Skip to content

Instantly share code, notes, and snippets.

@saurabh2590
saurabh2590 / alert-advice.md
Created August 13, 2026 12:32
alert-advice for STACKIT AUDIT

I now have a thorough understanding of the STACKIT audit log data. Let me compile the comprehensive alert recommendations based on the actual data patterns observed.

Based on my thorough analysis of your STACKIT audit logs in logs-generic.otel-default from the last 24 hours (527 events, 10 users, 16 initiators, 14 distinct actions across 5 services), here are the alerts I recommend, organized by category:


🔐 1. Authentication & Identity Alerts

Alert Rationale Suggested Condition
@saurabh2590
saurabh2590 / queries.js
Created July 13, 2026 11:33
Get Long Running OPs and kill
let count = 0;
db.aggregate([
{
$currentOp: { allUsers: true, idleConnections: false }
},
{
$match: {
"active": true,
"secs_running": {$gt: 10},
"ns": { "$regex": "cqrs.*" },
@saurabh2590
saurabh2590 / demo.json
Created June 5, 2026 12:13
sample payload
{
"model": "anthropic/claude-sonnet-4-6",
"max_tokens": 32000,
"messages": [
{
"role": "system",
"content": "You are OpenCode, the best coding agent on the planet.\n\nYou are an interactive CLI tool that helps users with software engineering tasks. Use the instructions below and the tools available to you to assist the user.\n\nIMPORTANT: You must NEVER generate or guess URLs for the user unless you are confident that the URLs are for helping the user with programming. You may use URLs provided by the user in their messages or local files.\n\nIf the user asks for help or wants to give feedback inform them of the following:\n- ctrl+p to list available actions\n- To give feedback, users should report the issue at\n https://github.com/anomalyco/opencode\n\nWhen the user directly asks about OpenCode (eg. \"can OpenCode do...\", \"does OpenCode have...\"), or asks in second person (eg. \"are you able...\", \"can you do...\"), or asks how to use a specific OpenCode feature (eg. implement a ho
@saurabh2590
saurabh2590 / response.json
Created November 20, 2025 10:06
Atlas Index Recommendation Response
{
"clusterId": null,
"collectedIndexes": [
{
"accessCount": 219,
"index": [
{
"user_id": 1
},
{
-- Counting unique users who have atleast produced one event
SELECT
"system",
COUNT(DISTINCT user_id) AS nof_users
FROM "catalog-s3".bronze.mongodb.archiver.events
WHERE
"timestamp" >= '2024-08-01' AND
"timestamp" < '2025-08-01'
GROUP BY "system"
ORDER BY "system"
@saurabh2590
saurabh2590 / openpanel_script.html
Created November 7, 2025 10:54
Openpanel Integaration
<script>
window.op = window.op||function(...args){(window.op.q=window.op.q||[]).push(args);};
window.op('init', {
apiUrl: "https://events.bettermarks.com",
clientId: "999eae4d-c62d-45f0-8e3b-7d213a54d779",
trackScreenViews: true,
trackOutgoingLinks: true,
trackAttributes: true,
});
</script>
@saurabh2590
saurabh2590 / Things to put
Last active October 15, 2025 13:48
Mixpanel Integration Notes
<head>
......
<script>
(function (f, b) { if (!b.__SV) { var e, g, i, h; window.mixpanel = b; b._i = []; b.init = function (e, f, c) { function g(a, d) { var b = d.split("."); 2 == b.length && ((a = a[b[0]]), (d = b[1])); a[d] = function () { a.push([d].concat(Array.prototype.slice.call(arguments, 0))); }; } var a = b; "undefined" !== typeof c ? (a = b[c] = []) : (c = "mixpanel"); a.people = a.people || []; a.toString = function (a) { var d = "mixpanel"; "mixpanel" !== c && (d += "." + c); a || (d += " (stub)"); return d; }; a.people.toString = function () { return a.toString(1) + ".people (stub)"; }; i = "disable time_event track track_pageview track_links track_forms track_with_groups add_group set_group remove_group register register_once alias unregister identify name_tag set_config reset opt_in_tracking opt_out_tracking has_opted_in_tracking has_opted_out_tracking clear_opt_in_out_tracking start_batch_senders people.set people.set_once people.unset people.increment people.append people.union people.track
┌─────────┬────────────────────────────────────┬────────────────────┬─────────────────────┬─────────────┬─────────────────┬───────────────┬────────────┬─────────┬───────────┬────────────┐
│ (index) │ name │ namespace │ cpu │ memory │ type │ instanceCount │ memoryCost │ cpuCost │ totalCost │ perPodCost │
├─────────┼────────────────────────────────────┼────────────────────┼─────────────────────┼─────────────┼─────────────────┼───────────────┼────────────┼─────────┼───────────┼────────────┤
│ 0 │ 'calico-node' │ 'kube-system' │ 0.25 │ 0 │ 'V1DaemonSet' │ 10 │ 0 │ 36 │ '36.00' │ '3.60' │
│ 1 │ 'csi-ionoscloud' │ 'kube-system' │ 0 │ 0 │ 'V1DaemonSet' │ 10 │ 0 │ 0 │ '0.00' │ '0.00' │
│ 2 │ 'konnectivity-agent' │ 'kube-system' │ 0.016
@saurabh2590
saurabh2590 / Experiment.md
Last active March 7, 2024 09:01
Brainstorming ideas
@saurabh2590
saurabh2590 / experiment.md
Last active February 23, 2024 07:51
MongoDB experiment Request

Note:

  • This is something to consider and discuss if we should do it now or later, and I would love a healthy debate about the pros and cons of doing it now or later.

Context:

  • We are going to turn on reading and writing both from MongoDB.
  • I believe that it is going to increase the load on our MongoDB Atlas clusters
  • Increased load means we may be required to use the large cluster size.
  • The large size of the cluster means higher costs.
  • The experiment aims to validate if MongoDB is a cost-effective & performant event store for the long run.