Re: View SEE logs in SEM
Hi tpmobley, If you do not find a connector listed to configure then it would be a New Connector Request. Contact support to file this feature request. Also I would highly recommend that you create a...
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
Hi ghayas, Oh! When license is expired no new nodes can be added. You will have to work with licensing and renewals if you previously had a license. If this was an eval you should work with Sales....
View ArticleView SEE logs in SEM
Symantec Endpoint Encryption (SEE) event logs can be found on client machines under Windows logs > Application > Symantec Encryption (Event IDs 3000-3013, 3020-3023, 3040-3045, 3070, 3071,...
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
The Device is currently unlicensed ( License Expire)
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
In Addition can you help to configure connector in solarwinds.
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
HI wolram, Case Already opened but IBM not support in Solarwinds. some replies are sharing. " Thank you for contacting IBM Support! My name is Prateek Jain and I'll be assisting...
View ArticleUSB detach rule not working anymore
Hello, We've been using a rule we made that would detach unauthorized USB from the computers, it then stopped working for some reason, we then tried to use the prebuilt template already available, the...
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
Hi ghayas, That looks like the correct ip address based on your other screenshots. Do you see the ip address of the device in any of the logs that you had a screenshot of? If you cannot find them in...
View ArticleRe: How to Integrate SEM (LEM) to IBM XGS 3100 (IPS/IDS)
HI Wolram, Im attaching Syslog Setting snap.
View ArticleRe: Checkpoint 80.30
Thanks for your reply. I have followed the steps mentioned in the link in your reply. the steps are very similar to integrating with R77 and I have done it many times over the years due to...
View ArticleSplunk cost can really add up...
If you ever used the licensed splunk you'd know it's licensed by the amount of data you log. Once you convert from free license to paid the price adds up quickly! SEM is node based in price and that...
View ArticleRe: SEM Agent installation on WIndows 2019 DC (domain controller)
At this point, it's best to raise a Tech Support ticket so an Engineering can dig a bit deeper and resolve the issue. If you want to send me the Case ID, I can follow up internally. Thanks!
View ArticleRe: SEM Agent installation on WIndows 2019 DC (domain controller)
Yesterday I was trying on OS clean installation without adding server to domain with no success. Also I trying to install that with Admin privileges. None of this option help. Windows OS is in eng...
View ArticleRe: Linux audit log parsing
Thanks for the auditd information. Unfortunately, it looks like the version of auditd that we're running on our test server does not support the ENRICHED directive (it's a RHEL 6 box), so we'll have to...
View ArticleSEM users: It's time to talk about reporting!
The SEM product team is working on revamping the reporting engine in SEM and we're looking for a few users to give their thoughts on early design ideas. If you're interested in participating in a...
View ArticleRe: Failed Authentication Attempts
Unfortunately, sometimes this is down to the way in which Windows logs the failed authentication events. Are you getting the same EventID (ProviderSID in SEM) for each logon failure, or are they...
View ArticleRe: Checkpoint 80.30
Provided the current connector is stopped, it shouldn't interfere with the connection to the R80.30. Can you confirm that you've followed all the steps listed here to configure the integration between...
View ArticleRe: SEM Appliance Security Information
Hi Ravi - this blog post goes into some additional detail: Security Event Manager Appliance Security and Data Protection. If there's a specific question you have around the SEM appliance security just...
View ArticleRe: Linux audit log parsing
There appears to be a setting you can adjust in auditd.conf that will replace the UIDs with the actual username. SEM will not automatically lookup the passed/group files, we will only parse the...
View Article