-the-room","guid":"https:\/\/speakerdeck.com\/reyjrar\/the-elephant-in-the-room"},{"title":"The Advanced Persistent Threat and You","description":"Introduction to APT for Perl Programmers presented at YAPC::NA in 2011.  High level overview of why it matters to programmers, and how they can help protect their organizations.  Yes, APT is a security buzzword, but it is very much a part of the world we software in!","pubDate":"Tue, 28 Jun 2011 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/the-advanced-persistent-threat-and-you","guid":"https:\/\/speakerdeck.com\/reyjrar\/the-advanced-persistent-threat-and-you"},{"title":"Regular Expressions for Fun and Profit","description":"A PCRE centric presentation on regular expressions.  Introduction and conceptual analysis of use cases, including a dive into \"Is it the right tool for the job?\"","pubDate":"Sat, 16 Oct 2010 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/regular-expressions-for-fun-and-profit","guid":"https:\/\/speakerdeck.com\/reyjrar\/regular-expressions-for-fun-and-profit"},{"title":"Network Introspection with Open Source Tools","description":"A talk from LinuxWorld 2008 looking at adding value and security to an organization by tackling problems the organization faces with security technologies.","pubDate":"Tue, 15 Jul 2008 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/reyjrar\/network-introspection-with-open-source-tools","guid":"https:\/\/speakerdeck.com\/reyjrar\/network-introspection-with-open-source-tools"}]}}