Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all 5385 articles
Browse latest View live

Re: SEM Agent Memory issues

$
0
0

For what it's worth we encountered this issue on 6.7 and a rollback of the agents to 6.6 has resolved the issue for us. While we're all waiting for a fix, this is better than nothing.


Re: SEM Agent Memory issues

$
0
0

SEM 6.7.1 is now available on your Customer Portal and includes a fix for the agent memory issue. Apologies for any inconvenience caused as a result of the issue, I understand it was frustrating. Once you upgrade the SEM appliance to 6.7.1, the update will push to your agents (provided auto-update is enabled) and no further action is required in order to resolve the issue.

 

Thanks for bearing with us!

Re: Since upgrade to 6.7, emails are not being sent

$
0
0

SEM 6.7.1 is now available on your Customer Portal and includes a fix for the e-mail alert issue. Apologies for any inconvenience caused as a result of the issue, I understand it was frustrating.

 

Thanks for bearing with us!

nDepth search for specific IP address

$
0
0

I had some odd traffic going from one of my computers to an external IP address and I'm trying to glean more information about what was going on. I'm trying to use nDepth to search for the external address using the condition "IP Address = the_IP_I'm_looking_for" but nothing is being found. I'm not sure what I'm doing wrong. I've browsed the forum for similar queries but am still not getting any results.

Re: Since upgrade to 6.7, emails are not being sent

$
0
0

I installed the update and I've began receiving emails again for at least 3 rules already.   Thanks!

Re: SEM Agent Memory issues

$
0
0

My server admin says the memory is back to normal on the clients we've updated so far.  Thanks for the fix.

Re: SEM Agent Memory issues

$
0
0

Great!  I've deployed 6.7.1 tonight - we will see for ourselves!

 

Mike

Re: SEM Agent Memory issues

$
0
0

Which windows download is for VM based SEM appliances ?

 

 

Thanks


Re: SEM Agent Memory issues

$
0
0

The appliance can be found under 'All Release Downloads' on your Customer Portal:

 

If you are upgrading your appliance, I'd recommend using the ISO within 'Upgrade Downloads':

 

Re: SEM Agent Memory issues

$
0
0

Apologies for misunderstanding.

I was referring to the version of Windows SEM Agent that is to be deployed, in order to address the memory leak issue.

 

I should have included a larger printscreen, (though the download size in my printscreen is an indication of small download size, compared to appliance)

 

Thanks.

Re: Decommissioned Nodes Still showing in SEM Nodes

$
0
0

The servers have been removed from the network and decommissioned(powered down, removed network connection, removed HD and Memory, and destroyed).

Nodes have the agent installed, but no nodes are showing.

$
0
0

I have a trial version of SEM installed as a test, the windows installer instals ok, the server is configured and can ping ip addresses, but the nodes aren't showing on the GUI.

I've left it around 45 minutes for the nodes to communicate with the server, but they're not there.  do I have to do anything else?  Such as a reboot or anything?

Re: Nodes have the agent installed, but no nodes are showing.

$
0
0

I'd guess a ports/firewall issue, they check in and show up on the web console immediately once the install completes.  This KB discusses troubleshooting the agents

Success Center

Looking for list of default reports in SEM reports

$
0
0

There used to be a list of default reports with descriptions available for LEM. I cannot find it now. The page redirects to a search.

 

Does anyone have this list or a link to it?

List of default SEM Reports with report description

$
0
0

Where can I find a list of the current default reports?


Re: Looking for list of default reports in SEM reports

Fortimail And FortiWeb Logging

$
0
0

Hi,

 

has anyone successfully setup the fortimail or fortiweb to successfully log on SEM?

 

i am running the latest update for the virtualised appliances of both.

 

i can see the logs passing the firewall and going to the LEM. I just cant get the console to show the info through the connectors.

 

Am i missing something? Any help would be appreciated.

 

Regards

 

Paul Dyball

Re: Fortimail And FortiWeb Logging

$
0
0

I'm assuming from your description that fortimail/fortiweb is sending syslog messages to SEM.

 

Do you see them in checklogs on the SEM?

 

Success Center

 

If you do, assuming the connector is enabled and reading from the same location, are you seeing unmatched data events in nDepth?

 

Success Center

Re: Nodes have the agent installed, but no nodes are showing.

$
0
0

I have had this issue before, and what I had to do was log onto the node directly, and run the SolarWinds clear certs script. It essentially stops the services, deletes all the files in the spop directory, and restarts the services. Once you restart the services, the nodes pop into the SEM again. Here is an excerpt of the .bat file/script that shows all the files to be deleted, and their locations (pasted as plain text):

 

del \\%1\c$\windows\sysWOW64\contegospop\spop\communications.xml

del \\%1\c$\windows\sysWOW64\contegospop\spop\alertdb.xml

del \\%1\c$\windows\sysWOW64\contegospop\spop\database_cfg.xml

del \\%1\c$\windows\sysWOW64\contegospop\spop\datadictionary.xml

del \\%1\c$\windows\sysWOW64\contegospop\spop\hierarchy.trigeo

del \\%1\c$\windows\sysWOW64\contegospop\spop\peer.trigeo

del \\%1\c$\windows\sysWOW64\contegospop\spop\private.trigeo

del \\%1\c$\windows\sysWOW64\contegospop\spop\StartupRules.xml

 

You can run this from any machine that will have access to all the machines that you need to have in the SEM, and the account you run the .bat file will need admin rights. You can create a ticket and request the clear certs script - SW should be able to help you with it...if not let me know if I can help

 

Respectfully,

 

Mike

Re: List of default SEM Reports with report description

Viewing all 5385 articles
Browse latest View live


Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>